Arbitrum Security Program is Live: Applications Now Open
Following the ArbitrumDAO’s approval, the Arbitrum Foundation has launched the Arbitrum Security Program (ASP), a 12-month program covering the full security lifecycle for projects building on Arbitrum.
The ASP evolves and broadens the Arbitrum Audit Program, launched in August 2025 with a one-year mandate. It now rests on four pillars:
-
AI-assisted screening ahead of a full audit
-
Human-conducted audits
-
The Arbitrum bug bounty program
-
The ArbitrumDAO Security Council
The Foundation is kicking off the ASP’s audit function today, building on learnings from the original program and introducing an updated framework to ensure projects are audit-ready before entering the program, create greater alignment between participating teams and the Arbitrum ecosystem, and make audit funding available to more projects.
The Foundation will subsidize a portion of selected projects’ audits, depending on the commercial agreement reached with each project.
Program Size
The Arbitrum Security Program commits ~7.8M (1.76M USDC and 25M ARB) at today’s market prices to protect the Arbitrum ecosystem. About $1.2M covers the existing Audit Program commitments, with roughly $6.6M going to new work that keeps builders and users safe. The Foundation will subsidize a portion of the selected projects’ audits depending on the commercial agreement reached with each project.
Application & Audit Process
Projects can apply through an open application process. Before the Foundation begins sourcing an auditor, an approved project will need to:
-
Confirm its codebase is audit-ready
-
Agree to the applicable audit subsidy
-
Sign a Commitment Agreement with the Arbitrum Foundation
Once these steps are complete, the Foundation will begin matching the project with an auditor. Selected teams will also have the opportunity to strengthen their codebase with pre-audit AI security screening ahead of their full audit.
How to Apply
The standardized application form collects key details about the project, team, audit scope, and budget, ensuring a streamlined and fair review. Applications are reviewed based on technical maturity, team, likelihood of success, and alignment with the Arbitrum ecosystem.
Timeline
Projects should plan for approximately one month between application approval and the expected start of the audit and should factor this into their development and launch schedules. The program covers the agreed initial audit only. Teams should ensure their code and intended audit scope are ready before entering the process.
Auditors
Projects accepted into the program will have access to the same group of leading smart contract security firms that powered the previous audit program:
-
ack3
-
Certora
-
Cyfrin
-
Decurity
-
Guardian
-
Hexens
-
Nethermind
-
Oak Security
-
OpenZeppelin
-
OXORIO
-
Pashov Audit Group
-
Sherlock
-
Trail of Bits
Projects will be matched with an appropriate auditor based on audit scope, technical requirements, and auditor availability.
Application Form: Applications
Read the approved proposal for more details: Snapshot
