Arbitrum Security Program
Abstract
The Arbitrum Foundation proposes to continue and evolve the Arbitrum Audit Program (AAP) - launched on 1 August 2025 with a one-year mandate - into a broader Arbitrum Security Program (ASP), running for a further 12 months on a rolling-application basis.
-
From “Audit” to “Security”. AAP delivered on its original purpose - real vulnerabilities surfaced and remediated before mainnet, with a high share of net-new teams brought to Arbitrum - and demonstrated where subsidised security converts into the most ecosystem value. Building on that, the mandate broadens to four pillars covering the full security lifecycle: AI-assisted screening ahead of a full audit, the human-conducted audit itself, the Arbitrum bug bounty program, and the ArbitrumDAO Security Council.
-
No new treasury request. ~$2M in cumulative audit commitments is expected by AAP’s close. The remaining $1.76M USDC + 25M ARB held by the Foundation becomes ASP’s operational budget, less ~$1.2M in predicted outstanding deployments.
-
Operational refinements from a year of experience. The audit committee technical expert retainer is right-sized to $2.5k/month based on expected workload; the DAO-approved alignment framework is maintained as the program’s baseline; program changes adopt a lightweight optimistic approval process to reduce governance overhead; and idle funds are put to work in low-risk management strategies.
The program runs for one year (or until funds are exhausted), managed by the Arbitrum Foundation and supported by the audit committee as technical SME, with quarterly transparency reports and a final summary report to the DAO.
Motivation
The AAP was approved by ArbitrumDAO to remove a barrier facing early-stage teams: third-party audits are the industry norm, but their cost puts them out of reach for many young projects. The program’s full design - objectives, eligibility, application process, auditor approval, and alignment commitments including Arbitrum exclusivity - is set out in the original proposal, and its performance has been reported quarterly (#1, #2, #3).
Results
(covering Q1-Q3 and preliminary Q4, prior to final report)
367 applications were received through preliminary Q4, with application-to-decision time averaging 2-3 weeks. To date, 18 completed audits reviewed 71,366 lines of code and identified 385 vulnerabilities - 13 critical and 40 high - remediated before mainnet. The average audit cost was $50,706, approximately $15 per line of code, which sits below the industry average of $70,000 for mid-complexity DeFi audits as per market references provided by Sherlock and Zealynx. The total commitments are expected to reach ~$2M once in-progress and pending audits are activated.
What Worked
- The program delivered on its original mandate. With ~60% of funded teams net new to the ecosystem, it attracted security-first founders who might otherwise have launched elsewhere.
- It demonstrated Arbitrum’s dedication to user security. Funding security work upfront led to tangible critical findings, remediated before mainnet.
- Operationally the program matured. A growing referral channel now drives roughly half of onboarded teams, and pricing has stayed within benchmarked ranges.
Lessons Learned
- Early-stage teams didn’t have enough runway to benefit from audits. Some recipients were unable to move forward after receiving funding, in a few cases winding down within months. Future eligibility should require at least 1 year of runway and the capacity to cover part of the audit cost.
- Value secured has concentrated in later-stage teams that could typically fund audits themselves - a tension with the early-stage mandate, since younger projects generally need more time to grow TVL for their product.
- Lead times are long. Audit contract signature to mainnet launch averages ~135 days for teams not yet live.
- Impact was real, but visibility was low. Audit subsidies set Arbitrum apart from other ecosystems, but the program received too little visibility to capitalize on that. Going forward, funded teams will be asked to publicly acknowledge the subsidy, among other improvements to program communications.
These results and lessons, among others, shape the adjustments below.
Specifications
Program Adjustments
1. Expand Scope with AI Audits
AAP identified five AI security agents to be trialed under this program. ASP will run the pilot: every funded team will receive an AI-assisted review ahead of its full audit, with lower-cost AI screening available to earlier-stage teams, and all five tools running in parallel for evaluation.
2. Expand Scope with Core Protocol Security: Bug Bounty & Security Council
Audits are point-in-time; protecting the core protocol that every funded team builds on also requires continuous review of live code and emergency response - the program’s third and fourth pillars:
- Bug Bounty (continuous review). Arbitrum operates a bug bounty covering the Arbitrum One and Arbitrum Nova smart contracts, with rewards of up to $2,000,000 for critical findings - a maximum that has never been paid out since the Foundation began running the program. Its scope remains the Arbitrum protocol codebase; ecosystem teams’ codebases are covered through the AI-screening and audit pathway above.
- Security Council (emergency response). The ArbitrumDAO Security Council is the DAO-elected body empowered by the Constitution to respond to security emergencies affecting the protocol in production, and has been historically funded by the AF on behalf of the DAO.
Both are included for the reason set out in the Abstract: redirecting part of the unspent allocation toward the security layers with the highest impact on the ecosystem - every team, user, and dollar of TVL on Arbitrum ultimately depends on the integrity of the core protocol they protect - with no change to the bounty’s scope and reward terms or to the Council’s compensation, election process, and constitutional mandate. Bug and bounty reporting will be provided yearly at a high level, e.g., total payout amounts.
3. Maintain Alignment Framework
After strict exclusivity created material friction during AAP, the requirement was revised via a formal governance proposal into a DAO-approved, alignment-based framework, which ASP adopts as its baseline.
4. Introduce a Lightweight Governance Process
Adjusting the exclusivity framework during AAP showed that putting every program change through the full governance process adds significant overhead. ASP therefore adopts the optimistic approval framework from the recent Code of Conduct proposal: changes posted to the forum by the AF take effect after 14 days unless a combined 5% of delegated VP (measured at the time of posting) raises objections, in which case the change goes to an off-chain vote at the non-constitutional quorum. The AF is responsible for monitoring objections and tallying VP.
5. Enable Idle Funds Deployment
Lastly, with the majority of AAP funds remaining unproductive for the duration of the program, we propose that ASP deploy idle funds into low-risk management strategies.
Budget
AAP was funded through a 30M ARB allocation, part of which was converted to cover audit commitments and the $60k technical expert retainer; roughly $1.23M was committed by the end of Q3, expected to reach ~$2M by program close (cumulative over the program’s duration). ASP requests no new funding: it operates from the actual remaining balance already held by the Foundation - $1.76M USDC plus 25M ARB - less ~$1.2M in predicted outstanding deployments (final amount depends on total audit commitments, some of which may not materialize). This budget covers the expanded scope:
- Audit, AI screening and security subsidies for ecosystem teams.
- Arbitrum protocol bug bounties: operation of the bug bounty program, with contingent reward payouts for validated findings.
- Security Council: member compensation of $5,000 per member per month across the 12-member Council, i.e., $720,000 per year.
- Technical expert: retainer of $2,500/month (down from $5,000/month, or $60,000/year, in AAP), reflecting updated workload.
- All other costs (legal, program management, operations) remain covered by the Arbitrum Foundation.
As in AAP, funds committed towards audits will be disclosed in each quarterly transparency report, giving the DAO visibility into deployment pace against the remaining balance. Any balance unspent at term end returns to the ArbitrumDAO treasury unless the DAO approves a continuation
Timeline
With AAP applications closed on 31 July 2026 and an approximate two-month wind-down underway, continuity of a live audit offering is an important matter for builders on Arbitrum. We propose the following governance timeline, subject to delegate feedback:
- August 13th → Proposal posted in the forum (complete)
- August 20th → Binding off-chain vote following non-constitutional quorum
- By October 1st → Applications open for the program, with an official announcement declaring the start date and the one-year clock.