Arbitrum Security Program

Budget questions

The proposal is explicit that it broadens the mandate, and that the bug bounty and the Security Council have been carried by the Foundation to date. Our questions are about what that means for the budget on both sides.

Both functions also sit inside the Foundation’s own 2027 funding, approved and transferred earlier this year: the technical lines are described in that proposal as covering “block explorers, bug bounties, auditing spend, cloud service providers,” and in that thread the Foundation listed the Security Council among what those lines cover. Nothing in ASP states that the corresponding amounts will be deducted from, returned from, or otherwise reconciled against that budget. The technical lines are aggregated, so this cannot be checked from outside.

What amounts for these two functions are currently embedded in the 2027 Foundation budget, and how will they be reconciled if these functions are funded through ASP?

On the program’s own breakdown: in the deck from the 18 August call, the Security Council and the technical expert carry defined annual amounts, the bug bounty carries its maximum payout per critical finding, and “Audits and AI screening” reads “from remaining balance.” If that reflects the intended hierarchy, ecosystem audit subsidies become the residual category.

What amount, or minimum floor, is reserved for the audit and AI screening pillar for the year? And is there a defined spending priority between the pillars if the balance does not cover all of them? The second was raised on the call and answered as to likelihood rather than as to rule.

We support @MconnectDAO on defining “low-risk” for idle fund deployment and on bounding which changes can pass through the 14-day optimistic process.

Pending answers, we are voting Against.

1 Like