Trillion Dollar Security Initiative - Devconnect
Devcon·Tue, Dec 9, 2025, 12:00 AM
Speakers: Fredrik Svantes, Mehdi Zerouali Event: Ethereum Day (Devconnect Argentina 2025) Keywords: Security, Ethereum, smart contracts, UX, infrastructure, consensus Ethereum's next frontier is Trillion Dollar Security, an ecosystem-wide initiative to further evolve the network into civilization-grade infrastructure capable of on-boarding billions of people and storing trillions of dollars in value in smart contracts. Building on a decade of progress, this effort maps security strengths and attack vectors across every layer of Ethereum’s stack, wallet UX, smart contracts, infrastructure, consensus, and beyond. Trillion Dollar Security is a collaborative mission uniting researchers, wallet teams, auditors, and users to ensure that Ethereum continues being the safest foundation for the world's digital and economic systems. About Devconnect Devconnect is a week-long gathering of the Ethereum community with events for developers, researchers, artists and creators. It’s organized by the Ethereum Foundation and took place in Buenos Aires, Argentina in Nov 2025, with ~20,000 attendees. What’s next The next major Ethereum community event is Devcon 8, happening in 2026. For updates visit: https://devcon.org More Follow us: @efdevcon · @ethereum Learn more about Ethereum: https://ethereum.org And the Ethereum Foundation: https://ethereum.foundation/
Transcript
Thank you, Benji. Hi, happy to see so many people here that are excited about Ethereum. My name is Frederick Suvantes. I lead the protocol security team at the Ethereum Foundation and I'm also one of the co-chairs of the uh trillion dollar security initiative that we're going to be speaking about today. With me, I have my co-speaker Medie.
Thanks, Frederick. It's an honor to be here today. Um, I'm a co-founder of Sigma Prime. We're a blockchain security and research firm. We're also Ethereum core developers, but we're here to talk today about something really, really close to our hearts, the onts initiative.
Before Frederick walks us through the nitty-gritty, the specifics of we're trying to achieve, we thought it was quite important to make sure that everybody understands how important Ethereum security is for everyone. And I mean everyone, not just people in this room. We already have today millions of people using Ethereum. And when we say millions, we're not talking about millions of wallets or millions of accounts. We're talking about millions of people, human beings, actually putting real economic value and trust into a system with no central operator.
This is probably unprecedented in the history of public infrastructure. Talking about economic value, there's already a lot happening on Ethereum. Over 500 billion dollars worth of value is secured using over a million validators that have staked over 35 million ETH today. The uptime is also something that we should all really really be proud of. 10 years of uninterrupted uptime for Ethereum.
Ethereum is the home of stable coins, hosting over $180 billion dollars worth of stable coins across mainnet and its L2s. And we also have 70 billion, if not more, 75 billion last time I checked this morning of TVL on our DeFi ecosystem. This is great. And when preparing these slides, I came across this number, which really blew my mind. $2.
8 8 trillion in October alone of stable coin onchain volume with circles USDC taking the lion share with just over $1.6 trillion. So this is all very promising and very exciting. But as I'm sure you know a lot of that value has been stolen by thread actors. As of today, 15 billion dollars worth of value has been hacked from Ethereum and its ecosystem.
Two billion dollars in just the first half of this year. Balancer's recent exploitation was unfortunately a pretty grim reminder of the importance of smart contract security. However, I invite everyone to zoom out, step back, and look at these losses over the past 18 months. The vast majority of them aren't related to smart contract security. They're unfortunately due to poor web 2 security hygiene and poor key management practices.
I think we have to acknowledge that each hack challenges the trust the public has in Ethereum and we believe that Ethereum is the most secure blockchain. You know, you could we could argue metrics and whatnot. Both of us are really convinced that's the case. It's been battle tested for over a decade now. But it's not enough.
As Frederick eloquently put it in an interview, we are the most secure chain, but that's not really our objective. Our objective is to make Ethereum civilization scale infrastructure. So our ambition goes way beyond blockchains. We want Ethereum to become the backbone of the internet, the backbone of the global economy. We want people, billions of people feeling confident transacting on a daily basis on Ethereum.
Be it individuals, institutions, governments, corporations, there's a long road ahead, but we already started seeing the institutional world embrace Ethereum. I was privileged to attend the New York Blockchain Week a couple of weeks ago. I've had amazing conversations with Wall Street leaders and I was really blown away by how much they're willing to build on the network we all love. Couple of examples on the screen. JP Morgan has led the way and Black Rockck has launched its uh money market fund, the Beetle Fund tokenizing um treasury on Ethereum.
I'll pass it over to Frederick to talk us through what TS actually means.
Thank you. So the scenario that Ny just described about being civilization scale, having billions of users, etc. might seem farfetched to some people or even says science fiction but as mainet launched uh snowball was set in motion that's just been accelerating in speed and growth and at this point we're at a stage where what meta described is actually unavoidable. Ethereum is the most secure, resilient and trusted blockchain in this ecosystem and across the world. But as Maddie again mentioned, we cannot settle with that.
we actually have to keep improving and build and build upon what we have today so that uh the next billion of people can start using this uh technology. So to help accelerate this progress we launched a project called the trillion dollar security project or one PS earlier this year and we need to arrive at a point where basically we can have billions of individuals who are comfortable holding more than $1,000 on chain. uh collectively amounting to over a trillion dollars. And we also need to have companies, institutions, governments, etc. feel comfortable storing at least a trillion dollars in a single smart contract or onchain application and are also comfortable transacting such large amounts uh on chain.
So at the Ethereum Foundation, we have Josh and I who are the co-chairs of this project. Uh we also have the digital studio team that's been helping out with a lot of the efforts. We have Lara, we have Jason, we have Tyler who have also been supporting this. And we have just recently signed with a new person who will be spending their full time uh coordinating this effort to help accelerate it even further. And to ensure we stay the course, we also have ecosystem stewards.
Uh we have Samson who is uh running security alliance. We have uh Zach who is one of the co-creators of uh Etherealize and uh we have Medi here uh who is uh one of the co-founders of Sigma Prime. Um but with that said this is not an initiative that we uh as in Ethereum foundation the stewards or any other single entity can handle on its own. especially not if you want to do it with the scale and speed that we are envisioning delivering on this uh on on this basically. So instead we have been working with many many people and entities and projects within the ecosystem to help advance and accelerate the solution space so that we can arrive at the point which Mary just described.
For one ts to be successful, we identify three different phases that we will need to complete. The first phase is the uh mapping phase where we gather input from across the ecosystem. We have the execution phase where we take that input and start delivering improvements based on that. And then we have the communication phase which I think is something that we continuously need to improve upon. um basically to describe how and why Ethereum is the most secure blockchain in the in the world.
So during the mapping phase which we have now completed, we spoke with over 500 people from across the ecosystem speaking with people such as developers, gamers, traders, uh institutions, protocols, stable coin issuers, etc., etc. basically to get their insight into what areas of security that they feel are necessary in order to reach the objectives that we have set. From these discussions, we ended up with six different focus areas. The first one is the UX and wallets which was brought up in every single call.
This is um big concern to many people especially around the complexity to understand the outcome of transactions as well as key management issues such that Medie mentioned. Smart contracts, while having had a decline in the amount of hacks, still continues to be a source of concern because many people still have this fear of interacting with smart contracts as they could end up losing their funds in some cases. infrastructure and cloud is one of the areas that Medi mentioned where we're seeing this kind of growth in hacks at the moment. Um, as smart contract security has improved, the attackers are moving to the the other type of layer which they can attack which is the infrastructure that's powering the front ends for smart contracts interactions for example. This is something that we need to also improve upon.
Monitoring in IR is about uh incident response and monitoring to be able to detect when a hack happens and being able to react when it does. Uh we already see some big efforts in this place today such as the security alliance and its seal 911 initiative which is being run by PCU. The consensus protocol is something that has not received as much concerns. Uh most likely partly because uh we've had over a decade of uptime. We haven't seen a serious security incident but we cannot forget that the protocol is super important.
We need to keep securing it especially considering things like postquantum and other things. The social layer and governance uh area is about staking centralization. Uh it can be about uh being concerned about how governments will treat Ethereum and those kind of aspects. So taking that and this might sound kind of bleak like I'm pulling up a lot of kind of negative aspects but if we don't know the issues then obviously we can't fix them. So the good news is that we're already starting to see improvements in many of these areas which we believe will have a ton of ton of positive impact on the whole ecosystem.
For example, we have wallet beat which is creating a minimum security standard for wallets. Uh it's also creating these kind of stages where wallets can progress upon depending on uh the security, privacy and um censorship resistance levels that they're at. similar to L2B. Um, we are also working on an initiative for securing smart contracts where we're collecting previously found vulnerabilities in this ecosystem. Uh, amounting to, you know, hundreds of thousands of potential weaknesses found through audits, through contests, etc.
putting that in a public data set that LLM providers and others can then use uh to train their models to become even better at finding vulnerabilities before contracts are deployed on chain. Uh transactions assertions is basically a way to allow people to set rules before they make the actual transaction and then have the protocol itself verify that the outcome of the transaction is what the user intended before it's actually written on chain. Something else that's super important if we're going to reach a billion people is that we need to we need to create wallets that are more beginner friendly. Um mentioned that we have a wallet page today which is super good. Uh many of them however require a bit of technical understanding in order to use them.
And to reach the next billions of people we need to have wallets that are basically foolproof and won't have a possibility to lead to user losses etc. The verifiable front ends is a project where we take the the issue that was mentioned previously about front ends being compromised. We need to have the ver variable front ends in order to protect users from a malicious threat actor taking over a website changing a JavaScript from something that's non-malicious into malicious uh which could potentially mean that you will end up losing your fonts when you're signing a contract. Removing blind signing is definitely the most critical thing that we have to fix. Many of you have probably done transactions on chain and when you're interacting with contracts, you might have seen something such as you're interacting with this public address, you're seeing a bunch of random call data, and then you kind of have to cross your fingers and hope that you don't lose all your money.
This is something that we need to fix. We need to make sure that people see very clearly what the outcome of the transaction is going to be. Um so that they can make a factual decision whether or not to interact with the uh with the contract. The third phase is the communication phase. Here, as I mentioned, we need to become much better at communicating that Ethereum is the most secure, resilient, and trusted blockchain ecosystem in the world.
To do that, the digital studio team at the EF together with Josh have been working on a new uh progress website that basically provides information about all the projects that we're working on such as the ones I mentioned and shows a progress bar where we're at, what kind of topics we would need um more more people from the ecosystem to come and help with etc. Um, and uh, yeah, that's where we're at right now. So, back to Media.
Thank you. Thanks, Frederick. Um, why should you care and how to get involved if uh, if you'd like to help? Um, well, I think everyone here should care because this is a strong signal that the Ethereum community is providing to the world. We are raising the bar.
the security posture of Ethereum is going to increase across its entire ecosystem across all the layers that users interact with. Um the end game as uh Thomas alluded to earlier is to have billions of people trusting Ethereum on a regular basis and we want everyone to be able to transact on Ethereum with confidence. remote farmers in developing countries, top CFOs and CEOs of Fortune 100 companies, everyone should hopefully feel safe on our lovely chain. And in order for us to achieve that, we need your help. We can't expect the EF alone to be fixing all these problems.
It's obviously not how we operate. Um, we need you to tell us what your pain points are. OneTS isn't about telling anyone what to do. It's about creating places where builders can collaborate on the security problems that affect all of us. So for builders in the room, you may have security concerns when building on Ethereum.
Are there any blocking points perhaps standing between you and the next wave of growth? Do you need more users? And can we do anything to unlock that next leg of growth? uh protocol researchers, there's so much that can be done through joint collaboration and I think collaboration here is the key and I just want to be explicit here. OneTS is not a procurement channel.
A lot of people have started coming to us pitching their proprietary protocols, their tokenpowered solutions. We cannot enshrine anything that is not open source in Ethereum. Open source first always. It's always been Ethereum's culture and one is carrying that mission. So if you're coming to us with ideas, please make sure that they're forkable, auditable, and more importantly, community owned.
Blind signing is a plague. We strongly believe that the solution is not about taxing users to transact safely. I'd like to think that everyone in this room believes that Ethereum has the security, the decentralization, the engineering culture to become the foundation of the world's financial infrastructure. And this initiative is essentially how we make that future safe. Thank you.
Thank you both.
Thank you both so much. Um, so we have a bunch of questions and again like thank you to the audience for asking these questions. They're they're honestly really great. So we only have time for three. Y.
Um, but one, do you think the demand for security researchers will increase in the coming years and won't they be replaced by AI agents or the like?
Yeah, sure. So uh I definitely think there will be a increase in demand. I think that well I think an increase in demand will come from the fact that people are using AI even more actually um especially today. I think even in the future if you're looking at things from a like if they are way more advanced I do think that there will still be a need or necessity for human beings to kind of operate them and and get them to actually uh understand what they're what they're about to do. So um there might not be as much of a need for let's say junior uh security people but definitely on a more architectural level and such I think there will be a big big demand.
If I may just add very briefly from uh the perspective of of a security firm u our clients are pumping code like crazy using using AI tools. It just increases the demand for code reviews and secure code reviews as of as of now.
Awesome. Um what are your thoughts on the potential impact of quantum computing on each security?
Yeah, look uh I'm no cryptographer expert. Uh but I I think it's very apparent that if there's one ecosystem that is geared and equipped to face that challenge, it's ours. Uh a lot of others are just pretending that this won't be a problem. uh we're tackling this head-on, funding a lot of research and actually starting building some of those postquantum cryptography primitives.
Yeah. Uh there's a lot of foresight involved in all of that.
Yeah, I mean just in the EF we have people that are focusing completely on on this particular topic. So yeah, it's definitely something that's being taken into a lot of consideration.
Um okay, another AI question. Would you want a ZK EVM question or an AI question? You pick.
Okay, let's do let's do a little se separate one. ZK EVMs seem like a massive change. How does Ethereum stay secure while replacing its core by bleeding edge tech that is not battle tested yet?
Yeah. Um this is I guess it would be interesting to hear your perspective as well. Uh from my point of view, this is kind of similar to the the way we did the merge where we had you know the execution layer at one point alone and then we kind of did this uh the merge where we introduced the consensus layer. This was obviously a very big shift. Um and I think you know we're looking at things from at least a similar scale where we need to put a lot of focus and efforts.
Uh from a security point of view we're already starting to ramp up with this. Uh there are a lot also already a lot of entities that are working on securing CK VMs etc. So from a security point of view I'm sure we're going to be more than ready for it but it's definitely a paradigm shift that we're going to have to think about. But I would be interested to hear your point of view from security.
The way the way I look at it um ZK security today is where solidity security was in 2016.
Very immature. Not many people who can reason about these concepts. So I think the same way we managed to onboard a heap of security researchers to comfortably review solidity code, we have to invest in training these people, onboarding more of them to focus on ZK primitives. And that's the type of stuff we do at CP. Uh shout out to Rare Skills who's uh hosted a week of collaborative learning.
Uh we sent a couple of our guys and you know they came back very excited about the future of securing ZK stuff.
Yeah, I mean if you want to look into the future of security and blockchain, it's definitely the one area that you should probably spend quite a lot of time on to be ready for when it comes.
It's such a core facet of it and especially as we get new users, developers, institutions like how do you view how do they view this? like from your understanding like how important is this for their operations uh when you're saying like institutions coming on chain etc like in your mind where does security lie in that
I mean it's it's critical um the time I spent in NYC last couple of weeks was a very strong reminder um that these institutions are looking really closely at how we tackle these problems we got to bear in mind that they have decades if not in some cases centuries of experience dealing with risk management, fraud prevention, secure design, right? We tend sometimes in our lovely bubble to discard all of that. But it was actually fascinating to hear how they think about these problems and they're looking at how we're responding and they're looking at it very closely and I believe some of them from the feedback I gathered are extremely extremely excited about one.
Yeah. Uh and I can say that from all the conversations I had with institutions, every single one of them said that security is the least concerned with regards to Ethereum. They very much understand that Ethereum is the most secure blockchain in the world and uh that's that's definitely being reflected by the choices they make when choosing where to deploy.
Awesome. Thank you both so much.
Thank you.
Thank you.
Automatic transcript — names and jargon may be misspelled.