On the 19th of November 2024, the ARDC Tally proposal was executed, marking the ArbitrumDAO’s decision to extend the ARDC with the launch of the ARDC V2. This iteration features a collaborative structure, comprising specialised working members in Research, Risk and Security, alongside a Supervisory Council. The program is designed to deliver ongoing, specialised specialised assistance to the ArbitrumDAO. For more details, see the executed proposal here: https://www.tally.xyz/gov/arbitrum/proposal/36792157050667056852025000136263368859227883753318633087194112219909798752014?govId=eip155:42161:0x789fC99093B09aD01C34DC7251D0C89ce743e5a4
Following a call for applications, a review process and an amendment period, conducted in accordance with the Election Process ratified by the ArbitrumDAO, the elections for the Arbitrum Research and Development Collective are now open. The full version of the applications can be viewed here:
We encourage all Arbitrum Delegates to vote responsibly and in the best interests of the ArbitrumDAO.
OpenZeppelin has been a foundational security provider in the blockchain ecosystem since 2016, with their open-source OpenZeppelin Contracts library being widely trusted and serving as the core infrastructure for secure smart contract development. Previous work with Arbitrum includes evaluating key governance upgrades, verifying proposal correctness, and conducting security design assessments for projects like Timeboost and BOLD. Their contributions to the Stylus Contracts Library further solidify their integration into the Arbitrum ecosystem, leveraging expertise in Stylus runtime.
OpenZeppelin’s approach to security includes fuzzing, and rigorous manual review that addresses vulnerabilities from multiple angles, even developing the Defender platform and being the only security provider to identify a critical vulnerability in their Uniswap V4 Audit. Having participated in the ARDC V1, OpenZeppelin carried out reviews of governance upgrades, verification of proposal correctness, and security design evaluations.
Specific work that we expect to complete within the first two months of the ARDC V2 program. Please note that some of these deliverables are time-dependent on the proposal details being ready for our security feedback within the 2-month time period.
Work that we expect to be ongoing depending on the current proposals and requests made to us throughout our ARDC term.
These deliverables address critical security needs and emphasize proactive upgrades and enhanced security governance. OpenZeppelin’s approach allows flexibility in addressing additional security tasks as ARDC’s term progresses. We are also open to additional feedback from other delegates and the guidance of the Supervisory Council, once elected.
Trail of Bits has been a leader in software security for over 12 years, combining cutting-edge security research with an attacker’s perspective to minimize risks and strengthen code. They have performed over 300 blockchain security reviews, dedicating 200+ engineer weeks of Arbitrum security reviews through their work with Offchain Labs, reviewing essential components such as Nitro, Timeboost Auction, Stylus, BoLD and the majority of ArbOS updates.
Trail of Bits excel in program analysis and tooling, as demonstrated by their numerous open-source projects, such as Slither, Echidna, Medusa, which combine a pragmatic approach and fundamental knowledge to create tools that provide value to their users. Setting them apart from other security consulting firms, Trail of Bits maintains a dedicated Research & Engineering division that integrates the latest advancements in security research into every project.
For the initial two months of the 6-month term, our services will include one or more of the following tasks, according to the priorities and needs of the ArbitrumDAO:
Trail of Bits has a robust, adaptive approach to executing projects, and our history of providing high-caliber security research and engineering solutions equips us well for managing ad hoc or flexible tasks, as requested by the Supervisory Council.
On the 19th of November 2024, the ARDC Tally proposal was executed, marking the ArbitrumDAO’s decision to extend the ARDC with the launch of the ARDC V2. This iteration features a collaborative structure, comprising specialised working members in Research, Risk and Security, alongside a Supervisory Council. The program is designed to deliver ongoing, specialised specialised assistance to the ArbitrumDAO. For more details, see the executed proposal here: https://www.tally.xyz/gov/arbitrum/proposal/36792157050667056852025000136263368859227883753318633087194112219909798752014?govId=eip155:42161:0x789fC99093B09aD01C34DC7251D0C89ce743e5a4
Following a call for applications, a review process and an amendment period, conducted in accordance with the Election Process ratified by the ArbitrumDAO, the elections for the Arbitrum Research and Development Collective are now open. The full version of the applications can be viewed here:
We encourage all Arbitrum Delegates to vote responsibly and in the best interests of the ArbitrumDAO.
OpenZeppelin has been a foundational security provider in the blockchain ecosystem since 2016, with their open-source OpenZeppelin Contracts library being widely trusted and serving as the core infrastructure for secure smart contract development. Previous work with Arbitrum includes evaluating key governance upgrades, verifying proposal correctness, and conducting security design assessments for projects like Timeboost and BOLD. Their contributions to the Stylus Contracts Library further solidify their integration into the Arbitrum ecosystem, leveraging expertise in Stylus runtime.
OpenZeppelin’s approach to security includes fuzzing, and rigorous manual review that addresses vulnerabilities from multiple angles, even developing the Defender platform and being the only security provider to identify a critical vulnerability in their Uniswap V4 Audit. Having participated in the ARDC V1, OpenZeppelin carried out reviews of governance upgrades, verification of proposal correctness, and security design evaluations.
Specific work that we expect to complete within the first two months of the ARDC V2 program. Please note that some of these deliverables are time-dependent on the proposal details being ready for our security feedback within the 2-month time period.
Work that we expect to be ongoing depending on the current proposals and requests made to us throughout our ARDC term.
These deliverables address critical security needs and emphasize proactive upgrades and enhanced security governance. OpenZeppelin’s approach allows flexibility in addressing additional security tasks as ARDC’s term progresses. We are also open to additional feedback from other delegates and the guidance of the Supervisory Council, once elected.
Trail of Bits has been a leader in software security for over 12 years, combining cutting-edge security research with an attacker’s perspective to minimize risks and strengthen code. They have performed over 300 blockchain security reviews, dedicating 200+ engineer weeks of Arbitrum security reviews through their work with Offchain Labs, reviewing essential components such as Nitro, Timeboost Auction, Stylus, BoLD and the majority of ArbOS updates.
Trail of Bits excel in program analysis and tooling, as demonstrated by their numerous open-source projects, such as Slither, Echidna, Medusa, which combine a pragmatic approach and fundamental knowledge to create tools that provide value to their users. Setting them apart from other security consulting firms, Trail of Bits maintains a dedicated Research & Engineering division that integrates the latest advancements in security research into every project.
For the initial two months of the 6-month term, our services will include one or more of the following tasks, according to the priorities and needs of the ArbitrumDAO:
Trail of Bits has a robust, adaptive approach to executing projects, and our history of providing high-caliber security research and engineering solutions equips us well for managing ad hoc or flexible tasks, as requested by the Supervisory Council.