Ethereum Foundation's 10-year bug bounty program: Security lessons | Fredrik Svantes episode artwork

EPISODE · Aug 19, 2025 · 1H 2M

Ethereum Foundation's 10-year bug bounty program: Security lessons | Fredrik Svantes

from The Web3 Security Podcast · host TheWeb3SecurityPodcast

Fredrik Svantes evolved from hunting World of Warcraft gold farmers to securing Ethereum's trillion-dollar ecosystem as the foundation's Security Research Lead. Running the world's oldest blockchain bug bounty program while spearheading initiatives to make Ethereum safe for both billion-user adoption and institutional trillion-dollar deployments, he offers rare insights into the security challenges of protecting critical infrastructure at unprecedented scale. His contrarian stance on replacing reactive blacklists with protocol-level whitelists, combined with hard-won lessons from coordinating the merge and subsequent upgrades, reveals how Ethereum balances decentralization with protection. From managing AI spam in bug reports to designing crowdsourced audit competitions, Fredrik's approach shows how to secure systems when traditional methods simply don't scale.   Topics discussed: $2 million audit competitions mobilizing hundreds of researchers across 10+ client implementations in different programming languages. Filtering AI-generated vulnerability spam in bug bounty programs using staking requirements and pattern recognition techniques. Trillion-dollar security initiative metrics: billion people holding $1,000 safely vs institutions deploying trillion-dollar smart contracts. Hard fork security procedures with assigned team roles following the Holesly testnet configuration incident. Protocol-level whitelists replacing reactive blacklists to eliminate entire vulnerability categories proactively. Reducing Ethereum Foundation dependencies through ecosystem-sponsored security programs across multiple entities. UX as Web3's critical weakness requiring iOS-level polish with guardrails that maintain decentralization principles.

Episode metadata supplied by the publisher feed · Published Aug 19, 2025

Embed this episode

Ready to play

Ethereum Foundation's 10-year bug bounty program: Security lessons | Fredrik Svantes

0:00 1:02:25

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Web3 Security Podcast?

This episode is 1 hour and 2 minutes long.

When was this The Web3 Security Podcast episode published?

This episode was published on August 19, 2025.

Can I download this The Web3 Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!