Security Subsidy Program for Scroll Builders
- 0xc0c3...475d For515.76K SCR
- 0xaeb0...ec96 Abstain500K SCR
Auto-abstaining wallet is abstaining, as approved in the relevant proposal (https://gov.scroll.io/proposals/5409234667693180350061650128008163181727456255407133381292624146987676794170)
- 406.53K SCR
https://forum.scroll.io/t/proposal-security-subsidy-program-for-scroll-builders/872/36
- 0xdonpepe.eth For402.05K SCR
https://forum.scroll.io/t/0xdonpepe-delegate-thread/1041?u=0xdonpepe
- olimpio.eth For217.98K SCR
- the-monsters.eth For98.37K SCR
- 85.29K SCR
The Event Horizon Community voted For on this proposal (ehSCR-18): EventHorizon.vote/vote/scroll/ehSCR-18
- compound-dao.eth For70.04K SCR
- 0xea17...6676 For57.4K SCR
- 53.56K SCR
- gov.ethereumtgu.eth Against50.15K SCR
https://forum.scroll.io/t/ethereum-tgu-delegate-thread/292/14?u=ethereumtgu
- cypherlab.eth For46.3K SCR
- 41.52K SCR
- pgov.eth For40.46K SCR
- 34.9K SCR
- 30.81K SCR
- jensei.eth For30.35K SCR
after adjustments to the proposal I am in support
- 0x76e4...a876 For29.94K SCR
https://forum.scroll.io/t/lifeofdan-el-delegate-thread/186/12?u=lifeofdan-el
- seiryuu.eth For25.35K SCR
- 0x906f...0b0c For25K SCR
- connorm.eth For24.36K SCR
https://play.negationgame.com/s/scroll/rationale/gQXHoFWlQOayrvG9U1Tqy
- slobo.eth For24.25K SCR
- surybonfil.eth For22.78K SCR
- 0xb62e...e495 For22.07K SCR
Security Subsidies are a standard practice in most DAOs lately and are critical
- gov.blockful.eth For20.7K SCR
https://forum.scroll.io/t/proposal-security-subsidy-program-for-scroll-builders/872/37?u=blockful
- blid.eth For18.82K SCR
- 18.82K SCR
- aretagov.eth Abstain18.6K SCR
- 16.79K SCR
We strongly support the Security Subsidy Program as a crucial initiative to bolster the growth and resilience of the Scroll ecosystem. By offering financial support for security audits, this program helps builders overcome the often prohibitive costs associated with thorough security reviews. This enables developers to prioritize secure and reliable project development, which in turn enhances overall network trust and encourages broader adoption. We believe this subsidy will play an important role in fostering a safer, more robust environment for innovation within the Scroll community.
- zkcampus.eth For13.83K SCR
- mexi.wtf For12.75K SCR
- sparenberg.eth For12.73K SCR
- cypherbadger.eth For11.05K SCR
- 0x901d...fe7d For10.46K SCR
Vote Justification: https://forum.scroll.io/t/matt-exunico-delegate-thread/781/12?u=matt_factorylabs
- 8.47K SCR
- 0x8b58...69b7 For8.08K SCR
- 7.08K SCR
https://forum.scroll.io/t/proxy-prev-boardroom-delegate-thread/561/7
- leyzerok.eth For6.64K SCR
- 0x0d32...9179 For6.47K SCR
- aranadigital.eth For6.43K SCR
- 6.25K SCR
- benedictvs.eth For6.22K SCR
- 0xf5ca...15ff For5.32K SCR
- axianetwork.eth For4.78K SCR
- 4.42K SCR
- rgalet.eth For2.89K SCR
- ignasdefi.eth For2.68K SCR
- menaskop.eth For2.14K SCR
- 1.59K SCR
- kryptokat.eth For1.55K SCR
- 0x807b...34fc For972.34 SCR
- 0x617d...f695 For777.23 SCR
- 0xe73a...d125 For540 SCR
Ensuring Scroll projects have security checks will make the difference when talking about our ecosystem. Subsidies are a must for builders and to lower the risks for Scroll users.
- lexx77.eth For529.89 SCR
- 392.6 SCR
As a founder looking to build on Scroll, the fact that a subsidy exists to ensure the project has the security to succeed seems like a gem to me. It also contributes to improving the perception of the industry for the long term.
- unicircle.eth Abstain354.68 SCR
https://forum.scroll.io/t/proposal-security-subsidy-program-for-scroll-builders/872/34?u=fadhil
- 0x9b8f...e7e1 For216.41 SCR
- 0x09b17…9cb4b For110.86 SCR
- 0x31488…ea6d5 For102 SCR
- tweenky.eth For100.68 SCR
- jameskbh.eth For100 SCR
- 0xac236…28f59 For98.03 SCR
- 0x413a9…e1af3 For87.78 SCR
- 0x1fc8b…a933d For68.36 SCR
- 0x6cd4...8fcd For65.86 SCR
- 0x09a6...6bd9 For47.94 SCR
- 0x1a925…82d56 For44.87 SCR
- 0x73bca…3de09 For42.86 SCR
- 0x45e92…b448a For42.58 SCR
- 0xebdd8…668a9 For41.09 SCR
- 0xb62ff…92b83 For40.86 SCR
- 0x11a1a…43771 For39.87 SCR
- 0x72cac…986fd For39.19 SCR
- 0x926e7…080a2 For39.17 SCR
- 0x3f4b2…aeb93 For23.09 SCR
- 0xee49f…03a44 For10.72 SCR
- 0x2bcd...b5c3 For8.62 SCR
- 0x0579...4048 For6.01 SCR
This is a well-designed and crucial program for Scroll's long-term growth and reputation. It rightly treats security as a public good, making the entire ecosystem safer for both builders and users by lowering a significant barrier to entry. The investment structure is particularly smart, as it confirms projects are committed to building on Scroll and gives the DAO potential upside. Its focus on end-to-end security moves beyond simple audits to provide the continuous support that modern projects actually need.
- 0x94b0...077f For2 SCR
- 0x3aec...52a8 For0.39 SCR
- 0x6de1...2309 For0.2 SCR
- 0x22bf...9208 For0.12 SCR
- 0xfe1c6…8da0c For0.1 SCR
- 0xc554...7759 For0.08 SCR
This is a well-designed and crucial program for Scroll's long-term growth and reputation. It rightly treats security as a public good, making the entire ecosystem safer for both builders and users by lowering a significant barrier to entry. The investment structure is particularly smart, as it confirms projects are committed to building on Scroll and gives the DAO potential upside. Its focus on end-to-end security moves beyond simple audits to provide the continuous support that modern projects actually need.
- 0x69ed...c5c0 For0.07 SCR
- 0x757f...beb6 For0.06 SCR
- 0xca84...b66f For0.05 SCR
- 0x2bea...1065 For0.04 SCR
- 0x68e02…22c65 For0.04 SCR
- 0x44ec...4859 For0.03 SCR
- 0xcb156…aa1a0 For0 SCR
- 0x9baa...cb58 For0 SCR
- ethereumsingapore.eth1.22M SCR
- 0xf552...05cb190K SCR
- 0x6a5c...eda7184.34K SCR
- 0x9996...91f699.21K SCR
- 0x7dd1...a84d79.37K SCR
- fanyarachel.eth79.37K SCR
- 0x2ed2...97e471.5K SCR
- gov.borderless.eth48.07K SCR
- andruhakolotuha.eth27.14K SCR
- tonyolendo.eth27.09K SCR
- pólar.eth25.06K SCR
- socket.eth22.81K SCR
- not0xaa.eth20.9K SCR
- layer3xyz.eth19.97K SCR
- n0n4m3.eth17.71K SCR
- selvagrowth.eth14.6K SCR
- 0x45c2...f93d13.82K SCR
- janabe.eth13.59K SCR
- reall2scan.eth13.33K SCR
- gov.fireeyesdao.eth11.96K SCR
- zengjiajun.eth11.78K SCR
- hushhushcrypto.eth11.41K SCR
- 0x6056...a1a011.36K SCR
- nohcha.eth11.3K SCR
- launamu.eth11.17K SCR
- 0x680f...1cb511.14K SCR
- 0xa7b0...141611.05K SCR
- rostos.eth10.86K SCR
- pagodasia.eth10.85K SCR
- brefoo.eth10.58K SCR
- lucky-s.eth10.43K SCR
- cperezz.eth10K SCR
- 0x43f0...bd3310K SCR
- boxchen.eth10K SCR
- 0xe3fc...eb2010K SCR
- definidude.eth9.43K SCR
- 0xb88f...e7e29.2K SCR
- 0x1d78...e9968.63K SCR
- modularcryptoxyz.eth8.11K SCR
- 0xd2c9...25a97.3K SCR
- 0x19b0...5d8a6.94K SCR
- 0xdf2f...13826.93K SCR
- pseudotheos.eth6.66K SCR
- 0xde6c...a0856.19K SCR
- ethkipu.eth5.82K SCR
- 0x83f9...07845.24K SCR
- 0x77fb...e6935.22K SCR
- 0x955a...afc85.06K SCR
- 0x0338...943c4.88K SCR
- 0xe56d...4b284.75K SCR
- 0x5ac2...8ad94.63K SCR
- 0x058b...4c584.59K SCR
- 0xc1db...4c0c4.52K SCR
- 0xbb34...2f214.46K SCR
- 0x1b7a...08004.37K SCR
- 0x3c0e...7caa4.35K SCR
- 0xcc9d...20b44.23K SCR
- 0xe1ce...07264.2K SCR
- 0x8a69...08d34.19K SCR
- 0x7cd6...3e6f4.04K SCR
- 0x9cef...d6664.01K SCR
- jkm.eth4K SCR
- eurekagov.eth4K SCR
- dnkta.eth3.88K SCR
- 0x65f7...df783.88K SCR
- 0xfac9...f0703.73K SCR
- 0xa936...40803.72K SCR
- 0x2e4b...21773.64K SCR
- donofdaos.eth3.54K SCR
- drnick.eth3.5K SCR
- cicim.eth3.37K SCR
- 0x59a9...ac023.26K SCR
- 0x6631...99a43.18K SCR
- 0xbecd...3ad33.14K SCR
- memnuniy.eth3.03K SCR
- 0xa76c...b9443.01K SCR
- 0x9239...0b523K SCR
- 0xa10f...bb6c2.85K SCR
- 0x20df...d7142.78K SCR
- 0x4662...38542.76K SCR
- norin.eth2.71K SCR
- 0xc183...c78d2.68K SCR
- 0x8637...3c192.58K SCR
- 0x2250...1acd2.55K SCR
- 0xac3c...f8132.51K SCR
- 0x122b...5e462.5K SCR
- 0x3b24...11292.5K SCR
- 0x5a38...06152.5K SCR
- 0x67c8...3b2c2.5K SCR
- 0x70b2...f4e72.5K SCR
- 0x7773...881c2.5K SCR
- 0x84f9...1f092.5K SCR
- 0x88cc...3d4a2.5K SCR
- 0x8e72...479f2.5K SCR
- 0x98d6...a9dd2.5K SCR
- 0xa5c6...f09d2.5K SCR
- 0xb2f1...c51f2.5K SCR
- 0xd4a3...1a2d2.5K SCR
- 0xdd0d...43d42.5K SCR
- 0x9870...cc2f2.5K SCR
- 0xa84e...fe1c2.46K SCR
- 0x188c...2f282.43K SCR
- 0x2eea...775f2.32K SCR
- 0x00df...83382.23K SCR
- 0x5778...30792.23K SCR
- tanegov.eth2.19K SCR
- 0x59d8...347e2.18K SCR
- 0x8655...18c82.17K SCR
- 0x3ea8...c0ac2.16K SCR
- 0x5394...f2692.14K SCR
- 0xf57c...9e3b2.03K SCR
- 0x2230...33f72.03K SCR
- 0x6c37...250c1.99K SCR
- 0xa9f5...55471.98K SCR
- 0x0310...81261.92K SCR
- 0xa018...84d91.91K SCR
- 0x04db...46f31.88K SCR
- devansh.voicedeck.eth1.86K SCR
- 0x08c7...87a51.85K SCR
- 0x806b...ee9e1.85K SCR
- 0xe2e6...39421.8K SCR
- 0xd235...abaf1.76K SCR
- 0x2902...ac2f1.74K SCR
- 0xf570...43c51.73K SCR
- 0xb3ea...9bc71.73K SCR
- 0x2900...2d6b1.69K SCR
- 0x5ba9...b69c1.69K SCR
- hipposwap.eth1.68K SCR
- 0xd8dc...415b1.67K SCR
- 0xaf92...77aa1.6K SCR
- 0xcdd9...c3601.59K SCR
- 0x4ad7...9b4f1.57K SCR
- 0x5f36...35691.57K SCR
- 0xee16...c29a1.56K SCR
- 0xe791...d54a1.56K SCR
- nosana.eth1.55K SCR
- 0xd95a...61e21.54K SCR
- 0x945d...0bd51.49K SCR
- 0x0ab9...78ba1.47K SCR
- 0x01fb...ad811.46K SCR
- 0x4a81...73331.44K SCR
- 0xa75d...a5421.44K SCR
- 0x9887...788d1.43K SCR
- 0xbe00...89ed1.42K SCR
- 0x4c57...4c4d1.4K SCR
- 0x4f5f...8c3d1.38K SCR
- 0x7140...ce071.38K SCR
- 0x3f10...ada91.36K SCR
- 0x0014...00411.36K SCR
- 0x429f...88921.34K SCR
- 0x4a37...c0921.34K SCR
- 0x38d4...44981.31K SCR
- 0xa60f...f62b1.31K SCR
- 0x872e...e1491.3K SCR
- 0xd95b...1aa11.3K SCR
- 0x96cd...97661.3K SCR
- 0x58a8...2e3c1.28K SCR
- 0xedfd...6d751.28K SCR
- 0xa7f3...a23e1.27K SCR
- 0xa0b2...df471.27K SCR
- 0x40a0...cb451.27K SCR
- 0x7bb3...9fc01.25K SCR
- 0xadbb...276c1.25K SCR
- 0x151a...e3061.23K SCR
- 0xa772...61711.23K SCR
- 0x599c...4d4f1.21K SCR
- 0x9404...e81d1.2K SCR
- 0x5c54...cf6f1.18K SCR
- 0x7148...045e1.13K SCR
- 0xb352...22861.12K SCR
- 0xb08c...83fa1.11K SCR
- 0x9ac7...40bd1.11K SCR
- 0xc5e7...60631.1K SCR
- 0xcf48...38c51.09K SCR
- 0xff06...cb3a1.09K SCR
- 0x1ce7...758b1.07K SCR
- 0x6881...228a1.05K SCR
- 0x2f80...2bb41.05K SCR
- 0xa4eb...31af1.03K SCR
- 0x9516...09ca1.01K SCR
- 0x6f92...013c1.01K SCR
- 0x54a0...25a31K SCR
- 0x25b6...02961K SCR
- 0xbb59...f25e1K SCR
- 0x1aae...fbc1997.64 SCR
- 0x3c35...570d991.93 SCR
- 0x495d...b019989.8 SCR
- 0x0696...6a0f989.62 SCR
- 0x585a...8588950.48 SCR
- 0xed72...ad9d943.74 SCR
- 0xf5ab...2617939.78 SCR
- 0x9304...56ba939.15 SCR
- 0x87c9...b948929.7 SCR
- 0x7999...c5b6918.55 SCR
- 0xe877...0062918.03 SCR
- 0x0ad9...e678913.75 SCR
- 0x7cb0...af1f905.9 SCR
- 0xadab...20ce900.97 SCR
- 0xff3f...4528896.5 SCR
- 0xdcc0...16df890.32 SCR
Top 200 of 1,130 delegates with voting power, by current VP.
Security Subsidy Program for Scroll Builders
Proposal Type: Growth
Forum discussion can be found here.
Summary:
This proposal introduces a pilot Security Subsidy Program for providing comprehensive onchain security for projects committed to building on Scroll, geared towards projects graduating from Scroll Open.
It is structured into two core components with an extra critical support component:
-
- Access to subsidized audit services via Areta’s open audit marketplace.
-
- Access to a discounted and subsidized onchain security marketplace managed by Immunefi for end-to-end protection beyond traditional audits, from pre-deployment through post-launch.
-
- Governed by mechanisms to ensure commitment to build on Scroll and prevent subsidy farming.
Funding Request & Support:
- Requests the SCR equivalent to $500k USD, with $300k dedicated to audit subsidies to be used in Areta’s open audit marketplace and $200k to the end-to-end security marketplace run by Immunefi.
- To be coordinated by Immunefi in collaboration with the newly-formed Ecosystem Growth Council and Scroll Labs, with oversight by the Scroll Foundation. Scroll Labs and the Foundation have final say over the eligibility of projects and over the marketplace offerings.
Expected Outcomes:
- Subsidize audits and related pre-launch and post-launch security services for eligible Scroll-native projects, covering up to 100% of audit costs and up to 75% of end-to-end security services, with an additional 25% discount on those end-to-end services, i.e. an effective subsidy of 100%.
- Discounted access (on top of the subsidies) to best-in-class providers across the security stack.
- Eliminate the burden of discovering and vetting the right security suppliers and tooling.
- Reduce the need to hire large internal teams to get effective security through a project’s life cycle.
- Reduce the cost hurdle to build a secure tech stack required to develop trust amid end-users.
- Improve the overall speed to market of the projects participating in Scroll’s Open Economy.
- Improve the attractiveness of the Scroll ecosystem to new builders deciding where to build.
- Improve the overall security practices and security culture within the Scroll ecosystem.
Motivation:
L2 security is critical yet often misunderstood. As L2s compete to attract builders and scale the EVM, it’s increasingly important to build trust across all ecosystem dimensions. For that, audits are an industry standard and a non‑negotiable best practice. Every project that launches on mainnet needs an audit.
However, modern on-chain security transcends audits, requiring tailored solutions focused on the various needs emerging from a complex code security lifecycle. This is because countless projects suffered devastating hacks after assuming audits were sufficient:
- Consider Immunefi’s statistics: among the roughly 500 projects that launched bug bounty programs there, nearly all had been audited previously, often multiple times.
- Yet, Immunefi’s community of security researchers has surfaced critical bugs in 80% of its bug bounty programs in the first year after launch.
- Consider the May 2025 hacks of Cetus on Sui or of Cork Protocol on Ethereum, with both projects having undergone multiple audits by reputable providers.
- Still, edge cases that were either considered out of scope or overlooked during the audits caused tens of millions in losses, showing how end-to-end security is key.
Scroll hasn’t assumed audits are sufficient, being well aware that “security is a continuous journey”. This has resulted in various positive outcomes from at least one of its always-on security programs:
- Scroll’s bug bounty program has awarded a $1M bounty to one of Immunefi’s elite security researchers in May 2025 for a bug found this April.
- Scroll’s own report acknowledged that, “if exploited, this vulnerability would allow an attacker to essentially mint an arbitrary amount of ETH or any ERC20 tokens on L2”.
- Overall, we have been authorized to share that Scroll’s bug bounty program with Immunefi helped report 4 critical bugs and 1 bug classified as high severity so far.
Now, as demonstrated by the Cetus hack on Sui, Scroll should extend this approach to its ecosystem. Given that Scroll is already committed to hard-wire security into its culture from the outset, this would:
-
Guarantee every eligible project undergoes a code review before launch.
- While also offering essential access to pre-deployment and post-launch security tools as per modern best practices that are rarely followed due to their perceived high costs.
-
Ensure access to competitive pricing through marketplace dynamics across the security stack.
- While benefiting from additional discounts from on top of the proposed subsidies.
-
Grant free-of-charge access to a suite of AI-driven security features and tooling available on the Immunefi Magnus platform during the duration of the program to its projects.
- While incentivising and regulating eligible projects to avoid subsidy farming.
With this program, Scroll ends up protecting its users, safeguarding its brand integrity, and sending a clear signal to builders and investors that it is the right place to innovate and scale. All in a streamlined manner that maximizes security outcomes for each dollar spent across the ecosystem.
Execution:
Operational:
This proposal recommends partnering with an established player with proven experience in crowdsourced onchain security to coordinate the Security Subsidy Program, Immunefi.
The subsidy funds will be allocated to two marketplaces: Areta Market and Immunefi Magnus.
About Immunefi:
Immunefi is the leading onchain security platform, offering a comprehensive suite of services through its Magnus marketplace to more than 350 leading protocols and dapps. In just over four years, it has directly prevented hacks worth over $25 billion USD and its community of Security Researchers was awarded +$120 million USD for responsibly disclosing over 5,000 web2 and web3 vulnerabilities.
Today, Immunefi works with leading projects including Sky (formerly MakerDAO), Optimism, Polygon, GMX, Chainlink, TheGraph, Lido, LayerZero, Arbitrum, StarkNet, EigenLayer, Astar Network, ZKsync and more, all publicly available on the website. It’s also a proven security partner to other large ecosystems:
- Whitelisted for Arbitrum’s Security Subsidy Fund and current Arbitrum Security Council Member to both secure what is built on Arbitrum and Arbitrum itself.
- Selected by Plume as the end-to-end security partner to support the secure scaling of its full-stack RWA L1 blockchain and ecosystem through Immunefi’s Magnus platform and marketplace.
- Optimism Growth Cycle and Retro Public Good Funding Grant Recipient for helping to ensure the security of the Optimism ecosystem.
- Ran the Binance Smart Chain Priority One joint Bug Bounty Program funded with $10M which supported 100 dApps over one year, including PancakeSwap.
- Ran the Nexus Mutual Bug Bounty Matching Program, saving the industry's largest insurer from major losses on well-known protocols such as Yearn.
- Ran the Algorand Ecosystem Bug Bounty Matching Program where the Algorand Foundation matched all ecosystem bounties up to US$100,000, thus further securing the Algorand ecosystem.
- Created the Immunefi Security Core Unit (IS-001) within MakerDAO to provide in-depth security to the Maker ecosystem. This included thorough identification of the critical infrastructure of the ecosystem, operational security audits for the core units, fire drill management and execution for the platform, and on-call security advisory, on top of active management and high-precision customized creation of the bug bounty program to ensure it reflected Maker’s security needs.
Magnus, Immunefi’s unified security marketplace, helps a project's security team deal with tool overload, blindspots and ever evolving threats. Teams can manage security engagements through a single command center — from triaging findings and PR reviews to vendor and payment management:
- Magnus integrates end-to-end onchain security solutions from multiple partners.
- Combining in-house tools built by Immunefi with tooling delivered by best-in-class firms.
- Already onboarded Runtime Verification, Failsafe, Fuzzland and ChainPatrol, as well as Nexus Mutual, Dedaub, OtterSec and ThreeSigma. More soon.
- Leveraging Immunefi’s proprietary vulnerabilities dataset, the industry’s largest.
- And aggregating a community of over 45,000 security researchers.
- Combining in-house tools built by Immunefi with tooling delivered by best-in-class firms.
- With a few clicks, projects can post a service request on Magnus and invite providers to match against technical and budget requirements.
- In addition to audits and crowdsourced security, these experts provide infrastructure audits in non-mainstream languages, fuzzing and formal verification, real-time monitoring, incident response, and operational security war gaming (emergency preparedness).
About Areta Market:
Areta Market is the leading marketplace solution for security audits. The product has been launched on Arbitrum and Uniswap and has facilitated over $35M in audit offers to date. It is a white-label tech solution that can be used by any party chosen by the Scroll DAO to manage subsidies.
Program Overview
This Security Subsidy Program proposal rests on two core components: 1) traditional audits and 2) end-to-end onchain security.
-
- The traditional audits component is focused on the following offering:
- Traditional audits: standard code reviews typically lasting between 3 days to 3 weeks.
Traditional audits are to be delivered through the Areta Market marketplace.
-
- The end-to-end onchain security component is focused on the following offering:
- Fuzzing: automated smart contract testing with variable inputs to detect bugs.
- Formal verification: mathematical proof of whether a smart contract is up to specifications.
- Pull-request reviews: streamlined code reviews from the very best security researchers embedded directly in the GitHub pull requests on the Magnus marketplace.
- Audit competitions: crowdsourced, time-bound code review with a fixed prize pool for valid reports, typically lasting one to three weeks.
- Bug bounty programs: incentivised, always-on program for security researchers to responsibly disclose vulnerabilities combined with a 24/7 managed triage service to filter through submitted reports together with active program monitoring and expert set-up.
- Real-time monitoring & threat prevention: detect and optionally intercept malicious transactions in the mempool before they get executed.
These are delivered through Immunefi’s Magnus marketplace and include free access to a suite of AI-driven security features for the duration of the Security Subsidy Program. This entails an AI-powered security copilot that can be privately trained on each project’s unique infrastructure and is powered by Codexa, the most comprehensive dataset of blockchain vulnerabilities in the industry.
The two components above are supported by a couple of mechanisms to ensure commitment to build on Scroll and prevent subsidy farming. This point was inspired by recent research conducted by RnDAO, delegate feedback and work developed by Areta to overcome similar issues as faced in other ecosystems.
-
- The commitment component is focused on the following mechanisms:
- Rating criteria to inform the evaluation of the applications.
- This framework is detailed further below in the proposal.
- Subsidies are distributed as investments instead of grants.
- This process is detailed further below in the proposal.
- An exclusivity clause for code audited under this program.
- This process is detailed further below in the proposal.
These ensure projects attracted to build on Scroll with this program are i) incentivised to remain and ii) those graduating from Scroll Open are motivated to continue advancing the open economy.
Moreover, note the Security Subsidy Program has a separate budget for each of the components which is unlocked per application and on a per product basis, detailed in the summary and in the financial section.
- This means each project can benefit from the products and services that best fit its specific security needs in the development lifecycle as opposed to a standard cookie cutter approach — maximising security outcomes for projects and for the Scroll ecosystem.
- To further reduce the risk of funds misuse, unused funds at the end of the program will either be returned to the DAO treasury or rolled into a renewed program, pending delegate approval.
Mechanisms to ensure commitment to Scroll
The commitment component outlined above should be driven by three mechanisms that work together to drive the long-term growth of the Scroll ecosystem and prevent abuse of grants with no strings attached.
A). Rating criteria framework to inform the evaluation of applications
a). Rating sheet with up to 10 possible points and a required grade of 6 to qualify.
1. 2 points — Existing fit with the Scroll ecosystem.
1. 0 points - no fit, e.g. no development on Scroll yet.
2. 1 point - some fit, e.g. graduating from Scroll Open.
3. 2 points - strong fit, e.g. project building on Scroll for > 6 months.
2. 2 points — Business plan.
1. 0 points - poor plan, e.g. no clarity, excessive scope.
2. 1 point - good plan, e.g. granular plan, realistic.
3. 2 points - strong plan, e.g. investment-worthy.
3. 2 points — Team qualifications.
1. 0 points - Weak team, e.g. lone individual with minimal to no industry background.
2. 1 point - reasonable team, e.g. co-founders with some industry background.
3. 2 points - strong team, e.g. mature team with extensive industry background.
4. 4 points - Value for Scroll.
1. 0 points - no alignment, e.g. no link to Scroll’s current plans.
2. 1 points - weak alignment, e.g. intangible link and some metrics.
3. 2 points - medium alignment, e.g. direct link and clear metrics.
4. 3 points - strong alignment, e.g. all the above and community support.
5. 4 points - excellent alignment, e.g. all the above and good optics.
b). This grading is an informative framework for pre-screening purposes. Final assessment shall be led by the Scroll Foundation, which will ensure that at least Scroll Labs or the newly-formed Ecosystem Growth Council will also provide input for any given application.
i). Moreover, the Scroll Foundation and Scroll Labs can pre-approve projects for any subsidy under this program.
B). Subsidies as investment contracts
a). Instead of handing out one-off grants, we propose to align the long-term goals of the recipient projects to those of the Scroll ecosystem by structuring the subsidies as investment contracts to the exclusive benefit of the Scroll ecosystem, through an entity to be managed by the Scroll Foundation. The model for these contracts is inspired by RnDAO’s approved agreement with the Arbitrum Foundation, with equivalent documents to be developed with the EGC once it’s formed.
i. That would be a legal document covering three scenarios:
1. Equity fundraising through a SAFE.
2. Token launch through a token warrant.
3. A side letter in case there’s no fundraising nor a token.
ii. This will grant a minority stake in the subsidy recipients proportional to the risk taken by Scroll with this program as per the final assessment of each project’s application, which will be done by the Scroll Foundation.
1. 1% for projects with 9 or 10 points.
2. 1.5% for projects with 7 or 8 points.
3. 2% for projects with 6 points.
iii. With an estimated average audit subsidy of $30k and average onchain security subsidy of $20k, this equates to an average investment of $50k in 10 projects.
1. While the minority stake percentage may seem low, this ensures any fundraising efforts aren’t hindered while allowing to recoup an investment in any project that reaches a minimum valuation of $2.5 to $5 million USD.
b). The legal entity shall be incorporated under the Scroll Foundation, pending legal review.
C). Exclusivity clause
a). Finally, to further promote long-term commitment to Scroll, the investment contracts will have a clause to ensure all code audited under this program must remain exclusive to the Scroll ecosystem for a fixed period, to be defined together with the Scroll Foundation. b). In cases of breach, legal action will be enforced against the project.
Program Phases:
In terms of structure, the Security Subsidy Program consists of three phases:
Phase 1: Program Setup (Month 1 — Sept.)
- (Week 1): Form election committee and validate application form.
- (Week 2): Validate investment vehicle structure with the Scroll Foundation and any relevant stakeholders.
- (Weeks 3–4): Open call for project applications according to the eligibility requirements.
- (Week 4): Vetting and selection of projects as per the requirements and criteria.
- (Week 4): Onboarding workshop, security best practices sessions and marketplace walkthrough.
Phase 2: Traditional Audits and End-to-End Onchain Security (Months 2 - 6 — Oct. to Mar.)
- (Month 2 onwards): First code reviews can begin for selected projects.
- (Month 2 onwards): Additional onchain security services (e.g. PR reviews, audit competitions, bug bounty programs, monitoring) can kick-off through the Magnus marketplace.
- (Month 2 onwards): Open call for projects to apply according to the eligibility requirements.
- (Month 2 onwards): Ongoing vetting and selection of projects as per the requirements and criteria.
Phase 3: Program review (Months 3-6 — Nov. to Mar.)
- (Month 3 onwards): Oversee the quality of the deliverables and report back to the DAO at the end of the 3rd and 6th month of the program.
The Security Subsidy Program may be renovated at the end of the term depending on performance and desire of the community, subject to an updated governance proposal.
Note that even though the Security Subsidy Program’s applications are only open for five months, the projects can benefit from these security products and services for up to one year. For example, an audit competition can be contracted at the end of the program to start a few months later. PR Reviews, bug bounty programs or real-time monitoring can be contracted anytime for a period of 12 months.
Personnel & Resources:
Below are the proposed personnel and their roles:
- Immunefi:
- Program Facilitator: Lead project vetting process in coordination with the Ecosystem Growth Council, conduct onboarding sessions and marketplace walkthrough.
- Recruitment and Onboarding: Launch open calls to onboard more qualified security firms and security researchers to Magnus. Launch open call for the first cohort of Scroll-native projects.
- Program Coordinator: Oversee the implementation of the Security Subsidy Program in alignment with Scroll’s ecosystem growth goals and security standards.
- Marketplace Operator: Facilitate a competitive open marketplace for auditors, security researchers and security firms to participate in audit engagements and security programs.
- Coordination with Ecosystem Growth Council: Work in collaboration with the Ecosystem Growth Council to align technical execution and ensure projects are supported end-to-end.
- Ongoing Operational Management: Monitor engagement quality, track deliverables, and coordinate communications between projects and providers across both phases of the program.
- Co-marketing efforts coordinator: Ensure the subsidy recipients promote the Security Subsidy Program appropriately, while also fostering co-marketing initiatives with the Program’s partners.
- Quarterly Transparency Reporting: Produce and publish a quarterly transparency report summarizing completed audits, active services, key findings, and overall impact of the program.
- Ecosystem Growth Council:
- Project vetting: Participate in the project vetting process in coordination with Immunefi.
- Coordination with the Scroll Foundation: Engage in the application assessment process.
- Scroll Labs:
- Project vetting: Participate in the project vetting process in coordination with Immunefi.
- Coordination with the Scroll Foundation: Engage in the application assessment process..
- Scroll Foundation:
- Subsidy Program Oversight: Liaise with Immunefi and with relevant stakeholders to ensure the program’s goals are met.
- Subsidy Program Funding Operations: Operate the investment entity that will disburse the security subsidies as investment contracts.
Finance:
The traditional audits component represents the bulk of the financial investment, given the mature nature of that market. Within this component, audit providers offer market rates to be subsidized by the Security Subsidy Program up to 100%, up to a $50k cap, with projects paying at least 10% of the audit cost to ensure they remain committed to the code review process. Projects are also required to engage in co-marketing activities to be coordinated by Immunefi, as detailed in the Roles section. This process follows the public learnings from previous subsidy funds with Arbitrum and Uniswap.
Within the end-to-end onchain security component, eligible marketplace providers offer a 25% discount, with the Security Subsidy Program subsidising them up to 75%, on a case-by-case basis. Moreover, Immunefi is offering free access to the Magnus marketplace and platform for a period of 6 months to all eligible projects. This includes a proprietary and private AI-powered security co-pilot.
The budget for this Security Subsidy Program shall then amount to $500k, based on the estimated costs to serve a significant portion of the projects graduating from Scroll Open, distributed as follows:
| Expense Category | Cost (USD) | Budget allocation |
|---|---|---|
| Traditional audit subsidies | $300,000 USD | $300k for audits for up to 10 projects — an average 75% subsidy for an average audit cost of $40k (roughly half of Arbitrum’s ADPC average audit cost) |
| End-to-end onchain security subsidies | $200,000 USD | Funds are unlocked per application and per product based on each project’s security needs, to be allocated in coordination with the Scroll Foundation. |
| Total | $500,000 USD | Current SCR equivalent at the time of the proposal. |
As shown in the budget above, this program has no OpEx as it will be run by Immunefi for the benefit of the Scroll ecosystem. Immunefi is directly and indirectly compensated, being a participant in the Areta Market marketplace for audits and being an operator of the Magnus marketplace.
SCR conversion shall be coordinated by Scroll’s upcoming treasury management provider. Until then, funds will be held at a multisig managed by the Scroll Foundation.
Unused funds at the end of the six-month period will either be returned to the DAO treasury or rolled into a renewed program, pending delegate approval.
Lastly, for additional context, here’s an overview of the typical market rates for each of the services included in the Security Subsidy Program (SSP), and the respective offer for Scroll ecosystem projects.
| Product and services | Market rates | Subsidy program rates |
|---|---|---|
| Traditional audits | Typically from $15k to $150k. | 50% to 100% subsidy, $50k cap per project up to 8 projects. |
| Fuzzing | Not enough data to estimate. | 25% vendor discount, up to 75% subsidy. |
| Formal verification | Not enough data to estimate. | 25% vendor discount, up to 75% subsidy. |
| Pull request reviews | Contingent on the scope of the code review. | 1 complimentary PR review per project up to 10 projects, then 25% vendor discount, up to 75% subsidy. |
| Audit competitions | Typically 15% to 25% of the rewards pool. | No fees up to $50k rewards pool, up to 50% subsidy on reward pools capped at $25k for up to 2 projects. |
| Bug bounty programs | $20k to $60k per year. | No bug bounty hosting fees for up to 10 projects for 1 year, assisted program design, safe harbor module and 25% discount on bug bounty programs with managed triage service add-on. |
| Real-time monitoring | Not enough data to estimate. | 25% vendor discount, up to 75% subsidy. |
Success metrics:
- At least 75% of the projects undergoing the program launch on Scroll within 6 months.
- At least 50% of the projects undergoing the program generate revenue within 6 months.
- At least 75% of the projects undergoing the program successfully fundraise within 12 months.
- At least 50% of the projects undergoing the program continue to build on Scroll within 12 months.
Conclusion:
The Security Subsidy Program is both urgent and foundational: it slashes security risk while accelerating time-to-launch for Scroll-native teams. This program gives Scroll and its projects an unique opportunity to access proven security outcomes with streamlined processes and long-term alignment.
Passing this proposal signals that the Scroll community is serious about retaining builders and securing TVL beyond just audits. With the full lifecycle security supported by Magnus, projects can iterate fast and scale confidently, protected by industry-leading bounties and precise, automated threat detection tools.
This proposal will break down barriers to secure deployment, fast-track project launches and deliver seamless best-in-class ongoing onchain security for early-stage Scroll teams — before and after going live. We welcome your questions and look forward to fortifying the ecosystem together.
Proposed Actions
This proposal does not execute any transactions onchain.
Voting over time
92 votes over the voting period
Proposal ID 9105421435… · data from on-chain Governor + SCR token (Scroll mainnet RPC) — durable source of truth