FINAL - Celo SHIELD - Subsidized Help for Improving Ecosystem-Level Defense
Proposal Key Aspects
- Receiver Entity: Celo Governance / Celo Public Goods
- Status: FINAL
- Title: Celo SHIELD - Subsidized Help for Improving Ecosystem-Level Defense
- Author(s):
- Type of Request: Funding
- Funding Request: 450,000 cUSD
Summary
Celo SHIELD Overview
The Security Team at cLabs proposes an initiative to subsidize the cost of security services to Celo ecosystem partners. This pro bono initiative will involve collaboration with leading security vendors to provide on-chain monitoring, automated security testing, brand protection, security architecture reviews, anti-money laundering (AML) compliance, and software supply chain security. We aim to leverage industry-leading practices and provide tools that empower partners to adopt and improve their security postures, reducing the risk of exploits that could impact the broader ecosystem.
The funds will be used to pay for third-party security services, for qualifying Celo projects, at no or discounted expense.
The proposed funding for this initiative is 450,000 cUSD to be distributed over a 1-year period, from January 2025 to December 2025.
Motivation
Web3 lost over $2 billion to hacks in 2024 alone. Every security incident in our ecosystem directly impacts CELO value and erodes user trust. This has a ripple-effect through every project building on Celo.
Traditional security reviews exceed $150,000 per project, forcing most teams building on Celo to choose between proper security and core development. This isn’t just about individual projects, it’s about protecting Celo’s entire ecosystem.
The urgency of this proposal is driven by three critical factors:
- Attack sophistication is rapidly evolving. Next-generation Financial Technology must be implemented with effective security testing.
- Regulatory pressure is constantly changing with authorities scrutinizing blockchain security more than ever. Security incidents attract unwanted regulatory attention, while proactive security measures demonstrate ecosystem maturity.
- Security has become a key differentiator for ecosystem growth, as leading chains strengthen their security posture and projects choose platforms partly based on security support.
This initiative transforms security from a luxury into a standard feature of building on Celo and aims to:
- Foster development on Celo by allowing projects to focus resources on development while maintaining security
- Make enterprise-level security services accessible to Celo ecosystem projects
- Reduce the financial barrier to implementing robust security measures
- Provide specialized Web3 security awareness training
- Protect user funds and maintain ecosystem trust
Specification
Program Structure
The program will operate on a first-come-first-served basis with additional rewards for projects that have already implemented security controls. Key components include:
Services Offered:
- Smart Contract & Wallet Security: Focusing on automated vulnerability scanning, smart contract security analysis, and wallet integration security. This foundational service helps projects secure their core smart contract infrastructure and user interaction points. The service includes gas optimization analysis and upgradability pattern security reviews.
- Brand Protection Services: Providing comprehensive brand security services to prevent spoofing attacks, phishing attempts, and reputation damage. This service helps maintain user trust and ecosystem integrity through continuous monitoring and protection of project digital assets.
- Attack Surface Monitoring: Implementing continuous scanning and monitoring of cloud infrastructure vulnerabilities, exposed API endpoints, and configuration issues. This service ensures projects maintain a secure operational environment.
- Sequencer Level Attack Monitoring and Prevention: On-chain security controls to alert on or block malicious actions.
- Secrets & Supply Chain Security: Monitoring for accidentally exposed API keys or service account credentials in public source code. Additionally, the service includes scanning for vulnerable dependencies in the software supply chain, ensuring secure development practices.
- Secure Deployment Workflows: Analyzing and securing deployment processes, focusing on preventing malicious, insecure, or inadequate automated workflows. This service helps projects maintain security throughout their development pipeline.
- Static Application Security Testing: Providing automated security scanning tools specifically designed for smart contract code, helping projects identify potential vulnerabilities early in the development cycle.
- Competitive Bug Bounty Programs: Supporting projects in establishing and maintaining bug bounty programs to incentivize responsible vulnerability disclosure and ecosystem security improvements.
- Security Program Reviews: Offering comprehensive security program assessments to ensure no critical assets remain at high risk, providing strategic guidance for security implementation.
Expenditure Breakdown ( amounts in cUSD )
- Smart Contract, Wallet, and WebApp Security Review 120,000
- Brand Protection 50,000
- Attack Surface Monitoring 45,000
- Sequencer Level Attack Monitoring and Prevention 25,000
- Secrets Management 45,000
- Supply Chain Security 20,000
- Secure Deployment Workflows 20,000
- Static/Dynamic Security Testing 40,000
- Competitive Bug Bounty Program 60,000
- Security Program Review 15,000
- Program Administration 10,000
- Total 450,000 cUSD
Timeline and Milestones
Phase 1: Program Setup (Q1 2025)
- Program infrastructure setup
- Security vendor onboarding
- Application process launch
- Community awareness campaign
Phase 2: Initial Partner Enrollment (Q1-Q2 2025)
- First batch of partner applications
- Initial security assessments
- Service implementation begins
- First monthly report publication
Phase 3: Full Program Operation (Q2-Q4 2025)
- Continuation of partner onboarding
- Service delivery and monitoring
- Monthly reporting and community updates
- Mid-program assessment and adjustments
Phase 4: Evaluation and Planning (Q4 2025)
-
Program impact assessment
-
Community feedback collection
-
Sustainability planning
-
Renewal proposal preparation
-
Implementation & Governance *
Partner Selection Process
- Open application process through Celo Forum (TBD)
- Clear eligibility criteria published
- Monthly batch processing of applications
- Bonus structure for existing security implementations
Fund Management
- 2/3 Multisig structure:
- cLabs Security Lead
- cLabs Project Manager
- cLabs Security Engineering
- Monthly budget reporting
- Quarterly audits
Metrics and KPIs
Key Performance Indicators:
- Number of Partners Onboarded: Successfully onboard at least 10 partners within the first three months.
- Reduction in Vulnerabilities: Reduction in the number of vulnerabilities identified by scanning tools by 30% by the end of the project.
- Competitive Bug Bounty Participation: At least 20 bug bounty submissions, with 5 critical vulnerabilities addressed.
- Partner Satisfaction: Gather feedback from partners; aim for an average satisfaction score of 7/10 or higher.
- Security Maturity: Increase in overall security maturity scores from a scale of 1 to 5 for at least 70% of the participating projects, with a target of moving projects from an average score of 2 to an average score of 4 by the end of the program.
Reporting Structures:
Monthly Updates:
- Partners onboarded
- Services utilized
- Security metrics
- Budget utilization
Quarterly Reports:
- Comprehensive impact analysis
- Success stories
- Security trends
- Program adjustments
Current Status
This is a new initiative.
Payment Terms
Fund Distribution:
- Initial transfer: 225,000 cUSD (Upon approval)
- Second transfer: 225,000 cUSD (End of H1 2025, subject to milestone completion)
Multisig Address: 0x35ff861a0b6215CeC71EA282B0D32AfefA661795
Signers:
- cLabs Security Lead: Benjamin Speckien (@ben) 0x48739572951F5bdb2CAC71BfF1Fc0747266C816e
- cLabs Project Manager: Nikolaos Frestis (@gloec) 0x2835cd3C9e5aD93C10eBFAcEc943fE1006B1F57a
- cLabs Security Engineer: Sefan Ioja (@si-csec) 0x32Af2978880CD100d6Afa1104e8d01554bFe5bD4
Team
Benjamin Speckien, acting currently as Head of Security for cLabs, has over 20 years experience in Security/IT. He has worked across the Celo Ecosystem with over 40 partners, implementing security controls and designing solutions. Benjamin holds a Master of Science in Cybersecurity and is CISSP certified.
Nikolaos Frestis has an extensive background in Information Security Project Management across the pharmaceutical and crypto-banking sectors. He maintains close relationships with security vendors in Web3 and has interviewed many people developing on Celo. Nikos currently acts as Project Manager for the cLabs Security Team.
Stefan Ioja is a Security Engineer at cLabs. He implements and maintains industry-leading security solutions, is well versed in the threat landscape of Web3, and is an expert in Incident Response. Stefan is skilled with maturing security posture, efficiently.
Additional Support/Resources
Feedback from the community is appreciated but not required.