The Ethereum Foundation’s Protocol Security Research Team announced the start of a four-week audit contest for the Fusaka network upgrade on September 15, 2025. Hosted by security platform Sherlock and co-sponsored by Gnosis and Lido, the competition advertised a maximum reward pool of $2 million for researchers who identified qualifying vulnerabilities before the code reached Ethereum’s production network.

The opening mattered because Fusaka was not an application running above Ethereum. It was a planned change to the protocol itself, spanning software maintained by multiple execution- and consensus-layer client teams. A defect capable of producing inconsistent behavior between implementations could affect network availability or consensus. The contest broadened review beyond the developers already building and testing the upgrade.

Paying for adversarial review

The Ethereum Foundation described the competition as a time-limited effort to maximize scrutiny of the Fusaka codebase. Only findings that were both impactful and compliant with the contest rules would qualify for rewards. Submitted issues were to be reviewed and validated, followed by an official report documenting findings and mitigation work.

The incentive schedule emphasized early disclosure. Valid findings submitted during the first week received a two-times multiplier in the contest’s points system, while findings submitted during the second week received a 1.5-times multiplier. The multipliers applied to reward points, not necessarily to a fixed cash payment for every report.

Gnosis contributed $100,000 and Lido contributed $25,000, according to the Foundation. Their combined $125,000 represented 6.25% of the advertised $2 million maximum. That percentage is a Coinburn calculation, not a figure published by the sponsors. The Foundation presented the outside contributions as evidence that responsibility for protocol security extended across the Ethereum ecosystem.

The $2 million headline also required qualification. It described the contest’s maximum potential pool rather than money guaranteed to be distributed. The event-day announcement did not establish how many researchers would participate, how many reports would prove valid, what severities would be assigned or how much ultimately would be paid.

Why Fusaka’s scope raised the stakes

Contemporaneous reporting identified Peer Data Availability Sampling, or PeerDAS, as Fusaka’s central scaling change. PeerDAS was intended to let nodes verify portions of blob data rather than requiring every node to download all of it, creating a path toward greater data capacity for rollups. The upgrade’s reviewed scope also included a higher gas limit, a secp256r1 cryptographic precompile and a mechanism for changing blob parameters without packaging every adjustment inside a larger fork.

Those features made the audit more complex than reviewing a single smart contract. Researchers had to consider specifications, communication between Ethereum’s execution and consensus layers, and behavior across several independently maintained clients. Blockworks reported on September 16 that developers were simultaneously stress-testing Fusaka’s fifth development network and addressing minor implementation issues.

The coexistence of devnet testing and an independent contest illustrated layered security work: tests could reveal operational failures under controlled conditions, while adversarial researchers could search for specification errors, implementation divergences and exploitable edge cases. Neither process constituted proof that the upgrade was free of defects.

What September 15 established

The verified development on September 15 was the opening of a substantial, public pre-deployment review program. Fusaka had not activated on Ethereum mainnet, and the contest announcement did not set a final mainnet date. It also did not demonstrate that PeerDAS had delivered greater capacity or lower transaction costs in production.

The Foundation’s separate standing bug-bounty program continued to offer as much as $250,000 for qualifying vulnerabilities affecting the wider Ethereum protocol. That ongoing program and the temporary Fusaka contest served different windows: one covered broader protocol security continuously, while the other concentrated researchers on a defined upgrade before deployment.

Later context

Sherlock reported in February 2026 that the contest ran for 28 days through October 13, 2025, attracted more than 510 participants and produced four high-severity, two medium-severity and eight low-severity findings. Sherlock said $500,000 of the potential pool was unlocked and that fixes were reviewed before Fusaka activated on December 3, 2025. None of those results was knowable when the contest opened on September 15.

Primary sourceEthereum Foundation — Fusaka $2,000,000 Audit Contest

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.