The Ethereum Foundation and Secureum TrustX convened roughly eighty security practitioners at Devconnect Buenos Aires for Trillion Dollar Security Day, a focused event aimed at identifying what it would take to securely support a trillion-dollar Ethereum economy. The gathering brought together experts from across the ecosystem—spanning infrastructure, interoperability, layer 1 and 2, onchain, offchain, privacy, and wallets—to assess the current security landscape and outline concrete next steps.
According to the Ethereum Foundation, the event was designed to foster in-depth, in-person discussions within individual layers, allowing practitioners to share operational realities and prioritize near-term actions. The outputs feed into the foundation's ongoing One Trillion Dollar Security (1TS) initiative, which seeks to strengthen Ethereum's security posture as the network scales.
Cross-Layer Themes Emerge
Participants identified several recurring themes across all seven layers. Security is often treated as a milestone rather than a continuous process, trust assumptions are insufficiently communicated to users, critical security tooling and public goods lack sustainable funding, and coordination and incentives—not cryptography—remain the dominant risk factors.
Breakout sessions by layer produced a detailed snapshot of key issues and immediate next steps. For layer 1 and 2, concerns included quantum risk, weak L1/L2 coordination, cloud dependence, and compressed testing timelines. Proposed actions include expanding the Ethereum Protocol Fellowship (EPF), creating L2 liaison roles, and improving EIP versioning and ownership.
Wallet security discussions highlighted the prevalence of blind signing in hardware wallets and limited coordination among wallet providers. A key proposal was the creation of an Open Signing Alliance, along with hosting the EIP-7730 registry in a neutral or on-chain context and funding wallet-focused security dashboards.
Onchain security experts noted that most recent losses stem from operational security failures rather than novel smart-contract exploits. They called for sustained funding for open-source security tooling, improved visibility into DeFi security posture—similar to an 'L2BEAT-like' approach—and broader adoption of SEAL frameworks.
Interoperability sessions emphasized that many non-canonical bridges fail the 'walkaway test' and that users often mistake speed and low cost for safety. Proposed next steps include developing interop trust ratings, requiring explicit trust disclosures from cross-chain aggregators, and improving canonical bridge UX to reduce reliance on riskier alternatives.
Privacy discussions acknowledged progress in zero-knowledge research but pointed to UX, cost, and infrastructure as major blockers. Recommendations included greater use of light-client data over P2P RPC, investment in private wallet UX, research into ZK-capable hardware signers, and engagement with regulators for clearer guidance on permissionless privacy technologies.
Infrastructure and offchain security were flagged as an invisible attack surface, with frontend compromises, DNS hijacks, RPC centralization, and supply-chain attacks repeatedly cited. Participants proposed building verifiable frontend prototypes, increasing transparency around infrastructure health, and creating structured collaboration models where private companies contribute time and resources to security public goods.
The Ethereum Foundation reported that participants rated the quality of discussion as excellent and expressed strong demand for future work on applied security standards, shared tooling, and practical implementation guidance. The event's primary areas for improvement were logistical, including group size and structured networking opportunities.



