#Arbitrum #ARB Arbitrum Foundation Beijing time on September 29 at 00:30 announced the launch of a 12-month Arbitrum Security Program (ASP) and opened applications for audits. What’s truly worth looking at isn’t the word “security” itself—it’s how the funding that previously centered on a single audit has been extended into four stages: pre-audit screening, manual audits, bug bounties, and the DAO Security Committee. Launching the plan doesn’t mean on-chain projects have already received security guarantees.

First, the timeline. The foundation says the original Arbitrum Audit Program began in August 2025 with a one-year term; this ASP is an extension of it. The new announcement states that audit functions will start running from now, and applications are open. Projects don’t automatically receive subsidies just by submitting a form. After approval, the team must also confirm the code is in an auditable state, accept the applicable audit subsidy arrangements, and sign an ecosystem commitment agreement with the foundation—only then will they start matching with audit firms. The official guidance suggests reserving about one month from approval to the expected start of audits. The program covers only the agreed initial audits.

The first change moves questions to before the audit. Selected teams can use AI-assisted security screening before manual audits. It may reduce the time manual auditors spend on basic issues, but AI screening can’t replace professional audits and can’t cover all risks after deployment. The real effect depends on the selected projects’ audit scope, the published reports, and their vulnerability remediation history.

The second change concerns the funding scope. The announcement says the plan involves about $7.8 million at the market price at the time of release—$1.76 million in USDC and 25 million ARB; of this, about $1.2 million corresponds to the commitments already included in the original audit plan, while about $6.6 million is for newly added work. This is a description of planned resources and intended use; it shouldn’t be written as same-day purchases of ARB, nor should the amount converted at market price be treated as a fixed USD budget. The foundation will subsidize part of the audit costs for each project under commercial agreements, not provide free audits for all projects.

The third change is the scope of applicability. Teams that haven’t launched yet, are migrating across chains, are in a growth stage, are rolling out new features, or are building their own Arbitrum Chain can apply. The review also considers technical maturity, the team, the likelihood of success, and alignment with the ecosystem. Expanding the scope may bring more projects into the formal security process, but being in the acceptance range doesn’t mean audits are completed, and it certainly doesn’t mean vulnerabilities won’t occur.

Going forward, the three most important things to track are: the first batch of approved and actually initiated audit projects; whether audit findings and remediation are publicly disclosed; and how bug bounties and the Security Committee coordinate to handle incidents. As for the ARB price, the announcement doesn’t provide evidence that it will directly create new token demand; the security program shouldn’t be mechanically interpreted as a short-term positive catalyst. Source: Arbitrum Foundation, “Introducing the Arbitrum Security Program,” September 28, 2026.