EEA EthTrust Security WG

EEA Working Group

EthTrust Security Levels

The EthTrust Security Levels set baseline requirements for Ethereum smart contract security audits. Their three levels help projects and audit firms describe whether an audit covers automated checks, manual review, and contract logic and documentation.

Specification Version 3 · March 2025 Three certification levels · [S] [M] [Q] Also developing · STIX for DeFi
Now in public review, Version 4 draft

EthTrust v4 proposed technical refresh

AI-generated initial draft for expert validation. Compare version 3 and version 4 changes, and review the candidate requirements. See the non-normative discussion of the GBBC Capital Markets Risk Mitigation Framework (RMF). The draft is not an approved EEA specification, and version 3 remains the certification baseline.

Contributors

The companies behind the standard

The Version 3 specification credits security practitioners from the firms below, along with EEA staff and independent experts. It also builds on the work behind earlier versions.

Our focus

Minimum standards for smart contract security audits

The EEA EthTrust Security Levels Working Group defines baseline requirements for Ethereum smart contract security audits. The three certification levels help projects and audit firms describe the depth of their review.

Automated checks

Requirements that a well-configured static analysis toolchain can verify across the full contract source.

Manual audit

Human review of the contract by qualified security auditors, beyond what automated tooling can establish.

Full logic & documentation review

The deepest level, with business logic and documentation reviewed end to end against the contract's declared intent.

Audit depth increases left to right

Resources

The specification

Current, Version 3

EEA EthTrust Security Levels Specification v3

Published March 2025. This remains the current approved EEA specification and certification baseline.

How to contribute

Two open strands of work

EthTrust Security Levels

Anyone may comment on the specification, raise an issue in the public EthTrust-public repository (no EEA membership required). To contribute directly, or to learn more about the working group, email editor@entethalliance.org.

STIX for DeFi

We are developing extensions to the STIX standard for DeFi-specific incident reporting. Join the Web3 STIX Telegram channel and contribute on the DeFi for STIX GitHub repository.