EEA Working Group
EthTrust Security Levels
The EthTrust Security Levels set baseline requirements for Ethereum smart contract security audits. Their three levels help projects and audit firms describe whether an audit covers automated checks, manual review, and contract logic and documentation.
EthTrust v4 proposed technical refresh
AI-generated initial draft for expert validation. Compare version 3 and version 4 changes, and review the candidate requirements. See the non-normative discussion of the GBBC Capital Markets Risk Mitigation Framework (RMF). The draft is not an approved EEA specification, and version 3 remains the certification baseline.
Contributors
The companies behind the standard
The Version 3 specification credits security practitioners from the firms below, along with EEA staff and independent experts. It also builds on the work behind earlier versions.
Our focus
Minimum standards for smart contract security audits
The EEA EthTrust Security Levels Working Group defines baseline requirements for Ethereum smart contract security audits. The three certification levels help projects and audit firms describe the depth of their review.
Automated checks
Requirements that a well-configured static analysis toolchain can verify across the full contract source.
Manual audit
Human review of the contract by qualified security auditors, beyond what automated tooling can establish.
Full logic & documentation review
The deepest level, with business logic and documentation reviewed end to end against the contract's declared intent.
Audit depth increases left to right
Resources
The specification
EEA EthTrust Security Levels Specification v3
Published March 2025. This remains the current approved EEA specification and certification baseline.
- Version 2 (checklist)Published 13 Dec 2023
- Version 1Published 22 Aug 2022
How to contribute
Two open strands of work
EthTrust Security Levels
Anyone may comment on the specification, raise an issue in the public EthTrust-public repository (no EEA membership required). To contribute directly, or to learn more about the working group, email editor@entethalliance.org.
STIX for DeFi
We are developing extensions to the STIX standard for DeFi-specific incident reporting. Join the Web3 STIX Telegram channel and contribute on the DeFi for STIX GitHub repository.