Crypto & Web3

Ethereum Foundation funds WEBCAT verification for wallets

Ethereum Foundation funds WEBCAT verification for wallets

Announcing a Trillion Dollar Security grant for WEBCAT | Ethereum Foundation Blog

The Ethereum Foundation’s Trillion Dollar Security (1TS) initiative has allocated a grant to the Freedom of the Press Foundation (FPF) to extend WEBCAT, an open-source browser verification tool, into Ethereum wallets and applications. WEBCAT, short for web-based code assurance and transparency, lets a browser verify that files served by an enrolled site match a signed manifest — a capability the project describes on its own site at webcat.tech. The grant targets a specific gap in web security: HTTPS authenticates the server and encrypts traffic, but it does not prove the delivered code matches what the developer published, as the Ethereum Foundation’s 1TS grant announcement explains.

Currently, WEBCAT ships as a Firefox extension that blocks pages from loading when verification fails, a behavior documented in the WEBCAT project’s own materials. The 1TS grant will fund a verification library that wallets can integrate directly, removing the need for users to install a separate browser add-on. The funding also supports research into Chrome and other Chromium-based browser compatibility, onboarding assistance for teams adding WEBCAT to their apps, an independent security audit, and an Ethereum Request for Comments (ERC) standard so wallet developers have a common interface to follow, according to the Ethereum Foundation’s 1TS grant announcement.

The initiative complements Clear Signing, an earlier 1TS effort that provides human-readable transaction descriptions to reduce blind signing. While Clear Signing helps users understand what they are approving, WEBCAT adds a complementary check that the app’s front-end code has not been altered before it reaches the browser. The Ethereum Foundation also announced Clear Signing as part of its Trillion Dollar Security push in May 2026, framing both efforts as layers in a broader defense against supply-chain and phishing attacks.

FPF originally built WEBCAT with SecureDrop, its open-source system for secure communication between journalists and anonymous sources, in mind. A future SecureDrop version will encrypt submissions in the browser before upload, and WEBCAT ensures the encryption code itself has not been tampered with by a compromised server. Because that code still comes from the server, a compromise could alter it to capture content before encryption occurs. Freedom of the Press Foundation, the nonprofit behind both SecureDrop and WEBCAT, describes its mission and tooling at freedom.press. The Ethereum Foundation’s grant announcement covers the integration roadmap in detail at blog.ethereum.org.

For Ethereum users, the risk is concrete: a tampered front end can alter transaction details, swap recipient addresses, or capture data before end-to-end encryption takes effect. Because wallets cannot distinguish a legitimate page from a malicious clone using TLS alone, verifying served code against a signed manifest adds a meaningful layer of protection — a problem the WEBCAT project frames as an extension of the same class of attacks that Clear Signing addresses on the transaction-approval side. Readers seeking broader guidance on protecting self-custodied Ethereum assets can consult our guide on Ethereum self-custody wallet security best practices, and teams interested in integrating the library or enrolling their domains can contact the initiative at trilliondollarsecurity@ethereum.org, as listed on the 1TS grant page.

Editorially independent: we accept no payment for coverage and currently use no affiliate links. Read our Editorial Standards and Corrections Policy. Published: Aug 14, 2026.
Jinultimate

Editor of ZBrandCo and the person accountable for what we publish — setting our sourcing standards, fact-checking claims against primary sources, and issuing corrections promptly across AI, open source, and gaming. Reach the desk at editorial@zbrandco.com.