
The grant supports a browser-based code verification tool aimed at a persistent crypto weak point: tampered web interfaces that can trigger malicious wallet approvals even when keys and contracts remain uncompromised.
The Ethereum Foundation's Trillion Dollar Security initiative has funded Freedom of the Press Foundation to expand WEBCAT, a tool designed to let browsers verify that a website's delivered code matches what its developers published. The effort targets front-end attacks in which a user keeps funds in a hardware wallet and signs a transaction built by a malicious version of a web page, even though private keys never leak and the underlying smart contracts remain unchanged. WEBCAT applies code-transparency principles to web delivery by comparing served code against a signed developer record, helping detect tampering through compromised hosting accounts, content delivery networks, DNS changes or targeted man-in-the-middle swaps. The grant underscores a part of crypto security that has received less attention than smart contract audits and wallet hardening, but adoption will depend on browser or extension integration and on websites choosing to publish signed code records.