Jade Doherty and Stefan Beyer speak to Lorenzo Sicilia, Head of Technology at the Arbitrum Foundation, whose path into crypto runs through ConsenSys, Casval, and Outlier Ventures. They open with the distinction that shapes everything else: the Foundation is the steward and legal wrapper of the DAO, not the team behind the tech. Lorenzo unpacks how it ran the Arbitrum Audit Program on the DAO's behalf, vetting a shortlist of thirteen audit firms and funding early-stage teams, and gets into the hard parts with Stefan: the "rubber stamp" risk when a Foundation-blessed audit becomes a trust signal, the friction of re-auditing when each iteration costs $50K to $250K, and the brutal cost-per-line metric the program can now benchmark across firms. On security responsibility, Lorenzo is precise: the Foundation has none in the formal sense. Incidents fall to a 12-member Security Council, elected and rotated by the DAO. From there the conversation turns to what keeps him up at night, the L1-L2 trust boundary and the bridge, and why fraud proofs through BoLD have improved the picture, landing on his own preference for "code is law" while acknowledging where reality forces harder trade-offs. The technical heart is Stylus, Arbitrum's WASM environment for writing contracts in Rust alongside the EVM. Lorenzo is unromantic about it: a second runtime widens the attack surface, and while safe Rust has real advantages, no language removes the authorisation, economic, and oracle pitfalls that actually cause losses, treating any language as "safe" is a mental trap. The episode also covers the freshly-shipped ZK-on-BoLD upgrade, the road to real-time proving, and why AI currently hands the red team a big advantage over the blue team, though Lorenzo is optimistic defenders can turn the same tooling back on their own code. He closes with hard-won advice: authenticity and persistence over a polished demo, understand your oracles and dependencies, get key management right, and know when to switch from "fake it till you make it" to full paranoia, because in this industry, you don't get a discount. Key Topics The Arbitrum Audit Program, and the "rubber stamp" problem with Foundation-backed audits Decentralised security responsibility: the Security Council, the L1-L2 boundary, and BoLD Stylus and WASM security, ZK-on-BoLD, real-time proving, and AI's red-team advantage Chapters 00:00 Introduction 00:35 From ConsenSys and Outlier Ventures to the Arbitrum Foundation 04:11 What the Foundation Actually Does, and How It Differs from Offchain Labs 06:50 The Audit Program: How It Works and Who Funds It 10:18 The "Rubber Stamp" Problem and Vetting Audit Firms 13:18 Early-Stage vs Mature Teams: Who the Program Is For 14:54 What's Next: Additional Tools, AI, and the Limits of Scope 17:15 Lessons From the First Iteration, and Cost-Per-Line Benchmarking 21:11 The Foundation's Responsibility and the Security Council 24:49 What Keeps Him Up at Night: The L1-L2 Boundary and Bridges 29:16 Security Policy, Bug Bounties, and Disclosure Across the Ecosystem 30:48 Stylus: Does a WASM Runtime Widen the Attack Surface? 34:49 Safe Rust vs Solidity, Tooling Gaps, and the "Mental Trap" 39:13 Adding ZK to BoLD, and the Multi-Prover Approach 42:20 Real-Time Proving and Where Arbitrum Is Heading 45:20 ZK for Compression vs ZK for Privacy 46:24 AI in 2026: Red Team vs Blue Team, and AI Slop 50:31 Judging Teams: Authenticity, Resilience, and Real Problems 53:33 The Biggest Security Mistakes New Teams Make 55:25 The Foundation's Security Vision for the Next Few Years 57:52 One Piece of Advice: Dependencies, Keys, and Knowing When to Get Paranoid Resources and Links Lorenzo on X: https://x.com/aboutlo Arbitrum: https://arbitrum.io Oak Security's Research: https://research.oaksecurity.io/