grantmaking.ai Launch Round
Cybersecurity is already an economic tax on software. Reported losses are in the tens of billions, average breach costs can be in the millions, and exploited vulnerabilities are increasingly a primary way attackers get into companies. That is before mythos-level and future frontier models make vulnerability discovery, exploitation, profit easier than ever.
Many legacy companies, small startups, and vibe-coded startups do not have the time, incentives, compute, process, or dev tools to support autonomous red teaming without real investment. At the same time, cyber risk is already a huge economic drag before AI fully accelerates the attacker side. AI will make recon, vulnerability discovery, exploit adaptation, phishing, and report generation cheaper.
Therefore, by creating a public/private security harness, we enable open-source contributors and independent researchers to turn excess compute, tokens, and security skill into verified defensive work. The key is that this has to be scoped: target owners opt in, define what they own, set allowed actions, approve risky steps, and receive evidence-backed results.
Private enterprises can use this to hedge against increasing cyber capabilities of models and preemptively harden their stack before a serious incident. Smaller companies and maintainers get access to security review they otherwise could not afford.
AI red-team agents could help, especially for maintainers and small teams. To me, the impact of this project is to enable a software owner to say: here is what I own, here is the scope, here are the actions that are allowed, here is what needs approval, here is the evidence required before I believe a finding, and here is the retest proof after a patch.
The ROI should be measurable: a dollar of model/API spend plus bounded human review should produce a reproduced finding, a useful refutation, or a retest receipt. Over time, the system can track cost per verified finding, refutation rate, patch acceptance, retest pass rate, and time from discovery to fix.
This project aims to strengthen the defenders by making AI security work authorized, measurable, and accountable as autonomous cyber capability becomes cheap and widespread and exploitation skyrockets.
Minimum funding of $30,000 would cover a focused MVP and the first controlled pilots. I am not trying to use the grant as a general bounty pool. The money would go toward the parts that make AI-assisted security work safe and useful: owner-approved scope, reproducible evidence, external review, legal boundaries, and small payments only for accepted defensive artifacts.
Minimum version:
$10,000: focused builder time for the MVP harness: owner verification, scoped mission runner, scope receipts, evidence packets, verifier/refuter flow, and basic report generation, compensation.$6,000: shared inference and sandbox pool: model/API credits, Docker/containerized test environments, execution logs, artifact storage, and abuse/rate-limit controls.$5,000: security reviewer/advisor time from people with red-team, AppSec, agent-eval, or frontier-lab safety experience. This would go toward reviewing scope policy, pilot reports, blocked action classes, and verifier/refuter criteria.$4,000: legal/scope/disclosure review: opt-in authorization language, contributor terms, private vulnerability handling, employment/IP concerns, and what can be public versus reviewer-only.$3,000: pilot subsidies / contributor stipends tied only to accepted artifacts: reproduced findings, useful refutations, reviewer feedback, or patch/retest receipts on opted-in targets.$2,000: hosting, database, queueing, logging, docs, and contingency.
At the minimum level, I would aim to ship a small but real harness: GitHub repo ownership verification, a scope receipt schema, a conservative local/lab runner, evidence packet generation, a verifier/refuter pass, and 5-10 pilot packets across lab targets or explicitly opted-in repos. The main question is whether model/API spend plus bounded human review can produce useful security outputs at lower cost than today’s manual review path.
Ideal funding of $70,000 would let me run a more serious 3-4 month pilot and test the economic model without turning this into an unscoped bounty market.
Ideal version:
$20,000: builder/researcher time for a stronger harness: GitHub/org onboarding, scoped target registration, mission queueing, approval gates, verifier/refuter pipeline, maintainer reports, and patch/retest workflow.$12,000: shared inference and sandbox pool: model/API credits, container execution, reproducible eval environments, evidence storage, logs, monitoring, and safety controls.$10,000: security reviewer/advisor support from a small group of security-minded researchers, red-teamers, applied AI SWEs, or agent-eval people. I would use this for adversarial review of the workflow and pilot reports, not vague advising.$8,000: legal, scope, and compliance review: authorization, responsible disclosure, private vulnerability handling, contributor terms, employment/IP concerns, and boundaries around live testing.$12,000: pilot subsidies and contributor/reviewer stipends. These would not pay for raw agent runs or unverified reports. They would only pay for accepted defensive artifacts inside approved scopes: reproduced findings, useful refutations, patch/retest receipts, or high-quality review work.$5,000: pilot operations and maintainer/user research: onboarding 3-5 opted-in targets, collecting feedback, writing the safety case, and publishing the public methodology without leaking sensitive vulnerability details.$3,000: hosting, logging, storage, docs, and contingency.
Longer term, companies should fund the reward pools for their own scopes. If a company wants AI-assisted security review, it should define the target, approve the allowed actions, and fund rewards for accepted work. The grant is mainly for the public-good bootstrap layer: the harness, shared inference/sandbox infrastructure, legal and security review, and early pilots for open-source maintainers or smaller teams that do not already have a bounty program.
If the award is below the ideal amount, I would not change the core safety shape of the project. I would keep owner verification, scoped missions, evidence receipts, verifier/refuter checks, and a small opted-in pilot. The cuts would come from scale: fewer subsidized pilot payouts, a smaller shared inference/sandbox pool, fewer external review cycles, and fewer partner pilots. I would rather prove the workflow carefully on a small number of targets than run a larger but less controlled bounty-style experiment.
The important constraint is that payment should be tied to verified defensive value, not activity. I do not want to pay people for running agents, generating scary reports, or spending compute. The unit of value should be something like a reproduced finding, a useful refutation, a patch/retest receipt, or reviewer validation that improves the system. If this works, the output is a measurable security workflow: cost per verified finding, refutation rate, patch acceptance, retest pass rate, and time from discovery to fix.