axol.io builds the security infrastructure Ethereum needs but nobody is paying for.
Former Blockdaemon node operators. Former DOJ/FBI financial intelligence analyst. An active Immunefi whitehat. Top research specialists, constantly building.
Xochi (xochi.fi) is the product. Its fees pay our rent. axol.io is the lab -- the Ethereum client written in the wrong language, the ZK compliance EIP nobody asked us to write, the stealth-address composition we built because nobody else had, the bridge-protocol bug we found. None of those make money reliabley. They are why this page exists.
ETH donated through Giveth gets staked via DVT. Principal stays staked. Yield funds the work for as long as Ethereum is running. We aren't asking for funding to start; we're asking for funding to not stop.
What we are funding
- Mana (Apache 2.0 + MIT): Ethereum execution client written in the Elixir language. If a supermajority client has a bug, the chain finalizes bad state. The BEAM runtime can swap signature verification on live validators without restarting.
- ZKSAR (CC BY-SA): Zero-Knowledge Suspicious Activity Reports. Regulators can verify you're clean without seeing the trade. Six proof types covering sanctions, risk scoring, structuring detection, and retroactive proof-of-innocence. An EIP draft so the next privacy protocol doesn't get sanctioned like Tornado Cash.
- Open Primitives (MIT): the crypto libraries behind Xochi, published as @xochi/shared. The interesting bit: ERC-5564 stealth addresses composed with ERC-4337 account abstraction and paymaster sponsorship for gasless claiming.
- Whitehat research: V found a $150M+ oracle bug in a bridge protocol. Disclosed and patched. The bounty conversation is ongoing. Reviewers can see the evidence packet privately.
- Validator operations: ETH staked via DVT (Obol + SSV) on Dappnode hardware. Principal stays staked. Yield funds operations permanently. At higher tiers, the validators run Mana.
Funding tiers
We don't know which tier we'll land in. Here's what each one makes possible. GitHub public updates will track deliverables against any funding received.
- Under $5K
- Whitehat research and ongoing node operation. ZK-Compliance Oracle spec refinement and public comment process.
- $5K to $10K
- Documentation for ERC-5564 + ERC-4337 gasless stealth composition. Oracle vulnerability education writeup.
- $10K to $25K
- Formal verification of stealth address ECDH math.
- $25K to $50K
- Dedicated researcher. Published threat intelligence on oracle and MEV attack patterns.
- $50K to $100K
- ZK-Compliance Oracle testnet as public infrastructure. Security education series. Open audit report.
- $100K to $250K
- Full-time team (2 researchers), quarterly disclosure reports. First Dappnode cluster running Mana validators via DVT.
- $250K to $500K
- Multi-region DVT cluster (3+ client implementations including Mana). Independent ZK-Compliance Oracle audit, published openly. Dedicated Mana development.
- $500K to $1M
- Permanent operation, quarterly reports, open tooling. Geographically distributed validators (3+ continents). ZK-Compliance Oracle through formal EIP standardization.
- Over $1M
- Endowment model. Stake majority via DVT, fund research and development permanently from yield. Position Mana as a percentage of execution client mix.
Donation networks
Donations are accepted on these networks via the Giveth project page:
- Ethereum
- Gnosis
- Optimism
- Polygon
- Celo
- Arbitrum
- Base
Ethereum Security QF Round closes May 14, 2026. Quadratic-funding matching rewards distinct donors more than donation size, so small donations matter disproportionately.
Donations only count toward quadratic-funding matching when made from links starting with qf.giveth.io. We're not asking for funding to start. We're asking for funding to not stop.