Instead of relying on passive awareness content, generic quizzes, or low-effort phishing emails, The Phishing Dojo creates realistic, interactive simulations of crypto-native threats: malicious wallet signatures, fake airdrops, scam websites, spoofed domains, approval traps, impersonation, fake block explorers, seed phrase theft, social engineering, and other attacks that users and builders actually face.
The platform lets people practice inside a safe environment without exposing real wallets, private keys, assets, or infrastructure. The goal is to turn phishing defense from theoretical knowledge into trained reflexes.
The Red Guild is a public-goods security organization.
Since the beginning of 2023, we have worked full-time on the safety of the Ethereum ecosystem through open research, free training, advisories, tooling, and education. Our blog is a public record of recurring status updates, technical writeups, event reports, and shipped resources. Anyone can verify what we build and maintain. Today that work spans six active lines: Phishing Dojo, Damn Vulnerable DeFi, contributing with SEAL, education and awareness, security research and advisories, and open-source tooling.
We do not focus only on smart contracts because the threats go well beyond them. We steward Damn Vulnerable DeFi as a forever-free training ground and keep turning it into workshops and walkthroughs. We created, along with Patrick Collins, the first free and most complete smart contract security course, which to this day is the most viewed and recommended by the community. We built The Phishing Dojo (currently under maintenance) to train users against phishing and scams through realistic simulations, and continued improving it through beta releases, new wallet-signing and email challenges, account management, and progress tracking. We lead SEAL’s Security Frameworks work, publish technical advisories and research on off-chain and developer-security topics, and maintain practical public resources such as DevSecOops, devcontainer research, devcontainer-wizard and now exploring with transient/ephermal VMs in a world where having a 0day vulnerability has become cheaper. That body of work includes public investigations and guidance on Ethereum 7702 risks, malicious VSCode extensions, container escapes, npm supply-chain threats, "Why technical excellence fails" (whitehats not recognized as a critical infrastructure) and the One Time Pwnage / SLOVENLY COMET advisory on SMS interception attacks.
Our public impact is not only digital. We have mentored, judged, organized, and taught across Ethereum Argentina, Ethereum Uruguay, DeFi Security Summit, Devcon, Devconnect, ETHCC, and pop-up cities like muBuenos and Aleph/Crecimiento.
We have also taken a very important role in many Ethereum-centered activities of course, two key examples are organizing the first iteration of the Ethereum Rangers program, and being champions at the One-trillion-dollar initiative first gathering, coordinating the Offchain layer, presenting insights and creating a blog-post later used by ethereum.org’s 1TS official report.
What matters now is continuity.
Our team ran out of funding on November 8, 2025, and kept going anyway: building, publishing, running the Devconnect awareness campaign, showing up for talks and workshops, and taking on community work because our commitment is to the ecosystem, not to a revenue model. We have no paywalls, no token, no closed access, and no sales funnel. Our public goods do not make money, but still require time, infrastructure, maintenance, logistics, and sustained research.
This moment is not about helping us start.
It is about deciding whether the work that The Red Guild has delivered, maintained, and used in public can continue to exist. People across the ecosystem keep saying The Red Guild’s work matters. This is when words can become concrete support. Our funding on this round decides whether The Red Guild survives and continues producing independent top-quality security public goods for Ethereum.
We want users, builders, teams, and communities to experience high-quality threat simulations before attackers target them in the wild. By replacing passive awareness with safe hands-on practice, The Phishing Dojo helps reduce preventable losses, improve security culture, and raise the baseline of crypto security across the ecosystem.
Most existing training platforms and campaigns are generic, boring, shallow, and disconnected from the real threats people face in crypto. They usually rely on slides, checklists, multiple-choice quizzes, fake corporate phishing emails, or simplistic “spot the scam” exercises. That does not build real defensive skill.

In crypto, getting phished is often treated like a lottery: people hope they will notice the scam in time, but they rarely get meaningful practice before they face a real attack. The first realistic phishing simulation many users experience is the real one, with their funds, identity, signing keys, or organization at risk.
Current awareness tools are cheap because they often provide little real value. They measure completion, not competence. They test whether someone clicked through training, not whether they can safely handle a malicious signature request, a fake token claim, a compromised frontend, a malicious approval flow, a spoofed support message, or a targeted social-engineering attack.
Crypto needs security training that reflects how crypto attacks actually work.
**
Users can practice realistic crypto threat scenarios without leaving the platform and without putting real assets at risk. The experience is closer to a dojo than a quiz: users learn by doing, failing safely, receiving feedback, and repeating until they improve.
The platform simulates attacks such as:
Malicious wallet-signing flows
The Phishing Dojo is designed to serve individuals, communities, protocols, wallets, events, and organizations that need practical crypto security education. It can be used for public training, onboarding, workshops, team exercises, conference activations, and ecosystem-wide security awareness campaigns.
Its value is not just awareness. It creates muscle memory.
We want this to be public good. Organizations will be able to pay a fee per seat to be able to use SSO, team management, training creation, metrics and insights from teams.
Want to grow through just grant funding
Global
0