There are things like https://geyser.fund/ (warning: they block tor users) that people use to crowdfund projects. I don't know how custody works on those platforms, but at the end of the day, it's ultimately going to be "people give money to someone they trust to deliver on their promise".
The only thing that can help mitigate the risk that doners will get burned is to fund it incrementally. That's hard to do with a code audit, but not impossible. Start with the core code, expand out to the libraries. Something like that.

