Cantina (cantina.xyz) Live Audit Competitions

0 Active contests
Active prize pool
70 Bug bounties
1 Platforms

Last updated Jul 14, 2026 · 05:51 UTC

Showing 81–100 of 198

128 audit contests70 bug bounty programs

Protocol Source Prize Window Link
VenusProtocol/governance-contracts
Solidity
Cantina Finished
$58K
Mar 22 - Apr 05, 2024
14 days
View
Smart-contracts
Solidity
Cantina Finished
$80K
Mar 19 - Apr 08, 2024
20 days
View
curvance
Solidity
Cantina Finished
$375K
Feb 27 - Apr 15, 2024
49 days
View
safe-extensions
Solidity
Cantina Finished
$75K
May 06 - May 10, 2024
4 days
View
Aave v3.1 Competition
Solidity
Cantina Finished
$150K
May 10 - May 20, 2024
10 days
View
YOLO Games
Solidity
Cantina Finished
$27K
May 27 - Jun 08, 2024
12 days
View
Euler-v2
Solidity
Cantina Finished
$1.2M
May 20 - Jun 17, 2024
28 days
View
SP1
Solidity
Cantina Finished
$110K
Jun 03 - Jun 23, 2024
20 days
View
Bitcoin Staking Scripts
Solidity
Cantina Finished
$150K
May 28 - Jun 24, 2024
27 days
View
Pegasus
Solidity
Cantina Finished
$80K
Jun 18 - Jun 28, 2024
10 days
View
grass
Solidity
Cantina Finished
$15K
Jun 24 - Jul 01, 2024
7 days
View
zetachain-protocol
Solidity
Cantina Finished
$120K
Aug 19 - Sep 04, 2024
16 days
View
Centrifuge
Solidity
Cantina Finished
$125K
Aug 19 - Sep 16, 2024
28 days
View
Royco Protocol
Solidity
Cantina Finished
$30K
Sep 13 - Sep 24, 2024
11 days
View
uniswap-v4
Solidity
Cantina Finished
$2.4M
Sep 06 - Oct 01, 2024
25 days
View
instadapp-fluid
Solidity
Cantina Finished
$250K
Sep 11 - Oct 02, 2024
21 days
View
symbioticfi-core
Solidity
Cantina Finished
$50K
Sep 11 - Oct 02, 2024
21 days
View
redstone-oracle
Solidity
Cantina Finished
$40K
Sep 24 - Oct 04, 2024
10 days
View
stakeup-bloomv2
Solidity
Cantina Finished
$60K
Oct 07 - Oct 21, 2024
14 days
View
mev-commit
Solidity
Cantina Finished
$65K
Oct 01 - Oct 22, 2024
21 days
View
Loading timeline...
Cantina Finished

VenusProtocol/governance-contracts

$58K Prize pool
Mar 22 - Apr 05, 2024
View on Cantina
Cantina Finished

Smart-contracts

$80K Prize pool
Mar 19 - Apr 08, 2024
View on Cantina
Cantina Finished

safe-extensions

$75K Prize pool
May 06 - May 10, 2024
View on Cantina
Cantina Finished

Aave v3.1 Competition

$150K Prize pool
May 10 - May 20, 2024
View on Cantina
Cantina Finished

Bitcoin Staking Scripts

$150K Prize pool
May 28 - Jun 24, 2024
View on Cantina
Cantina Finished

zetachain-protocol

$120K Prize pool
Aug 19 - Sep 04, 2024
View on Cantina
Cantina Finished

Royco Protocol

$30K Prize pool
Sep 13 - Sep 24, 2024
View on Cantina
Cantina Finished

instadapp-fluid

$250K Prize pool
Sep 11 - Oct 02, 2024
View on Cantina
Cantina Finished

symbioticfi-core

$50K Prize pool
Sep 11 - Oct 02, 2024
View on Cantina
Cantina Finished

redstone-oracle

$40K Prize pool
Sep 24 - Oct 04, 2024
View on Cantina
Cantina Finished

stakeup-bloomv2

$60K Prize pool
Oct 07 - Oct 21, 2024
View on Cantina

About Cantina

Cantina is backed by Spearbit, one of the most respected smart contract security firms. Cantina runs two products: large public audit competitions (typically $200,000-$2,000,000+ prize pools) and an ongoing Web3 bug bounty marketplace. Cantina contests draw the most experienced researchers in the industry and run 14 to 30 days.

This page shows only competitions aggregated from Cantina. For audit contests on other platforms, see the full Web3 audit competition tracker.

Smart Contract Audit Competition & Bug Bounty Platforms Compared

Six major platforms host the Web3 audit competitions and smart contract bug bounty programs aggregated above. Click any platform to see only its active contests.

Comparison of the major smart contract audit competition and bug bounty platforms.
Platform Type Typical Prize Contest Length Best For
Code4rena Audit contests $50K to $500K 3 to 14 days DeFi protocols pre-launch
Sherlock Contests + bounties $50K to $300K 7 to 30 days Insurance-backed audits
CodeHawks Audit contests + First Flights $5K to $200K 3 to 21 days Newer auditors building a track record
Cantina Mega-comps + bounties $200K to $2M+ 14 to 30 days Experienced researchers, high-value protocols
Immunefi Ongoing bug bounties Up to $15M per critical Ongoing Production protocol vulnerability hunting
HackenProof Bounties + crowdsourced audits $1K to $1M+ Ongoing or time-boxed Managed Web3 programs and exchange/protocol bounties

Frequently Asked Questions

How big are Cantina prize pools?

Cantina hosts the largest audit competitions in Web3, including $2M+ prize pools for EigenLayer-contracts ($2.5M), Uniswap v4 ($2.4M), and PumpSwap ($2M). Typical Cantina contests range $200,000 to $2,000,000, much higher than Code4rena or Sherlock averages.

Is Cantina the same as Spearbit?

Cantina is the public competition arm of Spearbit, a leading Web3 security firm. Spearbit runs private invite-only audits; Cantina runs open competitions where any researcher can participate. Both share judging expertise and quality standards.

What are the best smart contract bug bounty platforms?

The leading Web3 bug bounty platforms are Immunefi (largest, $15M max payouts on DeFi protocols), Cantina (Spearbit's bounty program plus audit competitions), HackenProof (managed Web3 bounties and crowdsourced audits), Sherlock (audit contests with insurance-backed bounties), and Code4rena (best known for time-boxed audit competitions). Codehawks rounds out the field with Cyfrin-run contests focused on emerging protocols and beginner-friendly First Flights.

Which audit competition platform pays the most?

Cantina runs the largest audit competitions ($2M+ prize pools for protocols like EigenLayer and Uniswap v4). Immunefi pays the highest per-bug bounty (up to $15M for critical findings). Code4rena and Sherlock typically run $100K-$500K audit contests. Codehawks First Flights are smaller but accessible to newer auditors.

How do smart contract audit competitions work?

Audit competitions invite security researchers to review a protocol's smart contract code for a fixed prize pool over 1-4 weeks. Rewards are split based on unique valid findings, weighted by severity (critical, high, medium). Code4rena, Sherlock, Codehawks, and Cantina are the main platforms.

How much can you earn in a smart contract audit competition?

Top auditors earn $10,000-$500,000+ per competition. Cantina and Code4rena regularly run $500K-$2M prize pool contests. Bug bounties can pay up to $15M per critical finding on platforms like Immunefi.

What is the difference between a bug bounty and an audit contest?

Audit contests run for a fixed time window with a fixed prize pool shared among all valid findings. Bug bounties are ongoing programs where each valid submission earns a direct per-vulnerability reward (often $50K-$15M depending on severity). Bug bounties require finding a real vulnerability in production code.

How do I get started with smart contract auditing?

Learn the most common vulnerability classes first: reentrancy, flash loan attacks, oracle manipulation, and access control. The SCH Smart Contract Hacking Course covers all the core attack patterns that audit competitions test, starting from zero experience.

How to Start Competing in Smart Contract Audits

A practical path from learning vulnerability classes to submitting your first contest finding.

  1. Learn the core vulnerability classes

    Master reentrancy, access control, oracle manipulation, flash loan attacks, and arithmetic overflows. These five classes account for most contest findings.

  2. Practice on retired contests

    Read every public report from past Code4rena and Sherlock contests. Try to spot findings yourself before reading the writeup. This is how every top auditor trained.

  3. Start with CodeHawks First Flights

    First Flights are small audit contests designed for newer auditors. Prize pools are under $20K, scope is small, and competition is lighter. They build real submission history.

  4. Enter your first full competition

    Pick an active audit contest from the tracker above filtered by Solidity and a $50K-$200K prize range. Spend 20 to 40 hours on the contest, even if you only find one valid medium-severity issue.

  5. Build a public track record

    Publish your findings, share writeups on Twitter and Mirror, and start accumulating valid submissions across multiple platforms. A documented track record is what opens bug bounty access and full-time auditor roles.