Code4rena Live Contests & Audit Competitions

0 Active contests
Active prize pool
0 Bug bounties
1 Platforms

Last updated Jul 11, 2026 · 09:32 UTC

Showing 1–20 of 25

25 audit contests

Protocol Source Prize Window Link
Hybra Finance Mitigation Review
Solidity
Code4Rena Finished
$5K
Nov 06 - Nov 10, 2025
4 days
View
Hybra Finance: mitigation review, round 2
Solidity
Code4Rena Finished
$5K
Nov 11 - Nov 12, 2025
1 day
View
Megapot
Solidity
Code4Rena Finished
$30K
Nov 03 - Nov 13, 2025
10 days
View
Sequence: Transaction Rails
Solidity
Code4Rena Finished
$18K
Nov 11 - Nov 17, 2025
6 days
View
Merkl
Solidity
Code4Rena Finished
$18K
Nov 25 - Dec 01, 2025
6 days
View
Brix Money
Solidity
Code4Rena Finished
$23K
Nov 26 - Dec 03, 2025
7 days
View
SukukFi
Solidity
Code4Rena Finished
$40K
Nov 26 - Dec 05, 2025
9 days
View
Garden
Solidity
Code4Rena Finished
$37K
Nov 24 - Dec 08, 2025
14 days
View
Swafe
Solidity
Code4Rena Finished
$100K
Nov 18 - Dec 09, 2025
21 days
View
Ekubo
Solidity
Code4Rena Finished
$183K
Nov 19 - Dec 10, 2025
21 days
View
Panoptic: Next Core
Solidity
Code4Rena Finished
$56K
Dec 19 - Jan 07, 2026
19 days
View
Rujira
Rust
Code4Rena Judging
$40K
Dec 16 - Jan 16, 2026
31 days
View
Olas
Solidity
Code4Rena Finished
$62K
Jan 22 - Feb 09, 2026
18 days
View
Panoptic: Next Core Mitigation Review
Solidity
Code4Rena Finished
$6K
Feb 13 - Feb 18, 2026
5 days
View
Panoptic: Next Core Mitigation Review: Round 2
Solidity
Code4Rena Finished
$6K
Feb 23 - Feb 25, 2026
2 days
View
Intuition
Solidity
Code4Rena Finished
$17K
Mar 04 - Mar 09, 2026
5 days
View
Jupiter Lend
Rust
Code4Rena Finished
$107K
Feb 12 - Mar 13, 2026
29 days
View
Injective Peggy Bridge
Rust
Code4Rena Finished
$105K
Feb 25 - Mar 17, 2026
20 days
View
Swafe Mitigation Review
Solidity
Code4Rena Finished
$12K
Mar 20 - Mar 24, 2026
4 days
View
Chainlink Payment Abstraction V2
Solidity
Code4Rena Finished
$65K
Mar 18 - Mar 27, 2026
9 days
View
Loading timeline...
Code4Rena Finished

Hybra Finance Mitigation Review

$5K Prize pool
Nov 06 - Nov 10, 2025
View on Code4Rena
Code4Rena Finished

Hybra Finance: mitigation review, round 2

$5K Prize pool
Nov 11 - Nov 12, 2025
View on Code4Rena
Code4Rena Finished

Sequence: Transaction Rails

$18K Prize pool
Nov 11 - Nov 17, 2025
View on Code4Rena
Code4Rena Finished

Panoptic: Next Core

$56K Prize pool
Dec 19 - Jan 07, 2026
View on Code4Rena
Code4Rena Finished

Panoptic: Next Core Mitigation Review

$6K Prize pool
Feb 13 - Feb 18, 2026
View on Code4Rena
Code4Rena Finished

Panoptic: Next Core Mitigation Review: Round 2

$6K Prize pool
Feb 23 - Feb 25, 2026
View on Code4Rena
Code4Rena Finished

Injective Peggy Bridge

$105K Prize pool
Feb 25 - Mar 17, 2026
View on Code4Rena
Code4Rena Finished

Swafe Mitigation Review

$12K Prize pool
Mar 20 - Mar 24, 2026
View on Code4Rena
Code4Rena Finished

Chainlink Payment Abstraction V2

$65K Prize pool
Mar 18 - Mar 27, 2026
View on Code4Rena

About Code4rena

Code4rena (often abbreviated C4) launched in 2021 and remains the most recognized audit competition platform in Web3. Contests typically run 3 to 14 days with prize pools between $50,000 and $500,000. Wardens submit findings, judges weight them by severity, and the prize pool is split proportionally across valid unique findings.

This page shows only contests aggregated from Code4rena. For audit contests on other platforms, see the full Web3 audit competition tracker.

Smart Contract Audit Competition & Bug Bounty Platforms Compared

Six major platforms host the Web3 audit competitions and smart contract bug bounty programs aggregated above. Click any platform to see only its active contests.

Comparison of the major smart contract audit competition and bug bounty platforms.
Platform Type Typical Prize Contest Length Best For
Code4rena Audit contests $50K to $500K 3 to 14 days DeFi protocols pre-launch
Sherlock Contests + bounties $50K to $300K 7 to 30 days Insurance-backed audits
CodeHawks Audit contests + First Flights $5K to $200K 3 to 21 days Newer auditors building a track record
Cantina Mega-comps + bounties $200K to $2M+ 14 to 30 days Experienced researchers, high-value protocols
Immunefi Ongoing bug bounties Up to $15M per critical Ongoing Production protocol vulnerability hunting
HackenProof Bounties + crowdsourced audits $1K to $1M+ Ongoing or time-boxed Managed Web3 programs and exchange/protocol bounties

Frequently Asked Questions

How do I find active Code4rena contests?

Every currently-active Code4rena audit competition appears in the listing above, pulled directly from the Code4rena API every 2 hours. You can also browse all contests on code4rena.com/audits.

How much can you earn on Code4rena?

Top Code4rena wardens have earned over $100,000 from a single contest by finding multiple critical-severity vulnerabilities. Most active wardens earn $1,000 to $20,000 per contest depending on their finding count and severity.

What are the best smart contract bug bounty platforms?

The leading Web3 bug bounty platforms are Immunefi (largest, $15M max payouts on DeFi protocols), Cantina (Spearbit's bounty program plus audit competitions), HackenProof (managed Web3 bounties and crowdsourced audits), Sherlock (audit contests with insurance-backed bounties), and Code4rena (best known for time-boxed audit competitions). Codehawks rounds out the field with Cyfrin-run contests focused on emerging protocols and beginner-friendly First Flights.

Which audit competition platform pays the most?

Cantina runs the largest audit competitions ($2M+ prize pools for protocols like EigenLayer and Uniswap v4). Immunefi pays the highest per-bug bounty (up to $15M for critical findings). Code4rena and Sherlock typically run $100K-$500K audit contests. Codehawks First Flights are smaller but accessible to newer auditors.

How do smart contract audit competitions work?

Audit competitions invite security researchers to review a protocol's smart contract code for a fixed prize pool over 1-4 weeks. Rewards are split based on unique valid findings, weighted by severity (critical, high, medium). Code4rena, Sherlock, Codehawks, and Cantina are the main platforms.

How much can you earn in a smart contract audit competition?

Top auditors earn $10,000-$500,000+ per competition. Cantina and Code4rena regularly run $500K-$2M prize pool contests. Bug bounties can pay up to $15M per critical finding on platforms like Immunefi.

What is the difference between a bug bounty and an audit contest?

Audit contests run for a fixed time window with a fixed prize pool shared among all valid findings. Bug bounties are ongoing programs where each valid submission earns a direct per-vulnerability reward (often $50K-$15M depending on severity). Bug bounties require finding a real vulnerability in production code.

How do I get started with smart contract auditing?

Learn the most common vulnerability classes first: reentrancy, flash loan attacks, oracle manipulation, and access control. The SCH Smart Contract Hacking Course covers all the core attack patterns that audit competitions test, starting from zero experience.

How to Start Competing in Smart Contract Audits

A practical path from learning vulnerability classes to submitting your first contest finding.

  1. Learn the core vulnerability classes

    Master reentrancy, access control, oracle manipulation, flash loan attacks, and arithmetic overflows. These five classes account for most contest findings.

  2. Practice on retired contests

    Read every public report from past Code4rena and Sherlock contests. Try to spot findings yourself before reading the writeup. This is how every top auditor trained.

  3. Start with CodeHawks First Flights

    First Flights are small audit contests designed for newer auditors. Prize pools are under $20K, scope is small, and competition is lighter. They build real submission history.

  4. Enter your first full competition

    Pick an active audit contest from the tracker above filtered by Solidity and a $50K-$200K prize range. Spend 20 to 40 hours on the contest, even if you only find one valid medium-severity issue.

  5. Build a public track record

    Publish your findings, share writeups on Twitter and Mirror, and start accumulating valid submissions across multiple platforms. A documented track record is what opens bug bounty access and full-time auditor roles.