HackenProof Live Bug Bounty Programs
Last updated Jul 20, 2026 · 14:49 UTC
Showing 181–200 of 291
80 audit contests211 bug bounty programs
| Protocol | Source | Prize | Window | Link |
|---|---|---|---|---|
|
TETU Smart Contracts
|
|
$1.0M max |
May 19 - May 20, 2024
367 days
|
View |
|
VeChainThor Wallet
|
|
$3K max |
Aug 22 - Sep 09, 2024
1845 days
|
View |
|
NodeTerminal DualDefense Audit
|
|
$9K |
Oct 24 - Nov 22, 2024
29 days
|
View |
|
Zharta DualDefense Audit
|
|
$30K |
Oct 26 - Nov 24, 2024
29 days
|
View |
|
Nya DualDefense Audit
|
|
$32K |
Nov 05 - Dec 04, 2024
29 days
|
View |
|
Portikus DualDefense Audit
|
|
$50K |
Nov 08 - Dec 07, 2024
29 days
|
View |
|
Common Wealth DualDefense Audit
|
|
$25K |
Oct 31 - Dec 08, 2024
38 days
|
View |
|
Lingo DualDefense Audit
|
|
$21K |
Nov 27 - Dec 10, 2024
13 days
|
View |
|
CratD2C DualDefense Audit
|
|
$20K |
Nov 11 - Dec 10, 2024
29 days
|
View |
|
Galileo Protocol DualDefense Audit
|
|
$14K |
Nov 11 - Dec 10, 2024
29 days
|
View |
|
CratD2C dApp DualDefense Audit
|
|
$11K |
Nov 24 - Dec 24, 2024
30 days
|
View |
|
Covalent DualDefense Audit
|
|
$16K |
Dec 06 - Dec 31, 2024
25 days
|
View |
|
Shido Network - Protocol
|
|
$10K max |
Feb 23 - Jan 08, 2025
320 days
|
View |
|
Unizen DualDefense Audit
|
|
$65K |
Dec 13 - Jan 09, 2025
27 days
|
View |
|
CratD2C L1 DualDefense Audit
|
|
$65K |
Dec 26 - Jan 18, 2025
23 days
|
View |
|
EverValue Coin DualDefense Audit
|
|
$37K |
Jan 11 - Feb 01, 2025
21 days
|
View |
|
Hubz DualDefense Audit
|
|
$16K |
Jan 18 - Feb 10, 2025
23 days
|
View |
|
Kinetic Audit Contest
|
|
$40K |
Jan 20 - Feb 20, 2025
31 days
|
View |
|
DexLyn SCA DualDefense Audit
|
|
$37K |
Jan 29 - Feb 24, 2025
26 days
|
View |
|
Smilee Smart Contracts
|
|
$75K max |
Mar 14 - Mar 05, 2025
356 days
|
View |
VeChainThor Wallet
NodeTerminal DualDefense Audit
Zharta DualDefense Audit
Nya DualDefense Audit
Portikus DualDefense Audit
Common Wealth DualDefense Audit
Lingo DualDefense Audit
CratD2C DualDefense Audit
Galileo Protocol DualDefense Audit
CratD2C dApp DualDefense Audit
Covalent DualDefense Audit
Shido Network - Protocol
Unizen DualDefense Audit
CratD2C L1 DualDefense Audit
EverValue Coin DualDefense Audit
Hubz DualDefense Audit
Kinetic Audit Contest
DexLyn SCA DualDefense Audit
Smilee Smart Contracts
About HackenProof
HackenProof is Hacken's Web3 bug bounty and crowdsourced audit platform. It combines ongoing vulnerability reward programs with time-boxed audit programs for smart contracts, exchanges, wallets, bridges, and L1/L2 ecosystems.
This page shows only Web3-relevant programs aggregated from HackenProof. For audit contests and bounties on other platforms, see the full Web3 audit competition tracker.
Smart Contract Audit Competition & Bug Bounty Platforms Compared
Six major platforms host the Web3 audit competitions and smart contract bug bounty programs aggregated above. Click any platform to see only its active contests.
| Platform | Type | Typical Prize | Contest Length | Best For |
|---|---|---|---|---|
|
|
Audit contests | $50K to $500K | 3 to 14 days | DeFi protocols pre-launch |
|
|
Contests + bounties | $50K to $300K | 7 to 30 days | Insurance-backed audits |
|
|
Audit contests + First Flights | $5K to $200K | 3 to 21 days | Newer auditors building a track record |
|
|
Mega-comps + bounties | $200K to $2M+ | 14 to 30 days | Experienced researchers, high-value protocols |
|
|
Ongoing bug bounties | Up to $15M per critical | Ongoing | Production protocol vulnerability hunting |
|
|
Bounties + crowdsourced audits | $1K to $1M+ | Ongoing or time-boxed | Managed Web3 programs and exchange/protocol bounties |
Frequently Asked Questions
What kind of programs does HackenProof run?
HackenProof runs public bug bounty programs, private bounty programs, and crowdsourced audits. In Web3, its listings include smart contracts, bridges, exchanges, wallets, and L1/L2 ecosystems.
How do I submit a report on HackenProof?
Open the protocol program page on hackenproof.com, review the scope, severity, reputation, and proof-of-concept requirements, then submit through the HackenProof dashboard.
What are the best smart contract bug bounty platforms?
The leading Web3 bug bounty platforms are Immunefi (largest, $15M max payouts on DeFi protocols), Cantina (Spearbit's bounty program plus audit competitions), HackenProof (managed Web3 bounties and crowdsourced audits), Sherlock (audit contests with insurance-backed bounties), and Code4rena (best known for time-boxed audit competitions). Codehawks rounds out the field with Cyfrin-run contests focused on emerging protocols and beginner-friendly First Flights.
Which audit competition platform pays the most?
Cantina runs the largest audit competitions ($2M+ prize pools for protocols like EigenLayer and Uniswap v4). Immunefi pays the highest per-bug bounty (up to $15M for critical findings). Code4rena and Sherlock typically run $100K-$500K audit contests. Codehawks First Flights are smaller but accessible to newer auditors.
How do smart contract audit competitions work?
Audit competitions invite security researchers to review a protocol's smart contract code for a fixed prize pool over 1-4 weeks. Rewards are split based on unique valid findings, weighted by severity (critical, high, medium). Code4rena, Sherlock, Codehawks, and Cantina are the main platforms.
How much can you earn in a smart contract audit competition?
Top auditors earn $10,000-$500,000+ per competition. Cantina and Code4rena regularly run $500K-$2M prize pool contests. Bug bounties can pay up to $15M per critical finding on platforms like Immunefi.
What is the difference between a bug bounty and an audit contest?
Audit contests run for a fixed time window with a fixed prize pool shared among all valid findings. Bug bounties are ongoing programs where each valid submission earns a direct per-vulnerability reward (often $50K-$15M depending on severity). Bug bounties require finding a real vulnerability in production code.
How do I get started with smart contract auditing?
Learn the most common vulnerability classes first: reentrancy, flash loan attacks, oracle manipulation, and access control. The SCH Smart Contract Hacking Course covers all the core attack patterns that audit competitions test, starting from zero experience.
How to Start Competing in Smart Contract Audits
A practical path from learning vulnerability classes to submitting your first contest finding.
-
Learn the core vulnerability classes
Master reentrancy, access control, oracle manipulation, flash loan attacks, and arithmetic overflows. These five classes account for most contest findings.
-
Practice on retired contests
Read every public report from past Code4rena and Sherlock contests. Try to spot findings yourself before reading the writeup. This is how every top auditor trained.
-
Start with CodeHawks First Flights
First Flights are small audit contests designed for newer auditors. Prize pools are under $20K, scope is small, and competition is lighter. They build real submission history.
-
Enter your first full competition
Pick an active audit contest from the tracker above filtered by Solidity and a $50K-$200K prize range. Spend 20 to 40 hours on the contest, even if you only find one valid medium-severity issue.
-
Build a public track record
Publish your findings, share writeups on Twitter and Mirror, and start accumulating valid submissions across multiple platforms. A documented track record is what opens bug bounty access and full-time auditor roles.