HackenProof Live Bug Bounty Programs

5 Active contests
$103,200$103K Active prize pool
211 Bug bounties
1 Platforms

Last updated Jul 20, 2026 · 14:49 UTC

Showing 161–180 of 291

80 audit contests211 bug bounty programs

Protocol Source Prize Window Link
Openware
webblockchainsmart contract
Hackenproof Finished
$5K max
Nov 12 - Jul 08, 2023
603 days
View
Exzo Network Protocol
smart contract
Hackenproof Finished
$100K max
May 02 - Jul 09, 2023
68 days
View
Exzo Network Web & API
webappsblockchain
Hackenproof Finished
$10K max
May 02 - Jul 09, 2023
68 days
View
FitBurn Smart Contracts
smart contract
Hackenproof Finished
$100K max
May 01 - Jul 21, 2023
81 days
View
Pandora Smart Contract
smart contract
Hackenproof Finished
$50K max
Feb 18 - Aug 01, 2023
529 days
View
NXT Permission Smart Contract
smart contract
Hackenproof Finished
$10K max
Aug 17 - Aug 18, 2023
1 day
View
Local Traders Smart Contracts
smart contract
Hackenproof Finished
$20K max
May 31 - Aug 31, 2023
92 days
View
Polkalokr
blockchainsmart contractweb
Hackenproof Finished
$5K max
Oct 26 - Sep 07, 2023
316 days
View
VirtuSwap Smart Contract
smart contract
Hackenproof Finished
$10K max
Dec 21 - Sep 12, 2023
265 days
View
Ternoa Smart Contracts
blockchainsmart contract
Hackenproof Finished
$100K max
Aug 09 - Oct 19, 2023
436 days
View
Aurora Audit Contest
Audit contest
Hackenproof Finished
$40K
Oct 09 - Oct 29, 2023
20 days
View
Swisstronik Blockchain Stability
blockchain
Hackenproof Finished
$500 max
Sep 04 - Nov 15, 2023
72 days
View
Swisstronik Core
blockchain
Hackenproof Finished
$4K max
Sep 04 - Nov 15, 2023
72 days
View
Avalanche Bridge
webblockchainsmart contract
Hackenproof Finished
$100K max
Jul 15 - Dec 04, 2023
507 days
View
Avalanche Protocol
blockchainsmart contract
Hackenproof Finished
$100K max
Mar 30 - Dec 04, 2023
979 days
View
Avalanche Websites and APIs
webblockchainsmart contract
Hackenproof Finished
$10K max
Mar 30 - Dec 04, 2023
979 days
View
Core
webappsblockchain
Hackenproof Finished
$10K max
Jul 14 - Dec 04, 2023
508 days
View
Humanode Competitive Developer Initiative Program
blockchain
Hackenproof Finished
Aug 01 - Dec 27, 2023
148 days
View
ENVELOP Smart Contracts
smart contract
Hackenproof Finished
$3K max
Jan 01 - Feb 02, 2024
32 days
View
Bluefin Audit Contest
Audit contest
Hackenproof Finished
$45K
Feb 13 - Mar 17, 2024
33 days
View
Loading timeline...
Hackenproof Finished

FitBurn Smart Contracts

$100K Max bounty
May 01 - Jul 21, 2023
View on Hackenproof
Hackenproof Finished

NXT Permission Smart Contract

$10K Max bounty
Aug 17 - Aug 18, 2023
View on Hackenproof
Hackenproof Finished

Local Traders Smart Contracts

$20K Max bounty
May 31 - Aug 31, 2023
View on Hackenproof
Hackenproof Finished

VirtuSwap Smart Contract

$10K Max bounty
Dec 21 - Sep 12, 2023
View on Hackenproof
Hackenproof Finished

Swisstronik Blockchain Stability

$500 Max bounty
Sep 04 - Nov 15, 2023
View on Hackenproof
Hackenproof Finished

Avalanche Websites and APIs

$10K Max bounty
Mar 30 - Dec 04, 2023
View on Hackenproof
Hackenproof Finished

Humanode Competitive Developer Initiative Program

Aug 01 - Dec 27, 2023
View on Hackenproof

About HackenProof

HackenProof is Hacken's Web3 bug bounty and crowdsourced audit platform. It combines ongoing vulnerability reward programs with time-boxed audit programs for smart contracts, exchanges, wallets, bridges, and L1/L2 ecosystems.

This page shows only Web3-relevant programs aggregated from HackenProof. For audit contests and bounties on other platforms, see the full Web3 audit competition tracker.

Smart Contract Audit Competition & Bug Bounty Platforms Compared

Six major platforms host the Web3 audit competitions and smart contract bug bounty programs aggregated above. Click any platform to see only its active contests.

Comparison of the major smart contract audit competition and bug bounty platforms.
Platform Type Typical Prize Contest Length Best For
Code4rena Audit contests $50K to $500K 3 to 14 days DeFi protocols pre-launch
Sherlock Contests + bounties $50K to $300K 7 to 30 days Insurance-backed audits
CodeHawks Audit contests + First Flights $5K to $200K 3 to 21 days Newer auditors building a track record
Cantina Mega-comps + bounties $200K to $2M+ 14 to 30 days Experienced researchers, high-value protocols
Immunefi Ongoing bug bounties Up to $15M per critical Ongoing Production protocol vulnerability hunting
HackenProof Bounties + crowdsourced audits $1K to $1M+ Ongoing or time-boxed Managed Web3 programs and exchange/protocol bounties

Frequently Asked Questions

What kind of programs does HackenProof run?

HackenProof runs public bug bounty programs, private bounty programs, and crowdsourced audits. In Web3, its listings include smart contracts, bridges, exchanges, wallets, and L1/L2 ecosystems.

How do I submit a report on HackenProof?

Open the protocol program page on hackenproof.com, review the scope, severity, reputation, and proof-of-concept requirements, then submit through the HackenProof dashboard.

What are the best smart contract bug bounty platforms?

The leading Web3 bug bounty platforms are Immunefi (largest, $15M max payouts on DeFi protocols), Cantina (Spearbit's bounty program plus audit competitions), HackenProof (managed Web3 bounties and crowdsourced audits), Sherlock (audit contests with insurance-backed bounties), and Code4rena (best known for time-boxed audit competitions). Codehawks rounds out the field with Cyfrin-run contests focused on emerging protocols and beginner-friendly First Flights.

Which audit competition platform pays the most?

Cantina runs the largest audit competitions ($2M+ prize pools for protocols like EigenLayer and Uniswap v4). Immunefi pays the highest per-bug bounty (up to $15M for critical findings). Code4rena and Sherlock typically run $100K-$500K audit contests. Codehawks First Flights are smaller but accessible to newer auditors.

How do smart contract audit competitions work?

Audit competitions invite security researchers to review a protocol's smart contract code for a fixed prize pool over 1-4 weeks. Rewards are split based on unique valid findings, weighted by severity (critical, high, medium). Code4rena, Sherlock, Codehawks, and Cantina are the main platforms.

How much can you earn in a smart contract audit competition?

Top auditors earn $10,000-$500,000+ per competition. Cantina and Code4rena regularly run $500K-$2M prize pool contests. Bug bounties can pay up to $15M per critical finding on platforms like Immunefi.

What is the difference between a bug bounty and an audit contest?

Audit contests run for a fixed time window with a fixed prize pool shared among all valid findings. Bug bounties are ongoing programs where each valid submission earns a direct per-vulnerability reward (often $50K-$15M depending on severity). Bug bounties require finding a real vulnerability in production code.

How do I get started with smart contract auditing?

Learn the most common vulnerability classes first: reentrancy, flash loan attacks, oracle manipulation, and access control. The SCH Smart Contract Hacking Course covers all the core attack patterns that audit competitions test, starting from zero experience.

How to Start Competing in Smart Contract Audits

A practical path from learning vulnerability classes to submitting your first contest finding.

  1. Learn the core vulnerability classes

    Master reentrancy, access control, oracle manipulation, flash loan attacks, and arithmetic overflows. These five classes account for most contest findings.

  2. Practice on retired contests

    Read every public report from past Code4rena and Sherlock contests. Try to spot findings yourself before reading the writeup. This is how every top auditor trained.

  3. Start with CodeHawks First Flights

    First Flights are small audit contests designed for newer auditors. Prize pools are under $20K, scope is small, and competition is lighter. They build real submission history.

  4. Enter your first full competition

    Pick an active audit contest from the tracker above filtered by Solidity and a $50K-$200K prize range. Spend 20 to 40 hours on the contest, even if you only find one valid medium-severity issue.

  5. Build a public track record

    Publish your findings, share writeups on Twitter and Mirror, and start accumulating valid submissions across multiple platforms. A documented track record is what opens bug bounty access and full-time auditor roles.