Sherlock (sherlock.xyz) Live Audit Contests
Last updated Jul 21, 2026 · 20:58 UTC
Showing 181–200 of 301
301 audit contests
| Protocol | Source | Prize | Window | Link |
|---|---|---|---|---|
|
MagicSea - the native DEX on the IotaEVM
|
|
$28K |
Jul 01 - Jul 11, 2024
10 days
|
View |
|
Union Finance Update #2
|
|
$12K |
Jul 08 - Jul 13, 2024
5 days
|
View |
|
Aloe Update
|
|
$12K |
Jul 08 - Jul 16, 2024
8 days
|
View |
|
Super Boring
|
|
$18K |
Jul 11 - Jul 17, 2024
6 days
|
View |
|
Allora
|
|
$78K |
Jun 28 - Jul 19, 2024
21 days
|
View |
|
Velocimeter
|
|
$67K |
Jul 01 - Jul 25, 2024
24 days
|
View |
|
Exactly Protocol Update - Staking Contract
|
|
$8K |
Jul 22 - Jul 25, 2024
3 days
|
View |
|
Kwenta Staking Rewards Upgrade
|
|
$8K |
Jul 31 - Aug 03, 2024
3 days
|
View |
|
MakerDAO Endgame
|
|
$415K |
Jul 08 - Aug 05, 2024
28 days
|
View |
|
Winnables Raffles
|
|
$8K |
Aug 16 - Aug 20, 2024
4 days
|
View |
|
Sentiment V2
|
|
$29K |
Aug 14 - Aug 24, 2024
10 days
|
View |
|
Midas - Instant Minter/Redeemer
|
|
$22K |
Aug 19 - Aug 27, 2024
8 days
|
View |
|
Rumpel Point Tokenization Protocol
|
|
$10K |
Aug 26 - Aug 29, 2024
3 days
|
View |
|
Velar Artha PerpDEX
|
|
$35K |
Aug 30 - Sep 09, 2024
10 days
|
View |
|
ZeroLend One
|
|
$44K |
Aug 22 - Sep 10, 2024
19 days
|
View |
|
Cork Protocol
|
|
$15K |
Aug 29 - Sep 10, 2024
12 days
|
View |
|
Perennial V2 Update #3
|
|
$54K |
Aug 26 - Sep 13, 2024
18 days
|
View |
|
Flayer
|
|
$46K |
Sep 02 - Sep 15, 2024
13 days
|
View |
|
Boost Core Incentive Protocol
|
|
$34K |
Sep 11 - Sep 20, 2024
9 days
|
View |
|
Saffron Lido Vaults
|
|
$12K |
Sep 16 - Sep 21, 2024
5 days
|
View |
Union Finance Update #2
Aloe Update
Super Boring
Allora
Velocimeter
Exactly Protocol Update - Staking Contract
Kwenta Staking Rewards Upgrade
MakerDAO Endgame
Winnables Raffles
Sentiment V2
Midas - Instant Minter/Redeemer
Rumpel Point Tokenization Protocol
Velar Artha PerpDEX
ZeroLend One
Cork Protocol
Perennial V2 Update #3
Flayer
Boost Core Incentive Protocol
Saffron Lido Vaults
About Sherlock
Sherlock launched in 2022 with a unique twist: protocols that pass a Sherlock audit can buy on-chain coverage backed by Sherlock and its watson community. Contests typically run 7 to 30 days with $50,000-$300,000 prize pools. Watsons (Sherlock auditors) submit findings, the judging panel determines severity, and the prize is split across valid unique findings.
This page shows only contests aggregated from Sherlock. For audit contests on other platforms, see the full Web3 audit competition tracker.
Smart Contract Audit Competition & Bug Bounty Platforms Compared
Six major platforms host the Web3 audit competitions and smart contract bug bounty programs aggregated above. Click any platform to see only its active contests.
| Platform | Type | Typical Prize | Contest Length | Best For |
|---|---|---|---|---|
|
|
Audit contests | $50K to $500K | 3 to 14 days | DeFi protocols pre-launch |
|
|
Contests + bounties | $50K to $300K | 7 to 30 days | Insurance-backed audits |
|
|
Audit contests + First Flights | $5K to $200K | 3 to 21 days | Newer auditors building a track record |
|
|
Mega-comps + bounties | $200K to $2M+ | 14 to 30 days | Experienced researchers, high-value protocols |
|
|
Ongoing bug bounties | Up to $15M per critical | Ongoing | Production protocol vulnerability hunting |
|
|
Bounties + crowdsourced audits | $1K to $1M+ | Ongoing or time-boxed | Managed Web3 programs and exchange/protocol bounties |
Frequently Asked Questions
What is the difference between Sherlock and Code4rena?
Sherlock contests have stricter judging and include an insurance-backed bounty period afterward. Code4rena focuses purely on time-boxed contests. Sherlock prize pools are typically smaller ($50K-$300K) than Code4rena ($50K-$500K), but Sherlock watsons earn from post-contest bounties too.
How do I find active Sherlock contests?
Every currently-active Sherlock audit competition appears in the listing above, pulled from the Sherlock API every 2 hours. You can also browse all contests directly on audits.sherlock.xyz.
What are the best smart contract bug bounty platforms?
The leading Web3 bug bounty platforms are Immunefi (largest, $15M max payouts on DeFi protocols), Cantina (Spearbit's bounty program plus audit competitions), HackenProof (managed Web3 bounties and crowdsourced audits), Sherlock (audit contests with insurance-backed bounties), and Code4rena (best known for time-boxed audit competitions). Codehawks rounds out the field with Cyfrin-run contests focused on emerging protocols and beginner-friendly First Flights.
Which audit competition platform pays the most?
Cantina runs the largest audit competitions ($2M+ prize pools for protocols like EigenLayer and Uniswap v4). Immunefi pays the highest per-bug bounty (up to $15M for critical findings). Code4rena and Sherlock typically run $100K-$500K audit contests. Codehawks First Flights are smaller but accessible to newer auditors.
How do smart contract audit competitions work?
Audit competitions invite security researchers to review a protocol's smart contract code for a fixed prize pool over 1-4 weeks. Rewards are split based on unique valid findings, weighted by severity (critical, high, medium). Code4rena, Sherlock, Codehawks, and Cantina are the main platforms.
How much can you earn in a smart contract audit competition?
Top auditors earn $10,000-$500,000+ per competition. Cantina and Code4rena regularly run $500K-$2M prize pool contests. Bug bounties can pay up to $15M per critical finding on platforms like Immunefi.
What is the difference between a bug bounty and an audit contest?
Audit contests run for a fixed time window with a fixed prize pool shared among all valid findings. Bug bounties are ongoing programs where each valid submission earns a direct per-vulnerability reward (often $50K-$15M depending on severity). Bug bounties require finding a real vulnerability in production code.
How do I get started with smart contract auditing?
Learn the most common vulnerability classes first: reentrancy, flash loan attacks, oracle manipulation, and access control. The SCH Smart Contract Hacking Course covers all the core attack patterns that audit competitions test, starting from zero experience.
How to Start Competing in Smart Contract Audits
A practical path from learning vulnerability classes to submitting your first contest finding.
-
Learn the core vulnerability classes
Master reentrancy, access control, oracle manipulation, flash loan attacks, and arithmetic overflows. These five classes account for most contest findings.
-
Practice on retired contests
Read every public report from past Code4rena and Sherlock contests. Try to spot findings yourself before reading the writeup. This is how every top auditor trained.
-
Start with CodeHawks First Flights
First Flights are small audit contests designed for newer auditors. Prize pools are under $20K, scope is small, and competition is lighter. They build real submission history.
-
Enter your first full competition
Pick an active audit contest from the tracker above filtered by Solidity and a $50K-$200K prize range. Spend 20 to 40 hours on the contest, even if you only find one valid medium-severity issue.
-
Build a public track record
Publish your findings, share writeups on Twitter and Mirror, and start accumulating valid submissions across multiple platforms. A documented track record is what opens bug bounty access and full-time auditor roles.