Sherlock (sherlock.xyz) Live Audit Contests

3 Active contests
$162,750$163K Active prize pool
0 Bug bounties
1 Platforms

Last updated Jul 21, 2026 · 10:55 UTC

Showing 261–280 of 301

301 audit contests

Protocol Source Prize Window Link
Usual ETH0
Solidity
Sherlock Finished
$39K
May 29 - Jun 05, 2025
7 days
View
DODO Cross-Chain DEX
Solidity
Sherlock Finished
$14K
Jun 02 - Jun 09, 2025
7 days
View
Superfluid Locker System
Solidity
Sherlock Finished
$14K
Jun 04 - Jun 11, 2025
7 days
View
Symbiotic Relay
Solidity
Sherlock Finished
$50K
Jun 19 - Jul 10, 2025
21 days
View
DeBank
Solidity
Sherlock Finished
$17K
Jul 03 - Jul 10, 2025
7 days
View
Notional Exponent
Solidity
Sherlock Finished
$37K
Jul 02 - Jul 18, 2025
16 days
View
Cap
Solidity
Sherlock Finished
$93K
Jul 10 - Jul 24, 2025
14 days
View
Mellow Flexible Vaults
Solidity
Sherlock Finished
$35K
Jul 14 - Jul 28, 2025
14 days
View
Allbridge Core Yield
Solidity
Sherlock Finished
$11K
Jul 25 - Jul 28, 2025
3 days
View
Oku Trade Order Types
Solidity
Sherlock Finished
$10K
Jul 28 - Jul 31, 2025
3 days
View
dHEDGE Update
Solidity
Sherlock Finished
$28K
Aug 04 - Aug 13, 2025
9 days
View
Malda
Solidity
Sherlock Finished
$42K
Jul 24 - Aug 14, 2025
21 days
View
Neutrl Protocol
Solidity
Sherlock Finished
$96K
Aug 18 - Aug 24, 2025
6 days
View
Yield Basis
Solidity
Sherlock Finished
$115K
Aug 18 - Sep 08, 2025
21 days
View
USG - Tangent
Solidity
Sherlock Finished
$28K
Aug 28 - Sep 11, 2025
14 days
View
Rezerve Money
Solidity
Sherlock Finished
$60K
Sep 03 - Sep 15, 2025
12 days
View
BMX Deli Swap
Solidity
Sherlock Finished
$19K
Sep 02 - Sep 16, 2025
14 days
View
Ammplify
Solidity
Sherlock Finished
$46K
Sep 02 - Sep 22, 2025
20 days
View
Dango DEX
Solidity
Sherlock Finished
$77K
Sep 15 - Sep 29, 2025
14 days
View
Brevis Pico ZKVM
Solidity
Sherlock Finished
$51K
Sep 01 - Sep 29, 2025
28 days
View
Loading timeline...
Sherlock Finished

DODO Cross-Chain DEX

$14K Prize pool
Jun 02 - Jun 09, 2025
View on Sherlock
Sherlock Finished

Superfluid Locker System

$14K Prize pool
Jun 04 - Jun 11, 2025
View on Sherlock
Sherlock Finished

Symbiotic Relay

$50K Prize pool
Jun 19 - Jul 10, 2025
View on Sherlock
Sherlock Finished

Notional Exponent

$37K Prize pool
Jul 02 - Jul 18, 2025
View on Sherlock
Sherlock Finished

Mellow Flexible Vaults

$35K Prize pool
Jul 14 - Jul 28, 2025
View on Sherlock
Sherlock Finished

Allbridge Core Yield

$11K Prize pool
Jul 25 - Jul 28, 2025
View on Sherlock
Sherlock Finished

Oku Trade Order Types

$10K Prize pool
Jul 28 - Jul 31, 2025
View on Sherlock
Sherlock Finished

Neutrl Protocol

$96K Prize pool
Aug 18 - Aug 24, 2025
View on Sherlock
Sherlock Finished

Brevis Pico ZKVM

$51K Prize pool
Sep 01 - Sep 29, 2025
View on Sherlock

About Sherlock

Sherlock launched in 2022 with a unique twist: protocols that pass a Sherlock audit can buy on-chain coverage backed by Sherlock and its watson community. Contests typically run 7 to 30 days with $50,000-$300,000 prize pools. Watsons (Sherlock auditors) submit findings, the judging panel determines severity, and the prize is split across valid unique findings.

This page shows only contests aggregated from Sherlock. For audit contests on other platforms, see the full Web3 audit competition tracker.

Smart Contract Audit Competition & Bug Bounty Platforms Compared

Six major platforms host the Web3 audit competitions and smart contract bug bounty programs aggregated above. Click any platform to see only its active contests.

Comparison of the major smart contract audit competition and bug bounty platforms.
Platform Type Typical Prize Contest Length Best For
Code4rena Audit contests $50K to $500K 3 to 14 days DeFi protocols pre-launch
Sherlock Contests + bounties $50K to $300K 7 to 30 days Insurance-backed audits
CodeHawks Audit contests + First Flights $5K to $200K 3 to 21 days Newer auditors building a track record
Cantina Mega-comps + bounties $200K to $2M+ 14 to 30 days Experienced researchers, high-value protocols
Immunefi Ongoing bug bounties Up to $15M per critical Ongoing Production protocol vulnerability hunting
HackenProof Bounties + crowdsourced audits $1K to $1M+ Ongoing or time-boxed Managed Web3 programs and exchange/protocol bounties

Frequently Asked Questions

What is the difference between Sherlock and Code4rena?

Sherlock contests have stricter judging and include an insurance-backed bounty period afterward. Code4rena focuses purely on time-boxed contests. Sherlock prize pools are typically smaller ($50K-$300K) than Code4rena ($50K-$500K), but Sherlock watsons earn from post-contest bounties too.

How do I find active Sherlock contests?

Every currently-active Sherlock audit competition appears in the listing above, pulled from the Sherlock API every 2 hours. You can also browse all contests directly on audits.sherlock.xyz.

What are the best smart contract bug bounty platforms?

The leading Web3 bug bounty platforms are Immunefi (largest, $15M max payouts on DeFi protocols), Cantina (Spearbit's bounty program plus audit competitions), HackenProof (managed Web3 bounties and crowdsourced audits), Sherlock (audit contests with insurance-backed bounties), and Code4rena (best known for time-boxed audit competitions). Codehawks rounds out the field with Cyfrin-run contests focused on emerging protocols and beginner-friendly First Flights.

Which audit competition platform pays the most?

Cantina runs the largest audit competitions ($2M+ prize pools for protocols like EigenLayer and Uniswap v4). Immunefi pays the highest per-bug bounty (up to $15M for critical findings). Code4rena and Sherlock typically run $100K-$500K audit contests. Codehawks First Flights are smaller but accessible to newer auditors.

How do smart contract audit competitions work?

Audit competitions invite security researchers to review a protocol's smart contract code for a fixed prize pool over 1-4 weeks. Rewards are split based on unique valid findings, weighted by severity (critical, high, medium). Code4rena, Sherlock, Codehawks, and Cantina are the main platforms.

How much can you earn in a smart contract audit competition?

Top auditors earn $10,000-$500,000+ per competition. Cantina and Code4rena regularly run $500K-$2M prize pool contests. Bug bounties can pay up to $15M per critical finding on platforms like Immunefi.

What is the difference between a bug bounty and an audit contest?

Audit contests run for a fixed time window with a fixed prize pool shared among all valid findings. Bug bounties are ongoing programs where each valid submission earns a direct per-vulnerability reward (often $50K-$15M depending on severity). Bug bounties require finding a real vulnerability in production code.

How do I get started with smart contract auditing?

Learn the most common vulnerability classes first: reentrancy, flash loan attacks, oracle manipulation, and access control. The SCH Smart Contract Hacking Course covers all the core attack patterns that audit competitions test, starting from zero experience.

How to Start Competing in Smart Contract Audits

A practical path from learning vulnerability classes to submitting your first contest finding.

  1. Learn the core vulnerability classes

    Master reentrancy, access control, oracle manipulation, flash loan attacks, and arithmetic overflows. These five classes account for most contest findings.

  2. Practice on retired contests

    Read every public report from past Code4rena and Sherlock contests. Try to spot findings yourself before reading the writeup. This is how every top auditor trained.

  3. Start with CodeHawks First Flights

    First Flights are small audit contests designed for newer auditors. Prize pools are under $20K, scope is small, and competition is lighter. They build real submission history.

  4. Enter your first full competition

    Pick an active audit contest from the tracker above filtered by Solidity and a $50K-$200K prize range. Spend 20 to 40 hours on the contest, even if you only find one valid medium-severity issue.

  5. Build a public track record

    Publish your findings, share writeups on Twitter and Mirror, and start accumulating valid submissions across multiple platforms. A documented track record is what opens bug bounty access and full-time auditor roles.