Back to Proof of Audits Home

Your Security Work Should Pay You Today—and Build Your Career Tomorrow.

Get a base fee for completing routed review work. Earn additional rewards for accepted findings and validation. Then compete within your tier for monthly leaderboard bonuses funded by Proof of Audits’s eligible platform earnings. Your total score builds your career. Your monthly score growth creates another opportunity to earn.

Paid for the work. Rewarded for the impact. Recognized for consistent growth.

Built for auditors already proven on public platforms

Sherlock
Code4rena
Immunefi
Cantina
HackenProof
Auditor tier guide

T4 → T3 → T2 → T1

Know your tier, scope, and path forward

A tier is routing authority, not a vanity rank. It defines the depth of work you can receive and which lower-tier findings you can validate.

Swordfish Scout · Function-level precision

Enters first and strikes deep at functions, invariants, and focused proof-of-concept work.

Score

0–249

Reliability

60% min

Gate

Fewer than 5 validated findings or reliability below 60%

Work

Hunt function-level issues and submit findings for T3 validation

T4
Swordfish Scout
T4 · Function-level precision

Score threshold

0pts

Hammerhead · Structural sweeper

Methodically probes contracts with fuzzing, access-control checks, and structural review.

Score

250–599

Reliability

60% min

Gate

At least 5 validated findings; automatic when every gate passes

Work

Validate routed T4 reports before opening T3 contract-level hunting

T3
Hammerhead
T3 · Structural sweeper

Score threshold

0pts

Orca Warden · Cross-system strategist

Connects contracts, oracles, state transitions, and exploit paths into one coordinated review.

Score

600–1199

Reliability

75% min

Gate

At least 5 validated findings, native review history, and admin approval

Work

Validate routed T3 reports before cross-contract hunting

T2
Orca Warden
T2 · Cross-system strategist

Score threshold

0pts

Phantom Octopus · System-level authority

Sees the whole system: governance, MEV, economic game theory, and final sign-off.

Score

1200+

Reliability

85% min

Gate

At least 5 validated findings, native review history, 2 T1 vouches, admin approval

Work

Validate routed T2 reports before leading system-level review

T1
Phantom Octopus
T1 · System-level authority

Score threshold

0+pts

How we decide your tier and assignments

Your computed tier shows what the evidence supports. Your effective tier is what the network permits today after caps and human review.

1

Verify identity

Wallet ownership, public handles, and accepted-finding evidence.

2

Compute gates

Score, reliability, validated-finding sample, and native-history gates.

3

Apply path rules

T3 automatic path or T2/T1 human approval requirements.

4

Route by fit

Exact-tier work when skills, availability, and conflict checks match.

One Platform. Six Ways to Earn.

BRING YOUR REPUTATION

Bring the reputation you already earned.

You should not have to restart from zero on every platform. Connect your verified work from Sherlock, Code4rena, Immunefi, Cantina, CodeHawks, Hats, HackenProof, GitHub, and approved private audit evidence.

Proof of Audits verifies ownership, accepted findings, severity history, specialties, reliability, and duplicate records.

Your past work becomes your starting point—not a forgotten profile link.

Sherlock
Code4rena
Immunefi
Cantina
HackenProof
Verified Identity

Wallet + public handles

Proof of Work

Accepted findings only

Skill Matching

AMM, lending, bridge, oracle, vaults

Routing Eligibility

Tier + skill + COI checked

From public proof to routed work

Same path as the score engine: prove handles, import history, score and classify, then route by fit.

01

Create the auditor profile

Wallet session, contact details, and public audit handles.

02

Prove handle ownership

A bio challenge ties each public profile back to the applicant.

03

Import verified history

Accepted findings, severity patterns, platforms, and contest evidence.

04

Score and classify

Tier, skill tags, reliability signals, and validation baseline.

05

Route by fit

Eligible work is based on exact tier, skill match, availability, and conflict checks.

06

Build live reputation

Accepted work, validation accuracy, closeout events, and reliability affect future routing.

Keep the proof

After closeout, verified work updates your Auditor Passport—not just a one-time payout.

Accepted findings
Specialties
Reliability
Validation accuracy
Tier
Score
Eligibility

Your Progress Can Earn a Monthly Bonus

Base fees and finding rewards pay you for individual engagements. The Monthly Auditor Reward Pool recognizes consistent contribution across the Proof of Audits ecosystem.

Monthly Leaderboard Bonus

Grow your score. Share in Proof of Audits's monthly success.
Open live leaderboard
Published % of eligible monthly platform earnings
Monthly Auditor Reward Pool
Tier Pools
Top 3 in each tier
Swordfish Scout
T4Swordfish Scout

Function-level contributors compete only inside their own tier for monthly bonus awards.

Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
Hammerhead
T3Hammerhead

Contract reviewers and validators compete only inside their own tier for monthly bonus awards.

Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
Orca Warden
T2Orca Warden

Cross-contract reviewers compete only inside their own tier for monthly bonus awards.

Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
Phantom Octopus
T1Phantom Octopus

System-level reviewers compete only inside their own tier for monthly bonus awards.

Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
Rankings are based on monthly score gained, not lifetime score.
Live ranks are shown on the auditor leaderboard when settlement data exists.

* Proof of Audits funds the Monthly Auditor Reward Pool using a published portion of eligible platform earnings. Auditor bonuses are performance rewards and do not represent equity, ownership, dividends, or a claim on Proof of Audits revenue. Eligible platform earnings include settled platform fees but exclude protocol bounty deposits, auditor base-fee funds, refundable balances, taxes, chargebacks, and unsettled or disputed payments. For tier changes, an auditor competes in the tier where they spent the greatest number of eligible days during the monthly cycle.

Calculate Your Earnings

See how base fees, unique findings, duplicate protections, and validation rewards compound into your final settlement.

The Settlement Formula

Base review fee(Completed scope review)
+ Accepted unique findings(100% of severity pool weight)
+ Cross-scope missed findings(Bounty + slashed base fee percentage)
+ Valid duplicate findings(Score/Rep increase only, $0 payout)
+ Validation rewards(For co-reviewer validation)
− Published deductions(For missed bugs on co-scope)
− Platform fee(5% standard fee)
= Final settlementNet Wallet Payout

Proof of Audits pays for completed review work under the accepted route terms, so a clean report can still earn its base review fee. Valid findings are additional rewards on top of that settled base.

Bounty Severity Ranges

SeverityPool ShareRep Points
Critical35%+15 points
High30%+7 points
Medium25%+3 points
Low / QA10%+1 point

* Pool shares are from the bounty pool portion of your tier share (50% of tier share).

* Missed basic bug = −10 reputation. Promotion: T4→T3 = 50 rep + 10 tasks, T3→T2 = 150 rep + 30 tasks, T2→T1 = 300 rep + 60 tasks.

* Submission stake: 3% of base fee per submission. Appeal stake: 5% of base fee.

Payout Estimator

Explain My Payout

Full-stack pool: $23,000 → Tier share: $5,750 → Base: $719 / Bounty: $2,875

Unique High Finding
1
Valid Duplicates
1
Cross-Scope MissedBounty + Slashed base fee
0
Cross-Scope Not MissedScore only (No Payout)
1
Base review fee$719
1 accepted High finding+$863
1 duplicate finding+$0 (+15 Reputation Pts)
1 cross-scope not-missed bug+$0 (+15 Reputation Pts)
Validation reward+$250
Platform fee (5%)-$128
Expected Net Settlement* Cross-scope findings earn bounty plus the base fee of the missed percentage only when missed. Duplicates and non-missed cross-scope findings receive score increase only.
$2,423

The Score Engine Pipeline.

Four stages that convert verified public security history into prioritized routing weight — the same trail as onboarding: import work, clean telemetry, profile skills, then allocate tier.

Walkthrough of the full path sits above in Bring your reputation (profile → proof → score → route). Lifetime score drives tier; monthly score growth drives the bonus board.

01
STAGE 01

Master Sync

Primary Hub & Handle Verification

Auditors submit their public handles. Sherlock acts as the primary hub, while mapped profiles from Code4rena, Immunefi, Cantina, Hats, and HackenProof are linked and de-duplicated. Ownership is verified through a unique bio challenge on the primary profile.

Sherlock
Code4rena
Immunefi
Cantina
HackenProof
pipeline_telemetry_v1.0
02
STAGE 02

Telemetry Cleanup

Public History Collection & De-duplication

Once handles are verified, Proof of Audits collects public findings from connected platforms and removes duplicate records, mirrored reports, and repeated entries to preserve a clean, high-fidelity audit history.

Duplicates Removed

27.4%

pipeline_telemetry_v1.0
03
STAGE 03

Skill Profiling

Manual Specialist Tagging

Verified findings are reviewed and tagged into protocol domains such as AMMs, lending, bridges, and RWAs, along with bug classes like reentrancy, access control, logic, and oracle manipulation. This is manually profiled for routing accuracy—not our scoring system-only tagging.

DOMAINS
AMMsLendingBridgesRWAs..
BUG CLASSES
ReentrancyAccessLogicOracle..
pipeline_telemetry_v1.0
04
STAGE 04

Tier Allocation

Formula-Driven Tiering

Severity mix, validation accuracy, and verified history flow into the scoring engine to compute the final routing score and assign the Sea Warrior Tier from T4 to T1. Tier safeguards help prevent volume gaming.

T1Phantom Octopus
T2Orca Warden
T3Hammerhead
T4Swordfish Scout
pipeline_telemetry_v1.0
Proof of Audits Pipeline

Transparent. Verifiable. Routing you can trust.

TRACE ID: 0xPROOF_AUDITS_PIPELINE_0081

Get routed to work that matches your skills.

///

Proof of Audits does not route audits only by leaderboard position. Routing considers your tier, verified specialties, protocol architecture, bug-class experience, availability, conflict-of-interest status, validation accuracy, and reliability history.

An auditor experienced in lending and oracle manipulation should receive lending and oracle-related scopes—not unrelated work simply because a slot is open.

Receive work that matches what you have proven you can review.

Routing rules before work opens

  • Applying does not instantly route audit work.
  • Unverified handles do not count toward score or tier.
  • T4, T3, T2, and T1 can receive hunting or validation work based on phase and assignment.
  • T0 handles final review, appeals, report approval, and settlement evidence.

Waterfall Review Cycle

Engagements cascade from T4 function-level sweeps down to T1 whole-system signoffs. T0 acts as the ultimate verification layer.

T4T3T2T1T0
T4Function Review
T3Contract Review
T2Cross-Contract Review
T1Whole-System Review
T0Final Review & Validation
function(){}
T4Swordfish Scout

Function Review

Focused review of assigned functions, invariants, and first routed findings.

Precise reports with clear proof and scoped impact.
CONTRACTStateFunctionsModifiersEvents
T3Hammerhead

Contract Review

Contract-level review plus validation of T4 reports before escalation.

Strong contract reasoning, severity calls, and validation accuracy.
ACTIVE PATH
CONTRACT ACONTRACT BROUTERBRIDGEORACLE
T2Orca Warden

Cross-Contract Review

Integration paths, oracle and state dependencies, and validation of T3 reports.

TARGET ELIGIBILITYEvidence across multiple contracts and connected exploit paths.
GOVERNANCEINCENTIVESUSERSPROTOCOL COREMODULESORACLESINTEGRATIONSINFRASTRUCTURE
T1Phantom Octopus

Whole-System Review

System-level risk review across architecture, incentives, governance, and final escalation.

Broad judgment, mature severity calibration, and reliable handoff notes.
T0Turtle Arbiter

Final Review and Validation

Appeals, missed-bug attribution, private-note validation, final report approval, and settlement evidence.

Independent closeout judgment. T0 is not a zero-engagement hunting role.

Your Score. Your Tier. Your Impact.

Your verified score, reliability, validated finding sample, and Proof of Audits-native history determine your computed auditor tier. T3 can be applied automatically when gates pass; T2 and T1 require review. T0 is a separate final-review appointment.

Built on Merit

Verified history only. Evidence, reliability, native findings, and reviewed promotions keep routing tied to proven performance.

Verified evidence

Public handles, accepted findings, severity, uniqueness, rank, difficulty, and recency build the starting record.

Fit-based routing

Work is matched by exact tier, skill tags, availability, protocol architecture, and conflict checks.

Validation responsibility

T3 validates routed T4 reports, T2 validates routed T3 reports, and T1 validates routed T2 reports.

Monthly score delta

Monthly bonus boards rank score gained during the cycle, separate from lifetime score.

How Your Score Determines Your Tier

Growth path in one place: T4 builds function-level proof → T3 proves contract consistency and validates T4 → T2 owns cross-contract risk → T1 leads system review → T0 is a separate final-review appointment. Lifetime score moves your tier; monthly score growth is a separate bonus path.

T4Entry
4

Swordfish Scout

Score: < 250 or gated

Reliability: < 60% / unknown

Build verified review evidence. Default entry and proof-building tier until sample-size, score, reliability, and review gates clear.

  • Routed function-level work
  • Submit focused findings
  • Build 5 validated findings
  • Eligible for T3 after gates pass
Foundation Phase
T3Participate
3

Hammerhead

Score: 250 - 599

Reliability: >= 60%

Review contracts and validate focused findings. Contract-level review, structural fuzzing, and validation of T4 reports before escalation.

  • Submit contract findings
  • Validate T4 reports
  • Skill tags drive routing
  • Auto tier when gates pass
Growth Phase
T2Validate
2

Orca Warden

Score: 600 - 1199

Reliability: >= 75%

Review cross-contract systems and exploit paths. Cross-contract and integration review, with validation responsibility for T3 escalations.

  • Validate findings from T3
  • Exploit-path review
  • Priority complex scopes
  • Requires admin approval
Expert Phase
T1Lead
1

Phantom Octopus

Score: >= 1200

Reliability: >= 85%

Lead whole-system review and senior validation. Whole-system review across governance, MEV, economic design, and final escalations.

  • System-level validation
  • Mentor & verify auditors
  • Access to premium scopes
  • Requires 2 T1 vouches + admin
Leadership Phase
T0Govern
0

Turtle Arbiter

Score: Appointment

Type: Final Review

Independent final-review appointment. Final review, appeals, report approval, missed-bug attribution, and settlement evidence.

  • Final report approval
  • Appeals and attribution
  • Settlement quality gate
  • Independent closeout authority
Governance Phase

What You Unlock At Higher Tiers

Higher Rewards

Better payout bands, priority fee allocations, and bonus pool distributions. Accepted routes show a base review fee by tier, with higher tiers carrying larger base allocations when scope and eligibility match.

Validation Powers

Validate downstream findings, construct exploit paths, and handle higher-tier escalations.

Priority Access

Get priority access where exact tier, skill tags, availability, and COI checks match.

Reputation Boost

Build verified on-chain credibility, reputation points, and global recognition.

Ecosystem Influence

Senior reviewers shape standards through validations, appeals, and final-report evidence.

Your Score Uses These Evidence Streams

Onboarding Import
Baseline

Verified public history establishes the starting score using accepted findings, severity, uniqueness, outcome, rank, difficulty, and recency.

Core Findings
Delta

At T0 closeout, confirmed findings apply severity x complexity deltas: Critical +160, High +90, Medium +35, Low +10.

Reliability
Gate

Reliability must be known and meet tier floors: T3 60%, T2 75%, T1 85%. Fewer than 5 validated findings stays T4.

Slashing Guard
Active

Invalid findings, copycats, wrong validations, denied appeals, and missed own-scope bugs reduce score at closeout.

External-only reputation can compute a strong score, but without Proof of Audits-native findings it is capped at T3; T2/T1 remain review-gated.
Next Milestones

Keep Improving

Your tier can grow as you grow. Keep participating in audits, sharpening your findings, and validating invariants to unlock the next levels of authority.

Submit Application
Trace Ref: M5_TIER_DECISION + CORE_CLOSEOUT_V1

Why Auditors Choose Proof of Audits

Predictable duplicate economics, tier growth you can earn, and reputation that travels with your verified work instead of staying trapped inside one contest page.

Duplicate economics

Duplicates in your own scope only raise your score. Cross-scope, you earn a share of the bounty plus the base fee of the missed percentage — only when the assigned auditor missed it.

Tiered growth

T3 unlocks automatically once score, reliability, and sample-size gates pass. T2 and T1 stay review-gated, so authority is earned, never guessed.

Validation work

Move from focused hunting into validation, escalation, and final-review work through the T4 → T1 cascade.

Proof you keep

Verified work feeds your Proof of Audits score, public profile, and protocol trust evidence — not a single platform's leaderboard.

What matters to youProof of AuditsContests & firms today

Duplicate payout clarity

When several researchers find the same bug.

Duplicates in your own scope are score-only. In other scopes you earn a share of the bounty plus the base fee of the missed percentage — and only when the assigned auditor missed it.

Contest pools shrink with every duplicate: Code4rena splits a finding by ≈0.9^(n−1) ÷ n, Sherlock divides the pool evenly across valid duplicates, and Immunefi pays only the first valid report.

Code4renaSherlockImmunefi

Career progression

How work turns into higher authority.

T4 → T1 has explicit score, reliability, finding-sample, native-history, vouch, and review gates.

Platform rank and reputation are local to each site and rarely convert into portable routing authority elsewhere.

Code4renaSherlock

Validation responsibility

Who reviews downstream findings.

T3 validates T4, T2 validates T3, T1 handles system-level validation, and T0 closes report, appeal, and settlement evidence.

Judging, triage, and mediation depend on each platform's judges, the client, or a private firm's internal process.

SherlockCantina

Payout governance

How money moves after finality.

Payouts move after settlement lock, payout request, and KYC gates, with the 5% auditor-side fee stated up front in policy.

Payout terms, duplicate treatment, timing, and project involvement vary contest by contest, bounty by bounty, and firm by firm.

ImmunefiCantina

Accountability

What happens when quality fails.

Invalid findings, copycats, wrong validations, denied appeals, and missed own-scope bugs all reduce score at T0 closeout.

Downside is usually limited to duplicate dilution, lost judge signal, or a platform-specific lead-role penalty.

Code4renaSherlock

Visibility

How your work is seen later.

Approved work feeds auditor profiles, leaderboards, trust passports, and protocol-facing proof surfaces.

Recognition normally stays inside one leaderboard, contest page, report credit, or private firm brand.

Code4renaImmunefi

Follow-on work

Beyond one finding submission.

Invariant, Sentinel, post-audit, validation, and final-review surfaces open more ways to prove skill when enabled.

Contests and bounties often end at judging, reward distribution, or a static report unless a separate engagement is bought.

CantinaImmunefi
How a duplicate finding pays across the market
Proof of Audits

Score-only in scope

Own-scope duplicates raise your score instead of diluting pay.

Code4rena

≈0.9^(n−1) split

Each extra duplicate shrinks every finder's slice of the pool.

Sherlock

Even pool split

Reward divided across valid duplicates of the same severity.

Immunefi

First valid report

Later duplicates of a known bug usually earn nothing.

Here, verified skill becomes routing power.

Duplicate models above reflect each platform's published payout rules; the Proof of Audits column reflects tier and closeout policy. Compared for auditors deciding where their work counts.

Before You Accept a Route

Your protections and every rule that can affect pay, score, and reputation — shown before you commit.

No hidden payout rules. No unexplained slashing. No silent score changes. Every engagement shows its scope, compensation, duplicate policy, accountability limits, judging process, and appeal window before acceptance.
Policy v1.0Effective 21 Jun 2026

1. Published compensation

Assigned scope, base fees, platform fee, and finding bounty structures are fully detailed before you accept a route.

2. Locked scope

The target code commits and boundaries are locked. Clients cannot sneak in code changes or extra folders during your review.

3. Duplicate rules

Duplicates yield score increases only. For cross-scope reviews, you can earn a percentage of the bounty plus the base fee of the missed percentage only when the assigned auditor missed it.

4. Maximum slashing cap

Your downside is capped. Missed bugs cannot create unlimited negative balances. Any deduction must pass standard attribution rules and the appeal window.

5. Written judging reasons

Every decision regarding classification, validity, duplicates, severity, or penalty includes a published written technical explanation.

6. Appeal window

Auditors have a standard appeal window (typically 48 hours) to dispute any preliminary judgements before closeout.

7. Settlement requirements

Settlement timelines, payment mechanisms, and KYC rules are transparently defined. No surprise deductions or delayed payouts.

Still have a question that's not covered?

Our auditor support team is here to help you.

Contact Auditor Support
Workflow Pipeline

From Submission to Settlement

Know what happens after you submit.

01

Submission

You submit your report before the deadline.

02

Initial Validation

Assigned validator reviews within 48–72 hours.

03

Duplicate Grouping

Findings are grouped and scored.

04

Preliminary Judgment

You receive results with reasons.

05

Appeal Window

48 hours to appeal any decision.

06

Final Judgment

T0 reviewer confirms final decisions.

07

Settlement

Payout is processed after all checks.

Ready to get routed to the right audits?

Join Proof of Audits and turn your verified skills into real impact and rewards.

Apply as Auditor