Function-level contributors compete only inside their own tier for monthly bonus awards.
Your Security Work Should Pay You Today—and Build Your Career Tomorrow.
Get a base fee for completing routed review work. Earn additional rewards for accepted findings and validation. Then compete within your tier for monthly leaderboard bonuses funded by Proof of Audits’s eligible platform earnings. Your total score builds your career. Your monthly score growth creates another opportunity to earn.
Paid for the work. Rewarded for the impact. Recognized for consistent growth.
Built for auditors already proven on public platforms
T4 → T3 → T2 → T1
Know your tier, scope, and path forward
A tier is routing authority, not a vanity rank. It defines the depth of work you can receive and which lower-tier findings you can validate.
Swordfish Scout · Function-level precision
Enters first and strikes deep at functions, invariants, and focused proof-of-concept work.
0–249
60% min
Fewer than 5 validated findings or reliability below 60%
Hunt function-level issues and submit findings for T3 validation

Score threshold
Hammerhead · Structural sweeper
Methodically probes contracts with fuzzing, access-control checks, and structural review.
250–599
60% min
At least 5 validated findings; automatic when every gate passes
Validate routed T4 reports before opening T3 contract-level hunting

Score threshold
Orca Warden · Cross-system strategist
Connects contracts, oracles, state transitions, and exploit paths into one coordinated review.
600–1199
75% min
At least 5 validated findings, native review history, and admin approval
Validate routed T3 reports before cross-contract hunting

Score threshold
Phantom Octopus · System-level authority
Sees the whole system: governance, MEV, economic game theory, and final sign-off.
1200+
85% min
At least 5 validated findings, native review history, 2 T1 vouches, admin approval
Validate routed T2 reports before leading system-level review

Score threshold
How we decide your tier and assignments
Your computed tier shows what the evidence supports. Your effective tier is what the network permits today after caps and human review.
Verify identity
Wallet ownership, public handles, and accepted-finding evidence.
Compute gates
Score, reliability, validated-finding sample, and native-history gates.
Apply path rules
T3 automatic path or T2/T1 human approval requirements.
Route by fit
Exact-tier work when skills, availability, and conflict checks match.
One Platform. Six Ways to Earn.
Base Review Fee
Get paid for correctly completing your assigned audit responsibilities.
Complete your assigned review correctly and earn the published base fee—even when no valid vulnerability is found.
Finding Rewards
Earn additional severity-based rewards for accepted security findings.
Your base fee pays for the review. Your findings reward the security impact you create.
Specialist Work
Earn for validation, fix verification, escalation, and post-audit checks.
Provide validation work or closeout review to earn specialized, steady secondary fees on engagements.
Monthly Leaderboard
Finish among the top three monthly score earners in your tier and share the reward pool.
Competitors in the same tier win bonuses based on score gained during the current monthly cycle.
Pre-Audit & Investor Review
Earn for pre-auditing protocol scope and performing investor risk reviews.
Review protocol architecture, verify scope boundaries, and conduct pre-audit risk assessments for investors before full execution.
Post-Audit Review
Earn for post-audit verification, invariant monitoring, and patch validation.
Validate protocol fixes, monitor post-deployment runtime invariants, and issue verified post-audit completion reports.
Bring the reputation you already earned.
You should not have to restart from zero on every platform. Connect your verified work from Sherlock, Code4rena, Immunefi, Cantina, CodeHawks, Hats, HackenProof, GitHub, and approved private audit evidence.
Proof of Audits verifies ownership, accepted findings, severity history, specialties, reliability, and duplicate records.
Your past work becomes your starting point—not a forgotten profile link.
Wallet + public handles
Accepted findings only
AMM, lending, bridge, oracle, vaults
Tier + skill + COI checked
From public proof to routed work
Same path as the score engine: prove handles, import history, score and classify, then route by fit.
Create the auditor profile
Wallet session, contact details, and public audit handles.
Prove handle ownership
A bio challenge ties each public profile back to the applicant.
Import verified history
Accepted findings, severity patterns, platforms, and contest evidence.
Score and classify
Tier, skill tags, reliability signals, and validation baseline.
Route by fit
Eligible work is based on exact tier, skill match, availability, and conflict checks.
Build live reputation
Accepted work, validation accuracy, closeout events, and reliability affect future routing.
Keep the proof
After closeout, verified work updates your Auditor Passport—not just a one-time payout.
Your Progress Can Earn a Monthly Bonus
Base fees and finding rewards pay you for individual engagements. The Monthly Auditor Reward Pool recognizes consistent contribution across the Proof of Audits ecosystem.
Monthly Leaderboard Bonus
Grow your score. Share in Proof of Audits's monthly success.Contract reviewers and validators compete only inside their own tier for monthly bonus awards.
Cross-contract reviewers compete only inside their own tier for monthly bonus awards.
System-level reviewers compete only inside their own tier for monthly bonus awards.
* Proof of Audits funds the Monthly Auditor Reward Pool using a published portion of eligible platform earnings. Auditor bonuses are performance rewards and do not represent equity, ownership, dividends, or a claim on Proof of Audits revenue. Eligible platform earnings include settled platform fees but exclude protocol bounty deposits, auditor base-fee funds, refundable balances, taxes, chargebacks, and unsettled or disputed payments. For tier changes, an auditor competes in the tier where they spent the greatest number of eligible days during the monthly cycle.
Calculate Your Earnings
See how base fees, unique findings, duplicate protections, and validation rewards compound into your final settlement.
The Settlement Formula
Proof of Audits pays for completed review work under the accepted route terms, so a clean report can still earn its base review fee. Valid findings are additional rewards on top of that settled base.
Bounty Severity Ranges
| Severity | Pool Share | Rep Points |
|---|---|---|
| Critical | 35% | +15 points |
| High | 30% | +7 points |
| Medium | 25% | +3 points |
| Low / QA | 10% | +1 point |
* Pool shares are from the bounty pool portion of your tier share (50% of tier share).
* Missed basic bug = −10 reputation. Promotion: T4→T3 = 50 rep + 10 tasks, T3→T2 = 150 rep + 30 tasks, T2→T1 = 300 rep + 60 tasks.
* Submission stake: 3% of base fee per submission. Appeal stake: 5% of base fee.
Explain My Payout
Full-stack pool: $23,000 → Tier share: $5,750 → Base: $719 / Bounty: $2,875
The Score Engine Pipeline.
Four stages that convert verified public security history into prioritized routing weight — the same trail as onboarding: import work, clean telemetry, profile skills, then allocate tier.
Walkthrough of the full path sits above in Bring your reputation (profile → proof → score → route). Lifetime score drives tier; monthly score growth drives the bonus board.
Master Sync
Primary Hub & Handle VerificationAuditors submit their public handles. Sherlock acts as the primary hub, while mapped profiles from Code4rena, Immunefi, Cantina, Hats, and HackenProof are linked and de-duplicated. Ownership is verified through a unique bio challenge on the primary profile.
Telemetry Cleanup
Public History Collection & De-duplicationOnce handles are verified, Proof of Audits collects public findings from connected platforms and removes duplicate records, mirrored reports, and repeated entries to preserve a clean, high-fidelity audit history.
Duplicates Removed
27.4%
Skill Profiling
Manual Specialist TaggingVerified findings are reviewed and tagged into protocol domains such as AMMs, lending, bridges, and RWAs, along with bug classes like reentrancy, access control, logic, and oracle manipulation. This is manually profiled for routing accuracy—not our scoring system-only tagging.
Tier Allocation
Formula-Driven TieringSeverity mix, validation accuracy, and verified history flow into the scoring engine to compute the final routing score and assign the Sea Warrior Tier from T4 to T1. Tier safeguards help prevent volume gaming.
Transparent. Verifiable. Routing you can trust.
Get routed to work that matches your skills.
Proof of Audits does not route audits only by leaderboard position. Routing considers your tier, verified specialties, protocol architecture, bug-class experience, availability, conflict-of-interest status, validation accuracy, and reliability history.
An auditor experienced in lending and oracle manipulation should receive lending and oracle-related scopes—not unrelated work simply because a slot is open.
Receive work that matches what you have proven you can review.
Routing rules before work opens
- Applying does not instantly route audit work.
- Unverified handles do not count toward score or tier.
- T4, T3, T2, and T1 can receive hunting or validation work based on phase and assignment.
- T0 handles final review, appeals, report approval, and settlement evidence.
Waterfall Review Cycle
Engagements cascade from T4 function-level sweeps down to T1 whole-system signoffs. T0 acts as the ultimate verification layer.
Function Review
Focused review of assigned functions, invariants, and first routed findings.
Contract Review
Contract-level review plus validation of T4 reports before escalation.
Cross-Contract Review
Integration paths, oracle and state dependencies, and validation of T3 reports.
Whole-System Review
System-level risk review across architecture, incentives, governance, and final escalation.
Final Review and Validation
Appeals, missed-bug attribution, private-note validation, final report approval, and settlement evidence.
Your Score. Your Tier. Your Impact.
Your verified score, reliability, validated finding sample, and Proof of Audits-native history determine your computed auditor tier. T3 can be applied automatically when gates pass; T2 and T1 require review. T0 is a separate final-review appointment.
Built on Merit
Verified history only. Evidence, reliability, native findings, and reviewed promotions keep routing tied to proven performance.
Public handles, accepted findings, severity, uniqueness, rank, difficulty, and recency build the starting record.
Work is matched by exact tier, skill tags, availability, protocol architecture, and conflict checks.
T3 validates routed T4 reports, T2 validates routed T3 reports, and T1 validates routed T2 reports.
Monthly bonus boards rank score gained during the cycle, separate from lifetime score.
How Your Score Determines Your Tier
Growth path in one place: T4 builds function-level proof → T3 proves contract consistency and validates T4 → T2 owns cross-contract risk → T1 leads system review → T0 is a separate final-review appointment. Lifetime score moves your tier; monthly score growth is a separate bonus path.
Swordfish Scout
Score: < 250 or gated
Reliability: < 60% / unknown
Build verified review evidence. Default entry and proof-building tier until sample-size, score, reliability, and review gates clear.
- Routed function-level work
- Submit focused findings
- Build 5 validated findings
- Eligible for T3 after gates pass
Hammerhead
Score: 250 - 599
Reliability: >= 60%
Review contracts and validate focused findings. Contract-level review, structural fuzzing, and validation of T4 reports before escalation.
- Submit contract findings
- Validate T4 reports
- Skill tags drive routing
- Auto tier when gates pass
Orca Warden
Score: 600 - 1199
Reliability: >= 75%
Review cross-contract systems and exploit paths. Cross-contract and integration review, with validation responsibility for T3 escalations.
- Validate findings from T3
- Exploit-path review
- Priority complex scopes
- Requires admin approval
Phantom Octopus
Score: >= 1200
Reliability: >= 85%
Lead whole-system review and senior validation. Whole-system review across governance, MEV, economic design, and final escalations.
- System-level validation
- Mentor & verify auditors
- Access to premium scopes
- Requires 2 T1 vouches + admin
Turtle Arbiter
Score: Appointment
Type: Final Review
Independent final-review appointment. Final review, appeals, report approval, missed-bug attribution, and settlement evidence.
- Final report approval
- Appeals and attribution
- Settlement quality gate
- Independent closeout authority
What You Unlock At Higher Tiers
Higher Rewards
Better payout bands, priority fee allocations, and bonus pool distributions. Accepted routes show a base review fee by tier, with higher tiers carrying larger base allocations when scope and eligibility match.
Validation Powers
Validate downstream findings, construct exploit paths, and handle higher-tier escalations.
Priority Access
Get priority access where exact tier, skill tags, availability, and COI checks match.
Reputation Boost
Build verified on-chain credibility, reputation points, and global recognition.
Ecosystem Influence
Senior reviewers shape standards through validations, appeals, and final-report evidence.
Your Score Uses These Evidence Streams
Verified public history establishes the starting score using accepted findings, severity, uniqueness, outcome, rank, difficulty, and recency.
At T0 closeout, confirmed findings apply severity x complexity deltas: Critical +160, High +90, Medium +35, Low +10.
Reliability must be known and meet tier floors: T3 60%, T2 75%, T1 85%. Fewer than 5 validated findings stays T4.
Invalid findings, copycats, wrong validations, denied appeals, and missed own-scope bugs reduce score at closeout.
Keep Improving
Your tier can grow as you grow. Keep participating in audits, sharpening your findings, and validating invariants to unlock the next levels of authority.
Why Auditors Choose Proof of Audits
Predictable duplicate economics, tier growth you can earn, and reputation that travels with your verified work instead of staying trapped inside one contest page.
Duplicate economics
Duplicates in your own scope only raise your score. Cross-scope, you earn a share of the bounty plus the base fee of the missed percentage — only when the assigned auditor missed it.
Tiered growth
T3 unlocks automatically once score, reliability, and sample-size gates pass. T2 and T1 stay review-gated, so authority is earned, never guessed.
Validation work
Move from focused hunting into validation, escalation, and final-review work through the T4 → T1 cascade.
Proof you keep
Verified work feeds your Proof of Audits score, public profile, and protocol trust evidence — not a single platform's leaderboard.
| What matters to you | Proof of Audits | Contests & firms today |
|---|---|---|
Duplicate payout clarity When several researchers find the same bug. | Duplicates in your own scope are score-only. In other scopes you earn a share of the bounty plus the base fee of the missed percentage — and only when the assigned auditor missed it. | ✕ Contest pools shrink with every duplicate: Code4rena splits a finding by ≈0.9^(n−1) ÷ n, Sherlock divides the pool evenly across valid duplicates, and Immunefi pays only the first valid report. Code4renaSherlockImmunefi |
Career progression How work turns into higher authority. | T4 → T1 has explicit score, reliability, finding-sample, native-history, vouch, and review gates. | ✕ Platform rank and reputation are local to each site and rarely convert into portable routing authority elsewhere. Code4renaSherlock |
Validation responsibility Who reviews downstream findings. | T3 validates T4, T2 validates T3, T1 handles system-level validation, and T0 closes report, appeal, and settlement evidence. | ✕ Judging, triage, and mediation depend on each platform's judges, the client, or a private firm's internal process. SherlockCantina |
Payout governance How money moves after finality. | Payouts move after settlement lock, payout request, and KYC gates, with the 5% auditor-side fee stated up front in policy. | ✕ Payout terms, duplicate treatment, timing, and project involvement vary contest by contest, bounty by bounty, and firm by firm. ImmunefiCantina |
Accountability What happens when quality fails. | Invalid findings, copycats, wrong validations, denied appeals, and missed own-scope bugs all reduce score at T0 closeout. | ✕ Downside is usually limited to duplicate dilution, lost judge signal, or a platform-specific lead-role penalty. Code4renaSherlock |
Visibility How your work is seen later. | Approved work feeds auditor profiles, leaderboards, trust passports, and protocol-facing proof surfaces. | ✕ Recognition normally stays inside one leaderboard, contest page, report credit, or private firm brand. Code4renaImmunefi |
Follow-on work Beyond one finding submission. | Invariant, Sentinel, post-audit, validation, and final-review surfaces open more ways to prove skill when enabled. | ✕ Contests and bounties often end at judging, reward distribution, or a static report unless a separate engagement is bought. CantinaImmunefi |
Score-only in scope
Own-scope duplicates raise your score instead of diluting pay.
≈0.9^(n−1) split
Each extra duplicate shrinks every finder's slice of the pool.
Even pool split
Reward divided across valid duplicates of the same severity.
First valid report
Later duplicates of a known bug usually earn nothing.
Here, verified skill becomes routing power.
Duplicate models above reflect each platform's published payout rules; the Proof of Audits column reflects tier and closeout policy. Compared for auditors deciding where their work counts.
Before You Accept a Route
Your protections and every rule that can affect pay, score, and reputation — shown before you commit.
1. Published compensation
Assigned scope, base fees, platform fee, and finding bounty structures are fully detailed before you accept a route.
2. Locked scope
The target code commits and boundaries are locked. Clients cannot sneak in code changes or extra folders during your review.
3. Duplicate rules
Duplicates yield score increases only. For cross-scope reviews, you can earn a percentage of the bounty plus the base fee of the missed percentage only when the assigned auditor missed it.
4. Maximum slashing cap
Your downside is capped. Missed bugs cannot create unlimited negative balances. Any deduction must pass standard attribution rules and the appeal window.
5. Written judging reasons
Every decision regarding classification, validity, duplicates, severity, or penalty includes a published written technical explanation.
6. Appeal window
Auditors have a standard appeal window (typically 48 hours) to dispute any preliminary judgements before closeout.
7. Settlement requirements
Settlement timelines, payment mechanisms, and KYC rules are transparently defined. No surprise deductions or delayed payouts.
Still have a question that's not covered?
Our auditor support team is here to help you.
From Submission to Settlement
Know what happens after you submit.
Submission
You submit your report before the deadline.
Initial Validation
Assigned validator reviews within 48–72 hours.
Duplicate Grouping
Findings are grouped and scored.
Preliminary Judgment
You receive results with reasons.
Appeal Window
48 hours to appeal any decision.
Final Judgment
T0 reviewer confirms final decisions.
Settlement
Payout is processed after all checks.
Ready to get routed to the right audits?
Join Proof of Audits and turn your verified skills into real impact and rewards.





