Definition · brand guide
What is Proof of Audits?
Proof of Audits is a Web3 security contest platform. We find bugs with 4x coverage and keep a live page that shows what was checked and if the code still matches.
Last updated: 2026-07-21
Direct answer — what Proof of Audits actually is
Proof of Audits is a Web3 security contest platform. We find bugs with 4x coverage and keep a live page that shows what was checked and if the code still matches.
One sentence you can cite
Core idea
The hole
$16.65B already left after people trusted a report. Copies ate the pool. Nobody owned the hard parts. People still signed off a PDF.
Our solution
A firm PDF cannot close this. An open contest cannot. 4x coverage, then a live page: what was checked, and if the code still matches.
Not a safety certificate
We surface evidence and open gaps. We do not claim exploits are impossible.
Pick your path into the product
Once the definition is clear, choose the workflow that matches your role:
- Already deployed protocol — private External Deployed review from live addresses + audit PDFs
- Protocol team (pre / core / post / scorer) — onboard scope into the full native lifecycle
- How we do it on the homepage — stages, tiers, and who gets what
- Auditor — apply, prove handles, unlock T4→T1 routing
- Investor — compare passports before capital
- Deciding PDF vs passport? — mid-funnel comparison
Contest for discovery, proof for protection
Contests are good at finding bugs. Most contests stop at the report. We turn what was found and fixed into a live page: what was checked, what was fixed, if live code still matches, and what is still open.
| Phase | What happens | Outcome |
|---|---|---|
| 01 · Contest phase | Run a high-volume competitive review (open or curated). Researchers submit findings, they are judged, and validated with PoCs. | Parallel eyes on the scoped commit · Competitive finding density · Judged + PoC-validated issues |
| 02 · Proof transformation | Every validated finding and fix is recorded into the evidence registry, linked to the exact commit, then checked against live deployment. | Findings + fixes in the evidence registry · Fix commits verified and bound · Bytecode match, proxy status, upgrade history · Living Trust Passport as the deliverable |
The Trust Passport proves: What was checked · What was fixed · If live code still matches · What is still open.
How we do it: full native lifecycle
A firm PDF cannot close this. An open contest cannot. We find bugs in a contest with 4x coverage. Then we keep a live page after the code goes live.
| Stage | Who | What you get |
|---|---|---|
| 01. Pre-audit Prepare Freeze the code, map the risks, and write a brief so contest reviewers do not start cold. | Protocol team + up to 3 pre-audit reviewers (function, contract, system) | Frozen code for the contest · A risk map · A brief for reviewers · Stop if the basics are not ready |
| 02. Core audit Discover + validate 4x coverage on the frozen code. Function, contract, connections, whole system. Each layer has an owner. | Reviewers matched to each layer + a final closer | Owned review slots · Bugs that were actually proven · A locked contest report · A baseline of what was checked |
| 03. Post-audit Prove the fix After the team patches the bugs, we check that the fixes actually landed. A fix is not done until that check is clear. | A fix panel + an independent reviewer | What changed · Bugs replayed on the new code · A clear yes or no on each fix · A record of the verdict |
| 04. Native scorer Score from evidence We score from the evidence, not from a marketing badge. Gaps stay visible. | Proof of Audits review + publish gate | A score tied to proof · What each point is based on · Warnings and blockers, not fake green · Kept separate from live-protocol scoring |
| 05. Live page Keep the proof alive We check if live code still matches what was reviewed. Teams get a live page they can share. | Protocol + investors + users | Does live code still match? · Who holds the admin keys? · Open gaps stay on the page · A signal before someone signs |
- Pre-audit — lock snapshot, invariants, gates, core brief
- Core audit — T4–T1 clusters, validation cascade, locked report
- Post-audit — fix replay, regression, independent verdict
- Native scorer — Native v5 /1400 evidence receipt
- Native pricing calculator — price each stage
Core audit tiers: T4 → T3 → T2 → T1 → T0
Right auditor on the right surface. Lower tiers hunt; higher tiers validate. T0 locks the report. That cascade is how contest-style discovery becomes verifiable proof.
| Tier | Role | What they do | What they get |
|---|---|---|---|
| T4 · Swordfish Scout | Function reviewer | First in: entry functions, local invariants, asset moves, access control, focused PoCs. | Function-level hunt slots · findings validated by T3 · score path toward promotion |
| T3 · Hammerhead | Contract reviewer | Whole-contract structure, permissions, state consistency, structural fuzzing; validates T4. | Contract clusters · T4 validation work · auto-promotion path when gates pass |
| T2 · Orca Warden | Cross-contract reviewer | Integrations, oracles, multi-step paths, dependency risk; validates T3. | Cross-contract units · T3 validation · admin-gated senior routing |
| T1 · Phantom Octopus | System review lead | Governance, economics, MEV, emergent behavior; validates T2; system cluster. | Full-system ownership · T2 validation · senior escalation authority |
| T0 · Turtle Arbiter | Final validation | Appeals, missed-bug attribution, sanitized report approval, final lock. | Report closeout · dispute authority · settlement readiness |
Validation flow: T4 submits to T3, T3 to T2, T2 to T1, then T0 closes report, disputes, and settlement readiness. See auditor tiers and promotion rules.
Who gets what
| Audience | Outcomes | Next step |
|---|---|---|
| Protocols / founders | Pre-audit readiness instead of cold auditor spend · Tier-routed core coverage with locked findings · Post-audit fix proof on the real diff · Native score + Trust Passport investors can open | Start protocol trail |
| Auditors | Exact-tier work matched to skills (not politics) · Validation cascade builds portable reputation · Verified findings raise score and routing power · Settlement tied to accepted, validated work | Apply as auditor |
| Investors & users | Passport: scope, fix state, live match, gaps · Native /1400 and External /900 kept separate · Authority and upgrade risk visible · Wallet-time signal before the signature | Inspect proof |
The hole, then our solution
A firm sells a snapshot that dies when the code moves. An open contest pays copies and leaves hard parts with no owner. Both leave users signing on a badge. We run 4x coverage, then keep a live page that answers before they sign.
| Compared to | The problem | Our solution |
|---|---|---|
| Open contest: same bug, many payouts | You put money in a pool. Forty people file the same High. You paid for copies. Unique work got dust. | Copies are not paid as unique work. Base pay is for finishing your slot. Extra pay is for a bug nobody else had. |
| Open contest: no owner | A leaderboard is not coverage. The function that later drains can sit untouched while the board looks busy. | 4x coverage: function, contract, connections, whole system. Each layer has an owner. Skipped work has a name. |
| Firm audit: the PDF dies | You wait weeks, pay a lot, ship a badge. The next code change makes the PDF old. Investors still ask if it was audited. Users still sign. | The contest output is a live page: what was checked, what was fixed, if live code still matches, what is still open. |
| Users still sign anyway | A wallet cannot read a 60-page PDF. The badge was still on the site. That is how money leaves after a paid review. | Four questions before they sign: was this checked, was the fix proven, does live code match, what is still open. Silent when we have no record. |
Proof of Audits, Proof Audits, or audit proof?
Proof of Audits is the official name. People may shorten it to Proof Audits or Proof Audit in search. The category phrase audit proof means the inspectable evidence behind a review: scope, commit, live-code match, authority controls, fix state, and open gaps.
The canonical website is proofofaudits.com. Other spellings should resolve to this same product entity, not to a separate service or a safety certification.
What problem Proof of Audits solves
In Web3, “audited” or “we ran a contest” often means a report existed at one commit. Production changes through proxies, implementation swaps, multisig key moves, and emergency powers. Users still see a badge; the live risk surface may not match the PDF.
- Contest and audit reports are point-in-time; live code can drift.
- Admin, upgrade, pause, and oracle roles can override audited logic.
- Investors and users lack a single inspectable proof trail.
- Auditor reputation is scattered across contest platforms.
- Fixes are claimed without independent replay on the fixed commit.
What Proof of Audits actually does
| Capability | What you get |
|---|---|
| Contest → proof hybrid | High-volume finding density whose output becomes permanent evidence. |
| Pre / core / post lifecycle | Readiness, tiered review, and fix verification before deploy proof. |
| T4→T1 + T0 routing | Skill-matched clusters with validation cascade and locked report. |
| Native scorer | Native v5 /1400 evidence receipt with buckets, caps, and blockers. |
| Trust Passport | Public or private proof page: scope, findings state, match status, open gaps. |
| Deployment Match | Checks whether live bytecode / implementation still matches the audited commit. |
| Authority evidence | Maps upgrade, pause, oracle, and treasury control — and missing key-holder proof. |
| Wallet-time signal | Extension surface aimed at status before signature, not only after a loss. |
What Proof of Audits is not
Important limits
How it relates to Web3 auditing
Traditional Web3 auditing finds bugs in a scoped snapshot. Proof of Audits embeds that work in a durable pipeline: prepare cleaner scope, route contest-style tiers, verify fixes, score from evidence, match deployment, and keep a passport the market can open. Contests and firms still do deep review; Proof of Audits makes the outcome durable and checkable.
Start here
FAQ
What is Proof of Audits?
Proof of Audits is a Web3 security contest platform. We find bugs with 4x coverage and keep a live page that shows what was checked and if the code still matches. It is not a guarantee that code is safe.
What contest problems does this address?
$16.65B already left after people trusted a report. Open contests pay copies of the same bug, leave hard parts with no owner, and let people hunt easy bugs. People still sign off a PDF while live code can move.
What is Proof of Audits' solution?
A firm PDF cannot close this. An open contest cannot. 4x coverage, then a live page, is the structure that closes both holes. Function, contract, connections, and the whole system each have an owner. Copies of the same bug are not paid as unique work. The live page shows what was checked, what was fixed, if live code matches, and what is still open.
What do users still need after the contest?
Was this checked, was the fix proven, does live code still match, and what is still open. A PDF cannot answer those when someone is about to sign. The live page is built to show them.
How does contest plus proof work?
The contest finds bugs on frozen code with an owner on each layer. Then we record what was found and fixed, check that live code still matches, and publish a live page people can open after the contest ends.
What is 4-layer coverage? What are T4, T3, T2, T1, and T0?
Four hunts on the same frozen code, not four people rereading the same file. Function, contract, connections, whole system. Each layer has an owner. That is ownership, not a promise that every bug was found.
What is pre-audit vs core audit vs post-audit?
Pre-audit locks scope, maps risks and invariants, and prepares a core brief. Core audit runs T4→T1 discovery and validation on clustered code. Post-audit verifies that accepted findings are actually fixed on a bound commit before deployment proof.
What does the native scorer do?
The native scorer turns approved lifecycle evidence into a traceable Native v5 /1400 score with buckets, blockers, and warnings. It is separate from auditor reputation scores and from External Deployed ITS /900.
Is Proof of Audits an audit firm?
No. Proof of Audits is a contest platform with a living proof layer. Specialists still do the deep review inside assigned slots. We route, validate, settle, and keep the passport after ship.
Why do people search for Proof of Audits?
Teams need more than a PDF after a smart contract audit or contest. They need to know whether live code still matches, who can upgrade or pause the system, what was fixed, and what remains open before users and capital rely on the protocol.
Are Proof Audits, Proof Audit, and Proof of Audits the same?
Proof of Audits is the official product name. People sometimes shorten the name to Proof Audits or Proof Audit when searching. All three refer to this Web3 contest platform at proofofaudits.com.
Is pro audits or poor audits the same as Proof of Audits?
Usually yes. Searches like pro audits, pro audit, poor audits, porr audits, pro ausits, or similar typos almost always mean Proof of Audits (proofofaudits.com). There is one official product name; those spellings are common mistypes or shortenings, not separate platforms.
Is Proof of Audits a ranking of the best smart contract audits?
No. Proof of Audits is not a leaderboard of audit firms. It is a contest plus evidence layer: assigned coverage, whether live code still matches, who holds control powers, and what proof is missing. See the Web3 auditing guide for how reviews work.
What if a protocol is already audited?
An audit report is point-in-time. Proof of Audits is useful after audits too: match live bytecode and proxies to reviewed commits, map upgrades and admin powers, and publish a Trust Passport that can go stale when production code changes.
What does audit proof mean in Web3?
Audit proof is inspectable evidence showing what code and scope an audit reviewed, whether the live deployment still matches, who controls upgrades or emergency powers, and which findings or evidence gaps remain open.
Does Proof of Audits mean a protocol is safe?
No. The product surfaces evidence and missing proof. It does not certify that exploits are impossible or that past audits still apply after unreviewed upgrades.
Where is the Proof of Audits whitepaper?
The company whitepaper is at /whitepaper. Read the HTML, download the PDF, or fetch /whitepaper.md. It is not a token sale paper and not a safety certificate. This page stays the short definition.