Definition · brand guide

What is Proof of Audits?

Proof of Audits is a Web3 security contest platform. We find bugs with 4x coverage and keep a live page that shows what was checked and if the code still matches.

Last updated: 2026-07-21

Direct answer — what Proof of Audits actually is

Proof of Audits is a Web3 security contest platform. We find bugs with 4x coverage and keep a live page that shows what was checked and if the code still matches.

One sentence you can cite

Proof of Audits is a Web3 security contest platform. We find bugs with 4x coverage and keep a live page that shows what was checked and if the code still matches.

Core idea

Contest for Discovery, Proof for Protection: contests find bugs; Proof of Audits turns validated findings into permanent, verifiable living proof.

The hole

$16.65B already left after people trusted a report. Copies ate the pool. Nobody owned the hard parts. People still signed off a PDF.

Our solution

A firm PDF cannot close this. An open contest cannot. 4x coverage, then a live page: what was checked, and if the code still matches.

Not a safety certificate

We surface evidence and open gaps. We do not claim exploits are impossible.

Pick your path into the product

Once the definition is clear, choose the workflow that matches your role:

Contest for discovery, proof for protection

Contests are good at finding bugs. Most contests stop at the report. We turn what was found and fixed into a live page: what was checked, what was fixed, if live code still matches, and what is still open.

PhaseWhat happensOutcome
01 · Contest phaseRun a high-volume competitive review (open or curated). Researchers submit findings, they are judged, and validated with PoCs.Parallel eyes on the scoped commit · Competitive finding density · Judged + PoC-validated issues
02 · Proof transformationEvery validated finding and fix is recorded into the evidence registry, linked to the exact commit, then checked against live deployment.Findings + fixes in the evidence registry · Fix commits verified and bound · Bytecode match, proxy status, upgrade history · Living Trust Passport as the deliverable

The Trust Passport proves: What was checked · What was fixed · If live code still matches · What is still open.

How we do it: full native lifecycle

A firm PDF cannot close this. An open contest cannot. We find bugs in a contest with 4x coverage. Then we keep a live page after the code goes live.

StageWhoWhat you get
01. Pre-audit
Prepare
Freeze the code, map the risks, and write a brief so contest reviewers do not start cold.
Protocol team + up to 3 pre-audit reviewers (function, contract, system)Frozen code for the contest · A risk map · A brief for reviewers · Stop if the basics are not ready
02. Core audit
Discover + validate
4x coverage on the frozen code. Function, contract, connections, whole system. Each layer has an owner.
Reviewers matched to each layer + a final closerOwned review slots · Bugs that were actually proven · A locked contest report · A baseline of what was checked
03. Post-audit
Prove the fix
After the team patches the bugs, we check that the fixes actually landed. A fix is not done until that check is clear.
A fix panel + an independent reviewerWhat changed · Bugs replayed on the new code · A clear yes or no on each fix · A record of the verdict
04. Native scorer
Score from evidence
We score from the evidence, not from a marketing badge. Gaps stay visible.
Proof of Audits review + publish gateA score tied to proof · What each point is based on · Warnings and blockers, not fake green · Kept separate from live-protocol scoring
05. Live page
Keep the proof alive
We check if live code still matches what was reviewed. Teams get a live page they can share.
Protocol + investors + usersDoes live code still match? · Who holds the admin keys? · Open gaps stay on the page · A signal before someone signs

Core audit tiers: T4 → T3 → T2 → T1 → T0

Right auditor on the right surface. Lower tiers hunt; higher tiers validate. T0 locks the report. That cascade is how contest-style discovery becomes verifiable proof.

TierRoleWhat they doWhat they get
T4 · Swordfish ScoutFunction reviewerFirst in: entry functions, local invariants, asset moves, access control, focused PoCs.Function-level hunt slots · findings validated by T3 · score path toward promotion
T3 · HammerheadContract reviewerWhole-contract structure, permissions, state consistency, structural fuzzing; validates T4.Contract clusters · T4 validation work · auto-promotion path when gates pass
T2 · Orca WardenCross-contract reviewerIntegrations, oracles, multi-step paths, dependency risk; validates T3.Cross-contract units · T3 validation · admin-gated senior routing
T1 · Phantom OctopusSystem review leadGovernance, economics, MEV, emergent behavior; validates T2; system cluster.Full-system ownership · T2 validation · senior escalation authority
T0 · Turtle ArbiterFinal validationAppeals, missed-bug attribution, sanitized report approval, final lock.Report closeout · dispute authority · settlement readiness

Validation flow: T4 submits to T3, T3 to T2, T2 to T1, then T0 closes report, disputes, and settlement readiness. See auditor tiers and promotion rules.

Who gets what

AudienceOutcomesNext step
Protocols / foundersPre-audit readiness instead of cold auditor spend · Tier-routed core coverage with locked findings · Post-audit fix proof on the real diff · Native score + Trust Passport investors can openStart protocol trail
AuditorsExact-tier work matched to skills (not politics) · Validation cascade builds portable reputation · Verified findings raise score and routing power · Settlement tied to accepted, validated workApply as auditor
Investors & usersPassport: scope, fix state, live match, gaps · Native /1400 and External /900 kept separate · Authority and upgrade risk visible · Wallet-time signal before the signatureInspect proof

The hole, then our solution

A firm sells a snapshot that dies when the code moves. An open contest pays copies and leaves hard parts with no owner. Both leave users signing on a badge. We run 4x coverage, then keep a live page that answers before they sign.

Compared toThe problemOur solution
Open contest: same bug, many payoutsYou put money in a pool. Forty people file the same High. You paid for copies. Unique work got dust.Copies are not paid as unique work. Base pay is for finishing your slot. Extra pay is for a bug nobody else had.
Open contest: no ownerA leaderboard is not coverage. The function that later drains can sit untouched while the board looks busy.4x coverage: function, contract, connections, whole system. Each layer has an owner. Skipped work has a name.
Firm audit: the PDF diesYou wait weeks, pay a lot, ship a badge. The next code change makes the PDF old. Investors still ask if it was audited. Users still sign.The contest output is a live page: what was checked, what was fixed, if live code still matches, what is still open.
Users still sign anywayA wallet cannot read a 60-page PDF. The badge was still on the site. That is how money leaves after a paid review.Four questions before they sign: was this checked, was the fix proven, does live code match, what is still open. Silent when we have no record.

Proof of Audits, Proof Audits, or audit proof?

Proof of Audits is the official name. People may shorten it to Proof Audits or Proof Audit in search. The category phrase audit proof means the inspectable evidence behind a review: scope, commit, live-code match, authority controls, fix state, and open gaps.

The canonical website is proofofaudits.com. Other spellings should resolve to this same product entity, not to a separate service or a safety certification.

What problem Proof of Audits solves

In Web3, “audited” or “we ran a contest” often means a report existed at one commit. Production changes through proxies, implementation swaps, multisig key moves, and emergency powers. Users still see a badge; the live risk surface may not match the PDF.

  • Contest and audit reports are point-in-time; live code can drift.
  • Admin, upgrade, pause, and oracle roles can override audited logic.
  • Investors and users lack a single inspectable proof trail.
  • Auditor reputation is scattered across contest platforms.
  • Fixes are claimed without independent replay on the fixed commit.

What Proof of Audits actually does

CapabilityWhat you get
Contest → proof hybridHigh-volume finding density whose output becomes permanent evidence.
Pre / core / post lifecycleReadiness, tiered review, and fix verification before deploy proof.
T4→T1 + T0 routingSkill-matched clusters with validation cascade and locked report.
Native scorerNative v5 /1400 evidence receipt with buckets, caps, and blockers.
Trust PassportPublic or private proof page: scope, findings state, match status, open gaps.
Deployment MatchChecks whether live bytecode / implementation still matches the audited commit.
Authority evidenceMaps upgrade, pause, oracle, and treasury control — and missing key-holder proof.
Wallet-time signalExtension surface aimed at status before signature, not only after a loss.

What Proof of Audits is not

Important limits

Proof of Audits is not insurance, not a guarantee of safety, and not a claim that a protocol cannot be exploited. It does not replace good engineering, continuous monitoring, or legal diligence. It makes the proof trail inspectable.

How it relates to Web3 auditing

Traditional Web3 auditing finds bugs in a scoped snapshot. Proof of Audits embeds that work in a durable pipeline: prepare cleaner scope, route contest-style tiers, verify fixes, score from evidence, match deployment, and keep a passport the market can open. Contests and firms still do deep review; Proof of Audits makes the outcome durable and checkable.

Start here

FAQ

What is Proof of Audits?

Proof of Audits is a Web3 security contest platform. We find bugs with 4x coverage and keep a live page that shows what was checked and if the code still matches. It is not a guarantee that code is safe.

What contest problems does this address?

$16.65B already left after people trusted a report. Open contests pay copies of the same bug, leave hard parts with no owner, and let people hunt easy bugs. People still sign off a PDF while live code can move.

What is Proof of Audits' solution?

A firm PDF cannot close this. An open contest cannot. 4x coverage, then a live page, is the structure that closes both holes. Function, contract, connections, and the whole system each have an owner. Copies of the same bug are not paid as unique work. The live page shows what was checked, what was fixed, if live code matches, and what is still open.

What do users still need after the contest?

Was this checked, was the fix proven, does live code still match, and what is still open. A PDF cannot answer those when someone is about to sign. The live page is built to show them.

How does contest plus proof work?

The contest finds bugs on frozen code with an owner on each layer. Then we record what was found and fixed, check that live code still matches, and publish a live page people can open after the contest ends.

What is 4-layer coverage? What are T4, T3, T2, T1, and T0?

Four hunts on the same frozen code, not four people rereading the same file. Function, contract, connections, whole system. Each layer has an owner. That is ownership, not a promise that every bug was found.

What is pre-audit vs core audit vs post-audit?

Pre-audit locks scope, maps risks and invariants, and prepares a core brief. Core audit runs T4→T1 discovery and validation on clustered code. Post-audit verifies that accepted findings are actually fixed on a bound commit before deployment proof.

What does the native scorer do?

The native scorer turns approved lifecycle evidence into a traceable Native v5 /1400 score with buckets, blockers, and warnings. It is separate from auditor reputation scores and from External Deployed ITS /900.

Is Proof of Audits an audit firm?

No. Proof of Audits is a contest platform with a living proof layer. Specialists still do the deep review inside assigned slots. We route, validate, settle, and keep the passport after ship.

Why do people search for Proof of Audits?

Teams need more than a PDF after a smart contract audit or contest. They need to know whether live code still matches, who can upgrade or pause the system, what was fixed, and what remains open before users and capital rely on the protocol.

Are Proof Audits, Proof Audit, and Proof of Audits the same?

Proof of Audits is the official product name. People sometimes shorten the name to Proof Audits or Proof Audit when searching. All three refer to this Web3 contest platform at proofofaudits.com.

Is pro audits or poor audits the same as Proof of Audits?

Usually yes. Searches like pro audits, pro audit, poor audits, porr audits, pro ausits, or similar typos almost always mean Proof of Audits (proofofaudits.com). There is one official product name; those spellings are common mistypes or shortenings, not separate platforms.

Is Proof of Audits a ranking of the best smart contract audits?

No. Proof of Audits is not a leaderboard of audit firms. It is a contest plus evidence layer: assigned coverage, whether live code still matches, who holds control powers, and what proof is missing. See the Web3 auditing guide for how reviews work.

What if a protocol is already audited?

An audit report is point-in-time. Proof of Audits is useful after audits too: match live bytecode and proxies to reviewed commits, map upgrades and admin powers, and publish a Trust Passport that can go stale when production code changes.

What does audit proof mean in Web3?

Audit proof is inspectable evidence showing what code and scope an audit reviewed, whether the live deployment still matches, who controls upgrades or emergency powers, and which findings or evidence gaps remain open.

Does Proof of Audits mean a protocol is safe?

No. The product surfaces evidence and missing proof. It does not certify that exploits are impossible or that past audits still apply after unreviewed upgrades.

Where is the Proof of Audits whitepaper?

The company whitepaper is at /whitepaper. Read the HTML, download the PDF, or fetch /whitepaper.md. It is not a token sale paper and not a safety certificate. This page stays the short definition.