Back to Proof of Audits Home

Your Security Work Should Pay You Today—and Build Your Career Tomorrow.

Get a base fee for completing routed review work. Earn additional rewards for accepted findings and validation. Then compete within your tier for monthly leaderboard bonuses funded by Proof of Audits’s eligible platform earnings. Your total score builds your career. Your monthly score growth creates another opportunity to earn.

Paid for the work. Rewarded for the impact. Recognized for consistent growth.

One Platform. Six Ways to Earn.

01 — THE REVIEW

Base Review Fee

Get paid for correctly completing your assigned audit responsibilities.

Complete your assigned review correctly and earn the published base fee—even when no valid vulnerability is found.

Compensated for scope completion
02 — FINDINGS

Finding Rewards

Earn additional severity-based rewards for accepted security findings.

Your base fee pays for the review. Your findings reward the security impact you create.

Rewarded for security impact
03 — SPECIALTIES

Specialist Work

Earn for validation, fix verification, escalation, and post-audit checks.

Provide validation work or closeout review to earn specialized, steady secondary fees on engagements.

Paid for downstream roles
04 — CONSISTENCY

Monthly Leaderboard

Finish among the top three monthly score earners in your tier and share the reward pool.

Competitors in the same tier win bonuses based on score gained during the current monthly cycle.

Rewarded for ecosystem growth
05 — PRE-AUDITING

Pre-Audit & Investor Review

Earn for pre-auditing protocol scope and performing investor risk reviews.

Review protocol architecture, verify scope boundaries, and conduct pre-audit risk assessments for investors before full execution.

Paid for pre-audit preparation
06 — POST-AUDIT

Post-Audit Review

Earn for post-audit verification, invariant monitoring, and patch validation.

Validate protocol fixes, monitor post-deployment runtime invariants, and issue verified post-audit completion reports.

Paid for post-audit verification

Bring the reputation you already earned.

You should not have to restart from zero on every platform. Connect your verified work from Sherlock, Code4rena, Immunefi, Cantina, CodeHawks, Hats, HackenProof, GitHub, and approved private audit evidence.

Proof of Audits verifies ownership, accepted findings, severity history, specialties, reliability, and duplicate records.

Your past work becomes your starting point—not a forgotten profile link.

Verified Identity

Wallet + public handles

Proof of Work

Accepted findings only

Skill Matching

AMM, lending, bridge, oracle, vaults

Routing Eligibility

Tier + skill + COI checked

Build authority from verified work.

Proof of Audits turns accepted findings, correct validations, reliability, and native audit history into routing authority. Lifetime score moves your tier. Monthly score growth creates a separate bonus path.

Real routing signal

Better work opens better matched scopes, not generic status badges.

T4 / Enter

Swordfish Scout

Function-level precision

Swordfish Scout

Focused function review, invariants, unit tests, and proof-of-concept findings.

What counts

Accepted external findings can establish a baseline; native Proof of Audits work builds the live score.

Eligible for T3 once score, reliability, and sample-size gates pass.

T3 / Prove

Hammerhead

Contract-level consistency

Hammerhead

Whole-contract review, fuzz harnesses, access-control sweeps, and validation of routed T4 reports.

What counts

Consistency starts to matter here: valid findings, correct validations, and missed-scope penalties all count.

T2 is review-gated, with stronger reliability and native-history requirements.

T2 / Own

Orca Warden

Cross-contract risk

Orca Warden

Integration paths, oracle and state dependencies, exploit construction, and validation of routed T3 reports.

What counts

Routing depends on exact tier, matching tags, availability, conflict checks, and reliability history.

T1 requires senior review, vouches, and evidence that the auditor can reason across whole systems.

T1 / Lead

Phantom Octopus

System-level authority

Phantom Octopus

Governance, MEV, economic design, systemic escalation, and validation of routed T2 reports.

What counts

T1 is not a slogan. It is a narrow authority band backed by verified score, reliability, and review evidence.

T0 is separate: final report, appeal, missed-bug attribution, and settlement closeout appointment.

Verified evidence

Public handles, accepted findings, severity, uniqueness, rank, difficulty, and recency build the starting record.

Fit-based routing

Work is matched by exact tier, skill tags, availability, protocol architecture, and conflict checks.

Validation responsibility

T3 validates routed T4 reports, T2 validates routed T3 reports, and T1 validates routed T2 reports.

Monthly score delta

Monthly bonus boards rank score gained during the cycle, separate from lifetime score.

Your Progress Can Earn a Monthly Bonus

Base fees and finding rewards pay you for individual engagements. The Monthly Auditor Reward Pool recognizes consistent contribution across the Proof of Audits ecosystem.

Monthly Leaderboard Bonus

Grow your score. Share in Proof of Audits's monthly success.
Open live leaderboard
Published % of eligible monthly platform earnings
Monthly Auditor Reward Pool
Tier Pools
Top 3 in each tier
Swordfish Scout
T4Swordfish Scout

Function-level contributors compete only inside their own tier for monthly bonus awards.

Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
Hammerhead
T3Hammerhead

Contract reviewers and validators compete only inside their own tier for monthly bonus awards.

Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
Orca Warden
T2Orca Warden

Cross-contract reviewers compete only inside their own tier for monthly bonus awards.

Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
Phantom Octopus
T1Phantom Octopus

System-level reviewers compete only inside their own tier for monthly bonus awards.

Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
Rankings are based on monthly score gained, not lifetime score.
Live ranks are shown on the auditor leaderboard when settlement data exists.

* Proof of Audits funds the Monthly Auditor Reward Pool using a published portion of eligible platform earnings. Auditor bonuses are performance rewards and do not represent equity, ownership, dividends, or a claim on Proof of Audits revenue. Eligible platform earnings include settled platform fees but exclude protocol bounty deposits, auditor base-fee funds, refundable balances, taxes, chargebacks, and unsettled or disputed payments. For tier changes, an auditor competes in the tier where they spent the greatest number of eligible days during the monthly cycle.

Your Protections Before Accepting

No hidden payout rules. No silent score changes. No unexplained deductions.

1. Published Compensation

Assigned scope, base fees, platform fee, and finding bounty structures are fully detailed before you accept a route.

2. Locked Scope

The target code commits and boundaries are locked. Clients cannot sneak in code changes or extra folders during your review.

3. Duplicate Rules

Duplicates yield score increases only. For cross-scope reviews, you can earn a percentage of the bounty plus the base fee of the missed percentage only when the assigned auditor missed it. If they did not miss it, you only get the score increase.

4. Maximum Slashing Cap

Your downside is capped. Missed bugs cannot create unlimited negative balances. Any deduction must pass standard attribution rules.

5. Written Judging Reasons

Every decision regarding classification, validity, duplicates, severity, or penalty includes a published written technical explanation.

6. Appeal Window

Auditors have a standard appeal window (typically 48 hours) to dispute any preliminary judgements before closeout.

7. Settlement Requirements

Settlement timelines, payment mechanisms, and KYC rules are transparently defined. No surprise deductions or delayed payouts.

Calculate Your Earnings

See how base fees, unique findings, duplicate protections, and validation rewards compound into your final settlement.

The Settlement Formula

Base review fee(Completed scope review)
+ Accepted unique findings(100% of severity pool weight)
+ Cross-scope missed findings(Bounty + slashed base fee percentage)
+ Valid duplicate findings(Score/Rep increase only, $0 payout)
+ Validation rewards(For co-reviewer validation)
− Published deductions(For missed bugs on co-scope)
− Platform fee(5% standard fee)
= Final settlementNet Wallet Payout

Proof of Audits pays for completed review work under the accepted route terms, so a clean report can still earn its base review fee. Valid findings are additional rewards on top of that settled base.

Bounty Severity Ranges

SeverityPool ShareRep Points
Critical35%+15 points
High30%+7 points
Medium25%+3 points
Low / QA10%+1 point

* Pool shares are from the bounty pool portion of your tier share (50% of tier share).

* Missed basic bug = −10 reputation. Promotion: T4→T3 = 50 rep + 10 tasks, T3→T2 = 150 rep + 30 tasks, T2→T1 = 300 rep + 60 tasks.

* Submission stake: 3% of base fee per submission. Appeal stake: 5% of base fee.

Payout Estimator

Explain My Payout

Full-stack pool: $23,000 → Tier share: $5,750 → Base: $719 / Bounty: $2,875

Unique High Finding
1
Valid Duplicates
1
Cross-Scope MissedBounty + Slashed base fee
0
Cross-Scope Not MissedScore only (No Payout)
1
Base review fee$719
1 accepted High finding+$863
1 duplicate finding+$0 (+15 Reputation Pts)
1 cross-scope not-missed bug+$0 (+15 Reputation Pts)
Validation reward+$250
Platform fee (5%)-$128
Expected Net Settlement* Cross-scope findings earn bounty plus the base fee of the missed percentage only when missed. Duplicates and non-missed cross-scope findings receive score increase only.
$2,423

Auditor Onboarding & Routing Walkthrough.

Learn how public security findings and contest outcomes are ingested into verified Sea Warrior tiers, mapping your skills to active project allocations.

Platform Walkthrough
YT: youtube.com/watch?v=proofofaudits-auditor-walkthrough
_______________________________ | [ ] proof_audits_telemetry | |===============================| | /\ /\ /\ /\ /\ /\ | | / \ / \ / \ / \ / \ / \ | |_______________________________|
Play: Auditor Reputation & Routing Walkthrough
00:00 / 02:45HD [STATUS: READY]

The Score Engine Pipeline.

Four stages that convert verified public security history into prioritized routing weight.

01
STAGE 01

Master Sync

Primary Hub & Handle Verification

Auditors submit their public handles. Sherlock acts as the primary hub, while mapped profiles from Code4rena, Immunefi, Cantina, Hats, and HackenProof are linked and de-duplicated. Ownership is verified through a unique bio challenge on the primary profile.

Sherlock
Code4rena
Immunefi
Cantina
HackenProof
pipeline_telemetry_v1.0
02
STAGE 02

Telemetry Cleanup

Public History Collection & De-duplication

Once handles are verified, Proof of Audits collects public findings from connected platforms and removes duplicate records, mirrored reports, and repeated entries to preserve a clean, high-fidelity audit history.

Duplicates Removed

27.4%

pipeline_telemetry_v1.0
03
STAGE 03

Skill Profiling

Manual Specialist Tagging

Verified findings are reviewed and tagged into protocol domains such as AMMs, lending, bridges, and RWAs, along with bug classes like reentrancy, access control, logic, and oracle manipulation. This is manually profiled for routing accuracy—not AI-only tagging.

DOMAINS
AMMsLendingBridgesRWAs..
BUG CLASSES
ReentrancyAccessLogicOracle..
pipeline_telemetry_v1.0
04
STAGE 04

Tier Allocation

Formula-Driven Tiering

Severity mix, validation accuracy, and verified history flow into the scoring engine to compute the final routing score and assign the Sea Warrior Tier from T4 to T1. Tier safeguards help prevent volume gaming.

T1Phantom Octopus
T2Orca Warden
T3Hammerhead
T4Swordfish Scout
pipeline_telemetry_v1.0
Proof of Audits Pipeline

Transparent. Verifiable. Routing you can trust.

TRACE ID: 0xPROOF_AUDITS_PIPELINE_0081

Get routed to work that matches your skills.

///

Proof of Audits does not route audits only by leaderboard position. Routing considers your tier, verified specialties, protocol architecture, bug-class experience, availability, conflict-of-interest status, validation accuracy, and reliability history.

An auditor experienced in lending and oracle manipulation should receive lending and oracle-related scopes—not unrelated work simply because a slot is open.

Receive work that matches what you have proven you can review.

Waterfall Review Cycle

Engagements cascade from T4 function-level sweeps down to T1 whole-system signoffs. T0 acts as the ultimate verification layer.

T4T3T2T1T0
T4Function Review
T3Contract Review
T2Cross-Contract Review
T1Whole-System Review
T0Final Review & Validation
function(){}
T4Swordfish Scout

Function Review

Focused review of assigned functions, invariants, and first routed findings.

Precise reports with clear proof and scoped impact.
CONTRACTStateFunctionsModifiersEvents
T3Hammerhead

Contract Review

Contract-level review plus validation of T4 reports before escalation.

Strong contract reasoning, severity calls, and validation accuracy.
ACTIVE PATH
CONTRACT ACONTRACT BROUTERBRIDGEORACLE
T2Orca Warden

Cross-Contract Review

Integration paths, oracle and state dependencies, and validation of T3 reports.

TARGET ELIGIBILITYEvidence across multiple contracts and connected exploit paths.
GOVERNANCEINCENTIVESUSERSPROTOCOL COREMODULESORACLESINTEGRATIONSINFRASTRUCTURE
T1Phantom Octopus

Whole-System Review

System-level risk review across architecture, incentives, governance, and final escalation.

Broad judgment, mature severity calibration, and reliable handoff notes.
T0Turtle Arbiter

Final Review and Validation

Appeals, missed-bug attribution, private-note validation, final report approval, and settlement evidence.

Independent closeout judgment. T0 is not a zero-engagement hunting role.

Your Score. Your Tier. Your Impact.

Your verified score, reliability, validated finding sample, and Proof of Audits-native history determine your computed auditor tier. T3 can be applied automatically when gates pass; T2 and T1 require review. T0 is a separate final-review appointment.

Built on Merit

Verified history only. Evidence, reliability, native findings, and reviewed promotions keep routing tied to proven performance.

How Your Score Determines Your Tier

T4Entry
4

Swordfish Scout

Score: < 250 or gated

Reliability: < 60% / unknown

Build verified review evidence. Default entry and proof-building tier until sample-size, score, reliability, and review gates clear.

  • Routed function-level work
  • Submit focused findings
  • Build 5 validated findings
  • Eligible for T3 after gates pass
Foundation Phase
T3Participate
3

Hammerhead

Score: 250 - 599

Reliability: >= 60%

Review contracts and validate focused findings. Contract-level review, structural fuzzing, and validation of T4 reports before escalation.

  • Submit contract findings
  • Validate T4 reports
  • Skill tags drive routing
  • Auto tier when gates pass
Growth Phase
T2Validate
2

Orca Warden

Score: 600 - 1199

Reliability: >= 75%

Review cross-contract systems and exploit paths. Cross-contract and integration review, with validation responsibility for T3 escalations.

  • Validate findings from T3
  • Exploit-path review
  • Priority complex scopes
  • Requires admin approval
Expert Phase
T1Lead
1

Phantom Octopus

Score: >= 1200

Reliability: >= 85%

Lead whole-system review and senior validation. Whole-system review across governance, MEV, economic design, and final escalations.

  • System-level validation
  • Mentor & verify auditors
  • Access to premium scopes
  • Requires 2 T1 vouches + admin
Leadership Phase
T0Govern
0

Turtle Arbiter

Score: Appointment

Type: Final Review

Independent final-review appointment. Final review, appeals, report approval, missed-bug attribution, and settlement evidence.

  • Final report approval
  • Appeals and attribution
  • Settlement quality gate
  • Independent closeout authority
Governance Phase

What You Unlock At Higher Tiers

Higher Rewards

Better payout bands, priority fee allocations, and bonus pool distributions. Accepted routes show a base review fee by tier, with higher tiers carrying larger base allocations when scope and eligibility match.

Validation Powers

Validate downstream findings, construct exploit paths, and handle higher-tier escalations.

Priority Access

Get priority access where exact tier, skill tags, availability, and COI checks match.

Reputation Boost

Build verified on-chain credibility, reputation points, and global recognition.

Ecosystem Influence

Senior reviewers shape standards through validations, appeals, and final-report evidence.

Your Score Uses These Evidence Streams

Onboarding Import
Baseline

Verified public history establishes the starting score using accepted findings, severity, uniqueness, outcome, rank, difficulty, and recency.

Core Findings
Delta

At T0 closeout, confirmed findings apply severity x complexity deltas: Critical +160, High +90, Medium +35, Low +10.

Reliability
Gate

Reliability must be known and meet tier floors: T3 60%, T2 75%, T1 85%. Fewer than 5 validated findings stays T4.

Slashing Guard
Active

Invalid findings, copycats, wrong validations, denied appeals, and missed own-scope bugs reduce score at closeout.

External-only reputation can compute a strong score, but without Proof of Audits-native findings it is capped at T3; T2/T1 remain review-gated.
Next Milestones

Keep Improving

Your tier can grow as you grow. Keep participating in audits, sharpening your findings, and validating invariants to unlock the next levels of authority.

Submit Application
Trace Ref: M5_TIER_DECISION + CORE_CLOSEOUT_V1

From public proof to routed work.

This is what auditors should expect before Proof of Audits sends work into a proof-backed engagement.

Start application
01

Create the auditor profile

Wallet session, contact details, and public audit handles.

Connect walletAdd public handlesSubmit candidate profile
02

Prove handle ownership

A bio challenge ties each public profile back to the applicant.

Generate codePlace it in profile bioVerify ownership
03

Import verified history

Accepted findings, severity patterns, platforms, and contest evidence.

Read public historyMap accepted findingsIgnore unverified claims
04

Score and classify

Tier, skill tags, reliability signals, and validation baseline.

Classify T4 to T1Attach skill tagsLock evidence trail
05

Route by fit

Eligible work is based on exact tier, skill match, availability, and conflict checks.

Check tier slotMatch tagsApply COI rules
06

Build live reputation

Accepted work, validation accuracy, closeout events, and reliability affect future routing.

Submit proofValidate fairlyImprove routing signal

Keep the proof

Your work should keep creating opportunities after the payout is complete.

After closeout, verified work updates the auditor’s record. The Auditor Passport displays your accepted findings, severity distribution, validated specialties, reliability, validation accuracy, duplicate history, fix-verification work, completed audit scopes, tier, score, and eligibility for future routes.

Why Auditors Choose Proof of Audits

More predictable duplicate economics, clearer tier growth, and reputation evidence that follows verified work instead of staying trapped inside one contest page.

Duplicate Economics

Duplicates within your scope yield score increases only. For cross-scope reviews, you can earn a percentage of the bounty plus the base fee of the missed percentage only when the assigned auditor missed it.

Tiered Growth

T3 can apply automatically after score, reliability, and sample-size gates; T2 and T1 remain review-gated so authority is earned, not guessed.

Validation Work

Auditors can move from focused hunting into validation, escalation, and final-review adjacent work through the T4 to T1 cascade.

Proof You Keep

Verified work feeds Proof of Audits score state, public profile surfaces, and protocol trust evidence instead of staying as a platform-only contest result.

What Matters To YouProof of AuditsContest / Firm Baseline

Duplicate payout clarity

When multiple researchers find the same bug.

Duplicates yield score increases only. In other scopes, you earn a percentage of the bounty plus the base fee of the missed percentage only when the assigned auditor missed it.

Traditional platforms use exponential duplicate decay, while bug bounty duplicate treatment varies program-by-program.

Career progression

How work turns into higher authority.

T4 to T1 has explicit score, reliability, finding-sample, native-history, vouch, and review gates.

External rankings and reputation are platform-specific and usually do not become portable routing authority.

Validation responsibility

Who reviews downstream findings.

T3 validates T4, T2 validates T3, T1 handles system-level validation, and T0 closes report/appeal/settlement evidence.

Judging, triage, and mediation depend on the platform, client, contest judge, or private firm process.

Payout governance

How money moves after finality.

Payouts move after settlement lock, payout request, and KYC gates, with the 5% auditor-side fee stated in policy.

Payout terms, duplicate treatment, timing, and project involvement vary by contest, bounty, or firm contract.

Accountability

What happens when quality fails.

Invalid findings, copycats, wrong validations, denied appeals, and missed own-scope bugs reduce score at T0 closeout.

Competitor penalties are narrower: duplicate dilution, judge signal losses, or platform-specific lead rules.

Visibility

How your work is seen later.

Approved work can feed auditor profiles, leaderboards, trust passports, and protocol-facing proof surfaces.

Recognition normally stays inside that platform's leaderboard, contest page, report credit, or private firm brand.

Follow-on work

Beyond one finding submission.

Invariant, Sentinel, post-audit, validation, and final-review surfaces create more ways to prove skill when enabled.

Contest and bounty programs often end at judging, reward distribution, or a static report unless a separate engagement is bought.

Here, verified skill becomes routing power.

Source-backed comparison inputs: alternative duplicate decay models, program-specific duplicate treatments, and Proof of Audits tier/closeout policy.

Others: 0.85 decayOthers: 0.9 decayOthers: program rulesOthers: first disclosureProof of Audits: score-only duplicatesSubmit Application

Before You Accept a Route

Every rule that can affect your work, payment, score, and reputation—answered before you commit.

No hidden payout rules. No unexplained slashing. No silent score changes. Every engagement shows its scope, compensation, duplicate policy, accountability limits, judging process, and appeal window before acceptance.
Policy v1.0Effective 21 Jun 2026

1. Your base fee

Paid for completed review work

Your base fee does not depend on finding a Critical or High-severity issue. It is earned by completing the accepted scope and submitting an original, policy-compliant review on time.

2. Your duplicate protection

Independent work still receives recognition

Proof of Audits identifies duplicates by root cause, affected mechanism, exploit result, and recommended remediation—not merely by similar titles.

3. Your maximum downside

Slashing is limited and reviewable

A missed bug cannot create an unlimited negative balance. Any deduction must pass the published attribution test, remain within the route’s maximum slashing cap, and survive the appeal window.

4. Your right to challenge

Every material decision includes reasons

Invalidity, duplicate classification, severity, slashing, and score changes include written reasons and an evidence trail. Auditors can appeal during the published review period.

Still have a question that's not covered?

Our auditor support team is here to help you.

Contact Auditor Support
Workflow Pipeline

From Submission to Settlement

Know what happens after you submit.

01

Submission

You submit your report before the deadline.

02

Initial Validation

Assigned validator reviews within 48–72 hours.

03

Duplicate Grouping

Findings are grouped and scored.

04

Preliminary Judgment

You receive results with reasons.

05

Appeal Window

48 hours to appeal any decision.

06

Final Judgment

T0 reviewer confirms final decisions.

07

Settlement

Payout is processed after all checks.

Ready to get routed to the right audits?

Join Proof of Audits and turn your verified skills into real impact and rewards.

Apply as Auditor
Proof of Audits

Proof of Audits helps Web3 protocols turn security work into investor-ready trust proof.

Status

Proof surfaces active
Trust Passport, investor view, and extension signals show proof, gaps, and review state.

Proof of Audits

Turn protocol security into proof the market can verify.

© 2026 PROOF_OF_AUDITS