Your Security Work Should Pay You Today—and Build Your Career Tomorrow.
Get a base fee for completing routed review work. Earn additional rewards for accepted findings and validation. Then compete within your tier for monthly leaderboard bonuses funded by Proof of Audits’s eligible platform earnings. Your total score builds your career. Your monthly score growth creates another opportunity to earn.
Paid for the work. Rewarded for the impact. Recognized for consistent growth.
You should not have to restart from zero on every platform. Connect your verified work from Sherlock, Code4rena, Immunefi, Cantina, CodeHawks, Hats, HackenProof, GitHub, and approved private audit evidence.
Proof of Audits verifies ownership, accepted findings, severity history, specialties, reliability, and duplicate records.
Your past work becomes your starting point—not a forgotten profile link.
Proof of Audits turns accepted findings, correct validations, reliability, and native audit history into routing authority. Lifetime score moves your tier. Monthly score growth creates a separate bonus path.
Better work opens better matched scopes, not generic status badges.
T4 / Enter
Swordfish Scout
Function-level precision
Focused function review, invariants, unit tests, and proof-of-concept findings.
What counts
Accepted external findings can establish a baseline; native Proof of Audits work builds the live score.
Eligible for T3 once score, reliability, and sample-size gates pass.
T3 / Prove
Hammerhead
Contract-level consistency
Whole-contract review, fuzz harnesses, access-control sweeps, and validation of routed T4 reports.
What counts
Consistency starts to matter here: valid findings, correct validations, and missed-scope penalties all count.
T2 is review-gated, with stronger reliability and native-history requirements.
T2 / Own
Orca Warden
Cross-contract risk
Integration paths, oracle and state dependencies, exploit construction, and validation of routed T3 reports.
What counts
Routing depends on exact tier, matching tags, availability, conflict checks, and reliability history.
T1 requires senior review, vouches, and evidence that the auditor can reason across whole systems.
T1 / Lead
Phantom Octopus
System-level authority
Governance, MEV, economic design, systemic escalation, and validation of routed T2 reports.
What counts
T1 is not a slogan. It is a narrow authority band backed by verified score, reliability, and review evidence.
T0 is separate: final report, appeal, missed-bug attribution, and settlement closeout appointment.
Verified evidence
Public handles, accepted findings, severity, uniqueness, rank, difficulty, and recency build the starting record.
Fit-based routing
Work is matched by exact tier, skill tags, availability, protocol architecture, and conflict checks.
Validation responsibility
T3 validates routed T4 reports, T2 validates routed T3 reports, and T1 validates routed T2 reports.
Monthly score delta
Monthly bonus boards rank score gained during the cycle, separate from lifetime score.
How are top contributors rewarded?
Your Progress Can Earn a Monthly Bonus
Base fees and finding rewards pay you for individual engagements. The Monthly Auditor Reward Pool recognizes consistent contribution across the Proof of Audits ecosystem.
Monthly Leaderboard Bonus
Grow your score. Share in Proof of Audits's monthly success.
Function-level contributors compete only inside their own tier for monthly bonus awards.
Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
T3Hammerhead
Contract reviewers and validators compete only inside their own tier for monthly bonus awards.
Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
T2Orca Warden
Cross-contract reviewers compete only inside their own tier for monthly bonus awards.
Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
T1Phantom Octopus
System-level reviewers compete only inside their own tier for monthly bonus awards.
Rank source: locked settlements and score events in the selected UTC month.
Award slots: top 3 positive net-point auditors when a tier pool is locked.
Payout split: rank 1 gets 50%, rank 2 gets 30%, rank 3 gets 20% of that tier pool.
Rankings are based on monthly score gained, not lifetime score.
Live ranks are shown on the auditor leaderboard when settlement data exists.
* Proof of Audits funds the Monthly Auditor Reward Pool using a published portion of eligible platform earnings. Auditor bonuses are performance rewards and do not represent equity, ownership, dividends, or a claim on Proof of Audits revenue. Eligible platform earnings include settled platform fees but exclude protocol bounty deposits, auditor base-fee funds, refundable balances, taxes, chargebacks, and unsettled or disputed payments. For tier changes, an auditor competes in the tier where they spent the greatest number of eligible days during the monthly cycle.
How are auditors protected?
Your Protections Before Accepting
No hidden payout rules. No silent score changes. No unexplained deductions.
1. Published Compensation
Assigned scope, base fees, platform fee, and finding bounty structures are fully detailed before you accept a route.
2. Locked Scope
The target code commits and boundaries are locked. Clients cannot sneak in code changes or extra folders during your review.
3. Duplicate Rules
Duplicates yield score increases only. For cross-scope reviews, you can earn a percentage of the bounty plus the base fee of the missed percentage only when the assigned auditor missed it. If they did not miss it, you only get the score increase.
4. Maximum Slashing Cap
Your downside is capped. Missed bugs cannot create unlimited negative balances. Any deduction must pass standard attribution rules.
5. Written Judging Reasons
Every decision regarding classification, validity, duplicates, severity, or penalty includes a published written technical explanation.
6. Appeal Window
Auditors have a standard appeal window (typically 48 hours) to dispute any preliminary judgements before closeout.
7. Settlement Requirements
Settlement timelines, payment mechanisms, and KYC rules are transparently defined. No surprise deductions or delayed payouts.
How are earnings calculated?
Calculate Your Earnings
See how base fees, unique findings, duplicate protections, and validation rewards compound into your final settlement.
The Settlement Formula
Base review fee(Completed scope review)
+ Accepted unique findings(100% of severity pool weight)
+ Cross-scope missed findings(Bounty + slashed base fee percentage)
− Published deductions(For missed bugs on co-scope)
− Platform fee(5% standard fee)
= Final settlementNet Wallet Payout
Proof of Audits pays for completed review work under the accepted route terms, so a clean report can still earn its base review fee. Valid findings are additional rewards on top of that settled base.
Bounty Severity Ranges
Severity
Pool Share
Rep Points
Critical
35%
+15 points
High
30%
+7 points
Medium
25%
+3 points
Low / QA
10%
+1 point
* Pool shares are from the bounty pool portion of your tier share (50% of tier share).
Expected Net Settlement* Cross-scope findings earn bounty plus the base fee of the missed percentage only when missed. Duplicates and non-missed cross-scope findings receive score increase only.
$2,423
How does the auditor onboarding flow work?
Auditor Onboarding & Routing Walkthrough.
Learn how public security findings and contest outcomes are ingested into verified Sea Warrior tiers, mapping your skills to active project allocations.
Four stages that convert verified public security history into prioritized routing weight.
01
STAGE 01
Master Sync
Primary Hub & Handle Verification
Auditors submit their public handles. Sherlock acts as the primary hub, while mapped profiles from Code4rena, Immunefi, Cantina, Hats, and HackenProof are linked and de-duplicated. Ownership is verified through a unique bio challenge on the primary profile.
Sherlock
Code4rena
Immunefi
Cantina
HackenProof
pipeline_telemetry_v1.0
02
STAGE 02
Telemetry Cleanup
Public History Collection & De-duplication
Once handles are verified, Proof of Audits collects public findings from connected platforms and removes duplicate records, mirrored reports, and repeated entries to preserve a clean, high-fidelity audit history.
→
Duplicates Removed
27.4%
pipeline_telemetry_v1.0
03
STAGE 03
Skill Profiling
Manual Specialist Tagging
Verified findings are reviewed and tagged into protocol domains such as AMMs, lending, bridges, and RWAs, along with bug classes like reentrancy, access control, logic, and oracle manipulation. This is manually profiled for routing accuracy—not AI-only tagging.
DOMAINS
AMMsLendingBridgesRWAs..
BUG CLASSES
ReentrancyAccessLogicOracle..
pipeline_telemetry_v1.0
04
STAGE 04
Tier Allocation
Formula-Driven Tiering
Severity mix, validation accuracy, and verified history flow into the scoring engine to compute the final routing score and assign the Sea Warrior Tier from T4 to T1. Tier safeguards help prevent volume gaming.
T1Phantom Octopus
T2Orca Warden
T3Hammerhead
T4Swordfish Scout
pipeline_telemetry_v1.0
Proof of Audits Pipeline
Transparent. Verifiable. Routing you can trust.
TRACE ID: 0xPROOF_AUDITS_PIPELINE_0081
How does smart routing match skills?
Get routed to work that matches your skills.
///
Proof of Audits does not route audits only by leaderboard position. Routing considers your tier, verified specialties, protocol architecture, bug-class experience, availability, conflict-of-interest status, validation accuracy, and reliability history.
An auditor experienced in lending and oracle manipulation should receive lending and oracle-related scopes—not unrelated work simply because a slot is open.
Receive work that matches what you have proven you can review.
Waterfall Review Cycle
Engagements cascade from T4 function-level sweeps down to T1 whole-system signoffs. T0 acts as the ultimate verification layer.
T4Function Review
T3Contract Review
T2Cross-Contract Review
T1Whole-System Review
T0Final Review & Validation
T4Swordfish Scout
Function Review
Focused review of assigned functions, invariants, and first routed findings.
TARGET ELIGIBILITYPrecise reports with clear proof and scoped impact.
▲
T3Hammerhead
Contract Review
Contract-level review plus validation of T4 reports before escalation.
TARGET ELIGIBILITYStrong contract reasoning, severity calls, and validation accuracy.
▲
ACTIVE PATH
T2Orca Warden
Cross-Contract Review
Integration paths, oracle and state dependencies, and validation of T3 reports.
TARGET ELIGIBILITYEvidence across multiple contracts and connected exploit paths.
▲
T1Phantom Octopus
Whole-System Review
System-level risk review across architecture, incentives, governance, and final escalation.
TARGET ELIGIBILITYBroad judgment, mature severity calibration, and reliable handoff notes.
▲
T0Turtle Arbiter
Final Review and Validation
Appeals, missed-bug attribution, private-note validation, final report approval, and settlement evidence.
TARGET ELIGIBILITYIndependent closeout judgment. T0 is not a zero-engagement hunting role.
How do auditor score levels work?
Your Score. Your Tier. Your Impact.
Your verified score, reliability, validated finding sample, and Proof of Audits-native history determine your computed auditor tier. T3 can be applied automatically when gates pass; T2 and T1 require review. T0 is a separate final-review appointment.
Built on Merit
Verified history only. Evidence, reliability, native findings, and reviewed promotions keep routing tied to proven performance.
How Your Score Determines Your Tier
T4Entry
4
Swordfish Scout
Score: < 250 or gated
Reliability: < 60% / unknown
Build verified review evidence. Default entry and proof-building tier until sample-size, score, reliability, and review gates clear.
Routed function-level work
Submit focused findings
Build 5 validated findings
Eligible for T3 after gates pass
Foundation Phase
T3Participate
3
Hammerhead
Score: 250 - 599
Reliability: >= 60%
Review contracts and validate focused findings. Contract-level review, structural fuzzing, and validation of T4 reports before escalation.
Submit contract findings
Validate T4 reports
Skill tags drive routing
Auto tier when gates pass
Growth Phase
T2Validate
2
Orca Warden
Score: 600 - 1199
Reliability: >= 75%
Review cross-contract systems and exploit paths. Cross-contract and integration review, with validation responsibility for T3 escalations.
Validate findings from T3
Exploit-path review
Priority complex scopes
Requires admin approval
Expert Phase
T1Lead
1
Phantom Octopus
Score: >= 1200
Reliability: >= 85%
Lead whole-system review and senior validation. Whole-system review across governance, MEV, economic design, and final escalations.
System-level validation
Mentor & verify auditors
Access to premium scopes
Requires 2 T1 vouches + admin
Leadership Phase
T0Govern
0
Turtle Arbiter
Score: Appointment
Type: Final Review
Independent final-review appointment. Final review, appeals, report approval, missed-bug attribution, and settlement evidence.
Final report approval
Appeals and attribution
Settlement quality gate
Independent closeout authority
Governance Phase
What You Unlock At Higher Tiers
Higher Rewards
Better payout bands, priority fee allocations, and bonus pool distributions. Accepted routes show a base review fee by tier, with higher tiers carrying larger base allocations when scope and eligibility match.
Validation Powers
Validate downstream findings, construct exploit paths, and handle higher-tier escalations.
Priority Access
Get priority access where exact tier, skill tags, availability, and COI checks match.
Reputation Boost
Build verified on-chain credibility, reputation points, and global recognition.
Ecosystem Influence
Senior reviewers shape standards through validations, appeals, and final-report evidence.
Your Score Uses These Evidence Streams
Onboarding Import
Baseline
Verified public history establishes the starting score using accepted findings, severity, uniqueness, outcome, rank, difficulty, and recency.
Core Findings
Delta
At T0 closeout, confirmed findings apply severity x complexity deltas: Critical +160, High +90, Medium +35, Low +10.
Reliability
Gate
Reliability must be known and meet tier floors: T3 60%, T2 75%, T1 85%. Fewer than 5 validated findings stays T4.
Slashing Guard
Active
Invalid findings, copycats, wrong validations, denied appeals, and missed own-scope bugs reduce score at closeout.
External-only reputation can compute a strong score, but without Proof of Audits-native findings it is capped at T3; T2/T1 remain review-gated.
Next Milestones
Keep Improving
Your tier can grow as you grow. Keep participating in audits, sharpening your findings, and validating invariants to unlock the next levels of authority.
More predictable duplicate economics, clearer tier growth, and reputation evidence that follows verified work instead of staying trapped inside one contest page.
Duplicate Economics
Duplicates within your scope yield score increases only. For cross-scope reviews, you can earn a percentage of the bounty plus the base fee of the missed percentage only when the assigned auditor missed it.
Tiered Growth
T3 can apply automatically after score, reliability, and sample-size gates; T2 and T1 remain review-gated so authority is earned, not guessed.
Validation Work
Auditors can move from focused hunting into validation, escalation, and final-review adjacent work through the T4 to T1 cascade.
Proof You Keep
Verified work feeds Proof of Audits score state, public profile surfaces, and protocol trust evidence instead of staying as a platform-only contest result.
What Matters To You
Proof of Audits
Contest / Firm Baseline
Duplicate payout clarity
When multiple researchers find the same bug.
Duplicates yield score increases only. In other scopes, you earn a percentage of the bounty plus the base fee of the missed percentage only when the assigned auditor missed it.
✕
Traditional platforms use exponential duplicate decay, while bug bounty duplicate treatment varies program-by-program.
Career progression
How work turns into higher authority.
T4 to T1 has explicit score, reliability, finding-sample, native-history, vouch, and review gates.
✕
External rankings and reputation are platform-specific and usually do not become portable routing authority.
Validation responsibility
Who reviews downstream findings.
T3 validates T4, T2 validates T3, T1 handles system-level validation, and T0 closes report/appeal/settlement evidence.
✕
Judging, triage, and mediation depend on the platform, client, contest judge, or private firm process.
Payout governance
How money moves after finality.
Payouts move after settlement lock, payout request, and KYC gates, with the 5% auditor-side fee stated in policy.
✕
Payout terms, duplicate treatment, timing, and project involvement vary by contest, bounty, or firm contract.
Accountability
What happens when quality fails.
Invalid findings, copycats, wrong validations, denied appeals, and missed own-scope bugs reduce score at T0 closeout.
✕
Competitor penalties are narrower: duplicate dilution, judge signal losses, or platform-specific lead rules.
Visibility
How your work is seen later.
Approved work can feed auditor profiles, leaderboards, trust passports, and protocol-facing proof surfaces.
✕
Recognition normally stays inside that platform's leaderboard, contest page, report credit, or private firm brand.
Follow-on work
Beyond one finding submission.
Invariant, Sentinel, post-audit, validation, and final-review surfaces create more ways to prove skill when enabled.
✕
Contest and bounty programs often end at judging, reward distribution, or a static report unless a separate engagement is bought.
Here, verified skill becomes routing power.
Source-backed comparison inputs: alternative duplicate decay models, program-specific duplicate treatments, and Proof of Audits tier/closeout policy.
Others: 0.85 decayOthers: 0.9 decayOthers: program rulesOthers: first disclosureProof of Audits: score-only duplicatesSubmit Application
What rules govern active audit routes?
Before You Accept a Route
Every rule that can affect your work, payment, score, and reputation—answered before you commit.
No hidden payout rules. No unexplained slashing. No silent score changes. Every engagement shows its scope, compensation, duplicate policy, accountability limits, judging process, and appeal window before acceptance.
Policy v1.0•Effective 21 Jun 2026•
1. Your base fee
Paid for completed review work
Your base fee does not depend on finding a Critical or High-severity issue. It is earned by completing the accepted scope and submitting an original, policy-compliant review on time.
2. Your duplicate protection
Independent work still receives recognition
Proof of Audits identifies duplicates by root cause, affected mechanism, exploit result, and recommended remediation—not merely by similar titles.
3. Your maximum downside
Slashing is limited and reviewable
A missed bug cannot create an unlimited negative balance. Any deduction must pass the published attribution test, remain within the route’s maximum slashing cap, and survive the appeal window.
4. Your right to challenge
Every material decision includes reasons
Invalidity, duplicate classification, severity, slashing, and score changes include written reasons and an evidence trail. Auditors can appeal during the published review period.