Back to Blog
EngineeringGuide · 5 min read

Audit Contest Earnings in 2026: Where Auditors Make Money After Code4rena

Code4rena wound down in May 2026 and the contest landscape shifted. Here is what Sherlock, Cantina, Immunefi and CodeHawks actually pay auditors.

Security researcher working across two code-filled monitors in a dark room

TL;DR

  • Code4rena shut down in May 2026. Immunefi absorbed its researchers.
  • Bug bounty rewards now exceed $162M across active programs.
  • Most contest auditors earn $1,000 to $20,000 per competition.
  • The largest single bounty is $16M on Sherlock.

If you are trying to work out where audit contest earnings actually come from in 2026, the landscape shifted underneath everyone this year. Code4rena, for years the default entry point for competitive auditors, announced it was winding down on 13 May 2026.

Immunefi moved immediately to absorb the fallout, publicly inviting Code4rena's wardens onto its own platform and pledging to help migrate bounty scopes and reward structures.

So the map has changed. Here is what the remaining platforms pay, what a realistic first year looks like and where the money is genuinely concentrated. If you want salaried alternatives alongside this, browse web3 jobs to compare.

What happened to Code4rena?

Code4rena pioneered the time boxed audit competition, researchers called wardens competed head to head on a fixed scope over one to four weeks, splitting a prize pool weighted by severity of findings.

It raised $6 million from Paradigm in 2023 and was acquired by security firm Zellic in 2024. Less than two years later it closed, promising to complete every contest and audit already underway rather than abandoning engagements mid flight.

The practical impact for anyone building an audit career is that the most beginner accessible high volume contest platform disappeared, and the remaining options have different economics.

How much can you actually earn from audit contests?

This is where most guides mislead people, because they quote the top of the distribution and ignore the median.

Most active contest auditors earn $1,000 to $20,000 per contest, depending on how many valid findings they submit and at what severity. Top performers earn $10,000 to $500,000 or more per competition, and a small number have cleared $100,000 from a single contest by finding multiple criticals.

That gap is not a matter of effort. It reflects a genuinely steep skill curve, and most participants spend their first year in the lower band.

PlatformModelTypical prize poolEntry barrier
ImmunefiStanding bug bounties, open submissionPer bug, $1K to $15.5MNone, no staking
SherlockContests plus insurance backed bounties$50K to $300K$250 USDC stake per report, refunded if valid
CantinaSpearbit's competitions and bounties$500K to $2M+Open, competitive field
CodeHawksCyfrin run contests, First Flights tierSmaller poolsExplicitly beginner friendly
HackenProofManaged bounties, CeFi and exchange focusVariesOpen
Comparison of smart contract audit contest and bug bounty platforms in 2026
Code4rena raised $6 million from Paradigm in 2023 and was acquired by Zellic the following year.

Which bug bounties pay the most?

Standing bug bounties work differently from contests. Instead of competing over a fixed pool, you hunt continuously against production code and earn a direct reward per verified vulnerability.

The ceilings are extraordinary. As of March 2026 the largest active web3 bug bounty is Usual's $16 million program on Sherlock, the highest in tech history. Uniswap v4 runs $15.5 million on Immunefi, and LayerZero sits at $15 million.

The total market now exceeds $162 million in available rewards across hundreds of active programs.

Before that number distorts your expectations: those maximums apply to critical findings in heavily audited blue chip protocols. Uniswap v4's program is backed by nine independent audits and a $2.35 million security competition that drew over 500 researchers. Anything left is extremely well hidden.

Lower severity findings are where most income actually comes from, and they typically pay $1,000 to $50,000.

Contests or bounties, which suits you better?

The two models reward different temperaments, and choosing badly is a common early mistake.

Audit contestsBug bounties
ScopeFixed codebase, defined windowLive production code, ongoing
Payout basisShare of pool, weighted by severityPer verified vulnerability
CompetitionDirect, duplicates dilute your shareFirst valid report wins
Income shapeFrequent, smallerRare, potentially enormous
Feedback loopFast, public scoringSlow, often silent
Best forLearning and building reputationExperienced hunters with patience

Contests are the better classroom. Every submission is judged transparently against other researchers, so you learn where your analysis was shallow within weeks.

Bounties reward persistence and nerve. You can spend six weeks on a protocol and find nothing, which is a difficult income model without savings behind you.

How do you build up to real contest earnings?

Start where the field is thinner

Beginner tiers exist for a reason. CodeHawks First Flights are explicitly designed for newer auditors and carry far less competition than headline competitions with $2 million pools.

Newer and smaller protocols are also softer targets. A medium severity finding in an obscure protocol pays real money and builds your record just as well as a near miss in a crowded contest.

Study exploits that already happened

Read Rekt.news, Immunefi's published vulnerability reports and public exploit databases. Work through each attack step by step until you could have written it yourself.

Most vulnerabilities are variations on known classes: reentrancy, flash loan manipulation, oracle attacks, broken access control. Pattern recognition is the skill being trained.

Practise where mistakes are free

Deploy deliberately vulnerable contracts on a testnet and exploit them yourself using Foundry. Damn Vulnerable DeFi is the standard starting set.

Writing the exploit teaches more than reading about it, because it forces you to understand exactly why the vulnerability is reachable.

Distribution of smart contract audit contest earnings per competition
Independent researchers outside contests charge $500 to $1,500 an hour, with engagements from $25,000 to $300,000.

Should you rely on contest income full time?

Most people should not, at least not at first. Contest income is lumpy, reputation gated and unpredictable in a way that salaried auditing is not.

The common pattern among successful independent auditors is a bridge period, salaried or contract work covering fixed costs while contest results accumulate publicly. Once the public record is strong enough to attract private engagements, the maths changes.

The Code4rena shutdown is a reminder of why that matters. A platform your income depended on can close with weeks of notice, and researchers who had diversified across Sherlock, Cantina and standing bounties absorbed that far more comfortably than those who had not.

Frequently asked questions

Is Code4rena still running contests?

No. Code4rena announced its wind down on 13 May 2026, completing existing engagements rather than abandoning them. Immunefi publicly invited its researchers to continue through their platform.

What is the biggest crypto bug bounty available?

Usual's $16 million program on Sherlock, the largest in tech history as of March 2026. Uniswap v4 follows at $15.5 million on Immunefi, then LayerZero at $15 million.

Do you need to stake money to enter audit contests?

It depends on the platform. Sherlock uses a stake to submit model at $250 USDC per report, refunded when the issue is valid. Immunefi has no staking requirement.

How long does it take to earn meaningfully from contests?

Most researchers spend six to twelve months in the lower earnings band before results become consistent. Starting with beginner tiers and smaller protocols shortens that considerably.

Are audit contests better than a salaried audit job?

They serve different purposes. Contests build a public reputation faster than employment can, but salaried work provides predictable income and structured mentorship. Many auditors do both.

Where to go from here

Contests remain the fastest way to build an auditing reputation from nothing, provided you go in with realistic expectations about the first year.

If you would rather pair that with steady income while you build the record, browse web3 jobs for current security openings.

Related reading: Smart Contract Developer Jobs and Web3 Developer Salary Guide 2026.

Share this post