TL;DR
- Code4rena shut down in May 2026. Immunefi absorbed its researchers.
- Bug bounty rewards now exceed $162M across active programs.
- Most contest auditors earn $1,000 to $20,000 per competition.
- The largest single bounty is $16M on Sherlock.
If you are trying to work out where audit contest earnings actually come from in 2026, the landscape shifted underneath everyone this year. Code4rena, for years the default entry point for competitive auditors, announced it was winding down on 13 May 2026.
Immunefi moved immediately to absorb the fallout, publicly inviting Code4rena's wardens onto its own platform and pledging to help migrate bounty scopes and reward structures.
So the map has changed. Here is what the remaining platforms pay, what a realistic first year looks like and where the money is genuinely concentrated. If you want salaried alternatives alongside this, browse web3 jobs to compare.
What happened to Code4rena?
Code4rena pioneered the time boxed audit competition, researchers called wardens competed head to head on a fixed scope over one to four weeks, splitting a prize pool weighted by severity of findings.
It raised $6 million from Paradigm in 2023 and was acquired by security firm Zellic in 2024. Less than two years later it closed, promising to complete every contest and audit already underway rather than abandoning engagements mid flight.
The practical impact for anyone building an audit career is that the most beginner accessible high volume contest platform disappeared, and the remaining options have different economics.
How much can you actually earn from audit contests?
This is where most guides mislead people, because they quote the top of the distribution and ignore the median.
Most active contest auditors earn $1,000 to $20,000 per contest, depending on how many valid findings they submit and at what severity. Top performers earn $10,000 to $500,000 or more per competition, and a small number have cleared $100,000 from a single contest by finding multiple criticals.
That gap is not a matter of effort. It reflects a genuinely steep skill curve, and most participants spend their first year in the lower band.
| Platform | Model | Typical prize pool | Entry barrier |
|---|---|---|---|
| Immunefi | Standing bug bounties, open submission | Per bug, $1K to $15.5M | None, no staking |
| Sherlock | Contests plus insurance backed bounties | $50K to $300K | $250 USDC stake per report, refunded if valid |
| Cantina | Spearbit's competitions and bounties | $500K to $2M+ | Open, competitive field |
| CodeHawks | Cyfrin run contests, First Flights tier | Smaller pools | Explicitly beginner friendly |
| HackenProof | Managed bounties, CeFi and exchange focus | Varies | Open |

Which bug bounties pay the most?
Standing bug bounties work differently from contests. Instead of competing over a fixed pool, you hunt continuously against production code and earn a direct reward per verified vulnerability.
The ceilings are extraordinary. As of March 2026 the largest active web3 bug bounty is Usual's $16 million program on Sherlock, the highest in tech history. Uniswap v4 runs $15.5 million on Immunefi, and LayerZero sits at $15 million.
The total market now exceeds $162 million in available rewards across hundreds of active programs.
Before that number distorts your expectations: those maximums apply to critical findings in heavily audited blue chip protocols. Uniswap v4's program is backed by nine independent audits and a $2.35 million security competition that drew over 500 researchers. Anything left is extremely well hidden.
Lower severity findings are where most income actually comes from, and they typically pay $1,000 to $50,000.
Contests or bounties, which suits you better?
The two models reward different temperaments, and choosing badly is a common early mistake.
| Audit contests | Bug bounties | |
|---|---|---|
| Scope | Fixed codebase, defined window | Live production code, ongoing |
| Payout basis | Share of pool, weighted by severity | Per verified vulnerability |
| Competition | Direct, duplicates dilute your share | First valid report wins |
| Income shape | Frequent, smaller | Rare, potentially enormous |
| Feedback loop | Fast, public scoring | Slow, often silent |
| Best for | Learning and building reputation | Experienced hunters with patience |
Contests are the better classroom. Every submission is judged transparently against other researchers, so you learn where your analysis was shallow within weeks.
Bounties reward persistence and nerve. You can spend six weeks on a protocol and find nothing, which is a difficult income model without savings behind you.
How do you build up to real contest earnings?
Start where the field is thinner
Beginner tiers exist for a reason. CodeHawks First Flights are explicitly designed for newer auditors and carry far less competition than headline competitions with $2 million pools.
Newer and smaller protocols are also softer targets. A medium severity finding in an obscure protocol pays real money and builds your record just as well as a near miss in a crowded contest.
Study exploits that already happened
Read Rekt.news, Immunefi's published vulnerability reports and public exploit databases. Work through each attack step by step until you could have written it yourself.
Most vulnerabilities are variations on known classes: reentrancy, flash loan manipulation, oracle attacks, broken access control. Pattern recognition is the skill being trained.
Practise where mistakes are free
Deploy deliberately vulnerable contracts on a testnet and exploit them yourself using Foundry. Damn Vulnerable DeFi is the standard starting set.
Writing the exploit teaches more than reading about it, because it forces you to understand exactly why the vulnerability is reachable.

Should you rely on contest income full time?
Most people should not, at least not at first. Contest income is lumpy, reputation gated and unpredictable in a way that salaried auditing is not.
The common pattern among successful independent auditors is a bridge period, salaried or contract work covering fixed costs while contest results accumulate publicly. Once the public record is strong enough to attract private engagements, the maths changes.
The Code4rena shutdown is a reminder of why that matters. A platform your income depended on can close with weeks of notice, and researchers who had diversified across Sherlock, Cantina and standing bounties absorbed that far more comfortably than those who had not.
Frequently asked questions
Is Code4rena still running contests?
No. Code4rena announced its wind down on 13 May 2026, completing existing engagements rather than abandoning them. Immunefi publicly invited its researchers to continue through their platform.
What is the biggest crypto bug bounty available?
Usual's $16 million program on Sherlock, the largest in tech history as of March 2026. Uniswap v4 follows at $15.5 million on Immunefi, then LayerZero at $15 million.
Do you need to stake money to enter audit contests?
It depends on the platform. Sherlock uses a stake to submit model at $250 USDC per report, refunded when the issue is valid. Immunefi has no staking requirement.
How long does it take to earn meaningfully from contests?
Most researchers spend six to twelve months in the lower earnings band before results become consistent. Starting with beginner tiers and smaller protocols shortens that considerably.
Are audit contests better than a salaried audit job?
They serve different purposes. Contests build a public reputation faster than employment can, but salaried work provides predictable income and structured mentorship. Many auditors do both.
Where to go from here
Contests remain the fastest way to build an auditing reputation from nothing, provided you go in with realistic expectations about the first year.
If you would rather pair that with steady income while you build the record, browse web3 jobs for current security openings.
Related reading: Smart Contract Developer Jobs and Web3 Developer Salary Guide 2026.
