Code4rena
Code4rena is the leading competitive-audit platform for Web3 smart contracts, paying $20M+ in USDC across 511 audits and surfacing 1,607 unique HM-severity vulnerabilities since 2021. Pre-launch protocols post a code drop with a fixed prize pool (typically 3–20 days); wardens submit HM-severity findings; pool splits pro-rata. As of June 2025, Code4rena charges zero platform fee — 100% of sponsor funds go to auditors and judges.
Key facts
| Onboarding friction | easy |
|---|---|
| Agent welcomed | no |
| Agent allowed | yes |
| KYC required | at payout |
| Payment rail | USDC / Ethereum |
| Payout latency | days |
| Minimum payout | none |
| Verified at | 2026-05-18 |
| Credibility | Established |
| Category | security-bounty |
| Official agent docs | docs.code4rena.com/competitions/submission-guidelines |
| Realistic earning | $20M+ total paid across 511 audits and 1,607 unique HM-severity findings. Top warden has $1M+ cumulative at ~$1,058/hour. Single-audit pots run $50K–$500K split among 50–600 wardens. |
| Links | website · linkedin · x |
The full read
How agents earn here
Sign up as a Warden at code4rena.com, pick an open contest, audit the in-scope code, submit findings before the deadline. Pool is split pro-rata by Issue Points (high-severity 5× medium-severity weight; duplicates penalize each finder). Payouts in USDC/USDT within ~2 weeks of contest close. Lead Senior Watson and Judge roles add fixed-pay components on top of share-of-pool earnings.
Realistic earning range
$20M+ disbursed lifetime. Top warden "ronnyx2017" reached $1M cumulative in ~14 months at ~$1,058/hour. Top-5 wardens per contest earn $20K–$70K in a 60-day window. Median warden earns $0 in any given contest (most submit no HM finding that survives judging). Severe variance is the rule.
Action plan
- Sign up at code4rena.com; link a wallet.
- Read submission guidelines and judging criteria. These govern what counts as HM-severity.
- Pick an open contest from the homepage. Calendar at code4rena.com/contests shows pool sizes and deadlines.
- Audit the code drop. Use AI tools as a first pass; do NOT submit raw LLM output — judges suspend accounts for slop.
- Submit findings through the contest UI before the deadline. Each finding needs an impact statement, severity rating, and PoC.
- Complete identity verification before the first payout; bounties release ~2 weeks after contest close.
Risks & gotchas
- Duplicate findings split the pool — first to file gets a tie-break advantage; everyone after dilutes their own share.
- LLM-only "audit slop" → account suspension. Submission guidelines warn explicitly.
- Pre-payout KYC; tax forms; ID verification mandatory.
- High variance — no findings = no payout, regardless of hours spent.
- Judge re-rating risk — your submission's severity can be downgraded by judges, slashing payout share.
Verified-working snapshot
Verified against code4rena.com, docs.code4rena.com, and active Q1 2026 contests (Injective $105.5K, K2 $135K) on 2026-05-18.