Browse docs

Getting started

What CertiK Hunt is, the two engagement formats, and what your access level opens.

CertiK Hunt is a private, invite-only Web3 security network. Vetted researchers surface real vulnerabilities in participating projects, and CertiK independently reproduces and rates every finding before it reaches the project — so severity isn't quietly negotiated down to dodge a payout.

This documentation explains how the platform works, how to submit findings that get accepted and paid, and the rules every participant agrees to.

#Who Hunt is for

Hunt is built for security researchers who want high-signal work and fair, independent review. If you find and responsibly disclose vulnerabilities in smart contracts, blockchain/DLT systems, or web applications, Hunt is for you.

#Two engagement formats

Hunt runs two formats on one researcher network. They are genuinely different products, not two labels on the same workflow:

  • Security challenges — focused, time-boxed missions with a published window, a set of instructions, and an enrollment step. Finish one and you have a verified track record on Hunt rather than a claim. Scoring and results stay sealed until CertiK publishes them.
  • Bug bounties — continuous, confidential coverage of live production systems. This is the format the report lifecycle in these docs describes: you submit a report, CertiK triages it independently, the project reviews it, and the project pays you directly.

#Your access level

Every account sits on a three-rung ladder, and each rung inherits everything below it:

LevelWhat it opens
ChallengerSecurity challenges
SentinelChallenges, plus the full detail page of a bug bounty program
VanguardEvery format, including submitting bug bounty reports

Manual invitation codes always start at Challenger. An approved application may start at Challenger, Sentinel, or Vanguard, chosen by the reviewer before the account exists. The rung is applied once when the matching verified CertiK email first signs in; later changes are made on the researcher account.

Your dashboard states which rung you hold and what it opens today. Promotions are a manual CertiK decision — an operator raises your level and the change is recorded against your account. There is no published, automatic promotion threshold yet; strong challenge results are the intended signal.

#Getting access

Hunt has two researcher-admission paths:

  • Redeeming a manual invitation code. It is a separate bearer credential and creates a Challenger account.
  • Applying for access. Tell us about your background and link your public profiles. If approved, your normalized verified CertiK email is authorized directly; there is no application code to redeem.

#After you're accepted

When your account is approved, a short onboarding captures your profile and specialties. Onboarding is required before you can enroll in anything. After that, what you can do depends on your rung:

Every researcher, from Challenger up

  • Browse Explore to see the live challenges and bug bounty programs. Engagements above your rung stay listed and state what they require — they just don't open.
  • Open a challenge, read the mission, schedule, resources, and announcements, and enroll. Enrolling means accepting that challenge's rules; some challenges cap enrollment, and you can withdraw while the challenge is still running.

Sentinel and above

  • Open the full detail page of a bug bounty program to read its scope, assets, and reward ranges.

Vanguard only

  • Submit a report against an in-scope asset in a bug bounty program you can reach.
  • Track your reports through triage, project review, and payment from your dashboard.

Bug bounty access is two gates, not one. The Vanguard rung opens the report pipeline; the program's own entry rule then decides which programs you reach. An open program that is live and taking submissions is reachable by any Vanguard. An invite-only program needs a grant on your account, which you request through its apply link.

The rest of these docs walk through each of those steps in detail. If you're new, read How it works next, then Writing a great report before your first submission.