Getting Started
What CertiK Hunt is, the three engagement formats, and what your access level opens.
CertiK Hunt is a private, invite-only Web3 security network. Vetted researchers surface real vulnerabilities in participating projects, and CertiK independently reproduces and rates every finding before it reaches the project — so severity isn't quietly negotiated down to dodge a payout.
This documentation explains how the platform works, how to submit findings that get accepted and paid, and the rules every participant agrees to.
#Who Hunt is for
Hunt is built for security researchers who want high-signal work and fair, independent review. If you find and responsibly disclose vulnerabilities in smart contracts, blockchain/DLT systems, or web applications, Hunt is for you.
#Three engagement formats
Hunt runs three formats on one researcher network. They are genuinely different products, not three labels on the same workflow:
- Security challenges — focused, time-boxed missions with a published window, a set of instructions, and an enrollment step. Finish one and you have a verified track record on Hunt rather than a claim. Scoring and results stay sealed until CertiK publishes them.
- Audit contests — fixed-window reviews of pinned code. The repository, the exact commit, the scope, the deadline, the duplicate policy, and the judging criteria are all published before submissions open, and a shared prize pool is split by the judged outcome.
- Bug bounties — continuous, confidential coverage of live production systems. This is the format the report lifecycle in these docs describes: you submit a report, CertiK triages it independently, the project reviews it, and the project pays you directly.
#Your access level
Every account sits on a three-rung ladder, and each rung inherits everything below it:
| Level | What it opens |
|---|---|
| Challenger | Security challenges |
| Sentinel | Challenges + audit contests, and the full detail page of a bug bounty program |
| Vanguard | Every format, including submitting bug bounty reports |
New accounts start at Challenger unless an admin or your invite grants a higher rung. That is deliberate: challenges are the entry point, and the rung you land on is set when your account is admitted, not by anything you do in onboarding.
Your dashboard states which rung you hold and what it opens today. Promotions are a manual CertiK decision — an operator raises your level and the change is recorded against your account. There is no published, automatic promotion threshold yet; strong challenge results are the intended signal.
#Getting access
Hunt is invite-only. You can join by:
- Redeeming an invite if you've received one.
- Requesting an invite through the application flow. Tell us about your background and link your public profiles — GitHub, X, audit work, past disclosures, and your profiles on other bug-bounty platforms (Immunefi, HackerOne, Code4rena, and others).
#After you're accepted
When your account is approved, a short onboarding captures your profile and specialties. Onboarding is required before you can enroll in anything. After that, what you can do depends on your rung:
Every researcher, from Challenger up
- Browse Explore to see the live challenges, audit contests, and bug bounty programs. Engagements above your rung stay listed and state what they require — they just don't open.
- Open a challenge, read the mission, schedule, resources, and announcements, and enroll. Enrolling means accepting that challenge's rules; some challenges cap enrollment, and you can withdraw while the challenge is still running.
Sentinel and above
- Enter audit contests, and open the full detail page of a bug bounty program to read its scope, assets, and reward ranges.
Vanguard only
- Submit a report against an in-scope asset in a bug bounty program you can reach.
- Track your reports through triage, project review, and payment from your dashboard.
Bug bounty access is two gates, not one. The Vanguard rung opens the report pipeline; the program's own entry rule then decides which programs you reach. An open program that is live and taking submissions is reachable by any Vanguard. An invite-only program needs a grant on your account, which you request through its apply link.
The rest of these docs walk through each of those steps in detail. If you're new, read How It Works next, then Writing a Great Report before your first submission.