# Secure3

Secure3 is an innovative platform revolutionizing the security landscape of Web3 through its decentralized approach to Web3 project auditing, by organizing audit contests that engage a diverse community of globally certified auditors. Learn more [here](/who-we-are).

### **Roles in Secure3**

* [**Projects**](/projects/audit-quality-assurance): Sponsor the audit contest and reward the auditors who helped secure their code.
* [**Auditors**](/auditors/become-a-secure3-auditor): Secure the Web3 ecosystem together through community-driven and collaborative audit contests
* **Secure3:**
  * Work together with *Projects* to ensure the spending is optimized for the best security coverage through:
    * Continuous improvement on the [**Intelligent Auditor Matching**](/features/intelligent-matching) mechanism
  * Work together with *Projects* and *Auditors* to ensure auditors' hard work is fairly evaluated and rewarded
    * Continuous improvement on the [**Incentive Model**](/features/incentive-model) and [**Severity Standard** ](/features/severity-standard)that strives for community growth

### What You'll Get from Secure3

Secure3 stands out in the Web3 security space by merging **decentralized intelligence with a performance-based incentive model**. This approach optimizes costs and enhances transparency, ensuring thorough, high-quality audits through collaboration with a global network of certified auditors.

#### **Secure3 Audit Contest** vs **Traditional Audit**

The Secure3 Audit Contest brings an innovative, decentralized, and performance-driven model to auditing, advancing beyond the limitations of centralized audits.

<table><thead><tr><th width="137"> </th><th width="323">Secure3 Audit Contest</th><th>Traditional Audit</th></tr></thead><tbody><tr><td><strong>Pricing</strong></td><td><strong>Affordable Pricing</strong>: Flexible fees tailored to your budget, with no fixed overhead.</td><td><strong>Expensive with Fixed Costs</strong>: Typically incur high fees due to overhead and firm salaries.</td></tr><tr><td><strong>Process Tracking</strong></td><td><strong>Transparency</strong>: Offers clear and open visibility at every stage of the audit.</td><td><strong>Sometimes Opaque</strong>: Often lacks insight into processes.</td></tr><tr><td><strong>Efficiency</strong></td><td><strong>Fast Turnaround</strong>: Audits can start within <strong>24 hours</strong>, providing rapid security coverage.</td><td><strong>Long Wait Time</strong>: Frequently experiences weeks-long waiting periods for audits.</td></tr><tr><td><strong>Coverage</strong></td><td><strong>Wide &#x26; Diverse Coverage</strong>: Engage <strong>5-50x more</strong> auditors, covering a variety of angles and expertise.</td><td><strong>Limited Coverage</strong>: Only 2-3 auditors per project, often repeating routine tasks.</td></tr><tr><td><strong>Incentive Model</strong></td><td><strong>Great Incentive</strong>: Rewards are allocated solely based on performance—no findings mean no rewards.</td><td><strong>Poor Incentive</strong>: Lacks motivation for auditors to go beyond routine checks.</td></tr><tr><td><strong>Post-Audit Support</strong></td><td><strong>Ongoing Support</strong>: Provides continuous assistance to ensure long-term code security.</td><td><strong>Limited Support</strong>: Typically restricts follow-up to the initial audit only.</td></tr></tbody></table>

#### **Secure3 Audit Contest** vs Bug Bounty

The Secure3 Audit Contest is a pre-launch audit, serving as the final, comprehensive security check before your project goes live. In contrast, Bug Bounty programs typically run after a project has launched and focus on continuous vulnerability identification.

<table><thead><tr><th width="147"></th><th width="319">Secure3 Audit Contest</th><th>Bug Bounty</th></tr></thead><tbody><tr><td><strong>Incentive Model</strong></td><td><strong>Great Incentive</strong>: Rewards are distributed based on performance—no findings, no rewards—encouraging auditors to uncover unique insights</td><td><strong>Poor Incentive</strong>: Winner-takes-all, with only one reward per issue, leading to low engagement</td></tr><tr><td><strong>Participation Model</strong></td><td><strong>Auditor Matching</strong>: Only certified auditors with relevant expertise are matched to projects</td><td><strong>Short-term Engagement</strong>: Open to anyone at any time, without sustained commitment</td></tr><tr><td><strong>Focus of Effort</strong></td><td><strong>Dedication &#x26; Focus</strong>: Auditors focus on one project at a time, ensuring thorough security and business analysis of your code</td><td><strong>No Focus</strong>: Whitehats juggle multiple projects, focusing only on low-hanging vulnerabilities</td></tr><tr><td><strong>Efficiency of Findings</strong></td><td><strong>High Efficiency</strong>: Cross-examination and validation handled in-house for optimized turnaround.</td><td><strong>Low Efficiency</strong>: High-quality findings are overwhelmed by random submissions</td></tr></tbody></table>

### **How Secure3 Ensures Better Audit Quality**

Secure3’s Audit Contests deliver end-to-end security solutions, from mainnet launch prep to ongoing code improvements, covering smart contracts, protocols, dApps, and more. Our performance-based incentives, intelligent auditor matching, transparent severity standards, and rigorous grading ensure top-tier, consistent audit quality tailored to your Web3 project’s needs. Learn more about our [Audit Quality Assurance](/projects/audit-quality-assurance).

### **How Secure3 Works**

This documentation provides essential guidelines and [FAQs](/faqs) about Secure3 and our decentralized audits. Here are some key sections that our community members often explore:

#### **For Projects**

* [How Audit Contest Works](/projects/audit-quality-assurance)
* [Audit Process with Secure3](/projects/how-audit-contest-works)
* [Preparation for a Secure3 Audit](/projects/audit-preparation)
* [Intelligent Auditor Matching for Your Project](/features/intelligent-matching)
* [How Severity is Accessed and Rated](/features/severity-standard)
* [How Rewards Are Allocated Based on the Incentive Model](/features/incentive-model)

#### For Auditors

* [How to Become a Secure3 Auditor](/auditors/become-a-secure3-auditor)
* [How to Participate in Audit Contests](/auditors/participate-in-audit-contests)
* [Learn the Submission Guidelines](/auditors/submission-and-grading)
* [Learn the Severity Standard](/features/severity-standard)
* [Understanding Incentive Allocation](/features/incentive-model)
* [How to Claim Your Rewards](/auditors/how-to-get-your-rewards)
* [Access Your Auditor Profile and Leaderboard](/auditors/profile-and-leaderboard)


# Who We Are

[Secure3](https://secure3.io/) is a **Web3 Security Audit** platform headquartered in Silicon Valley, leveraging a decentralized approach to protect smart contracts, blockchain protocols, dApps, cross-chain bridges, codebases, and the wider Web3 ecosystem against bugs and technical threats.&#x20;

Joined by globally certified auditors and security experts, Secure3 provides a range of services, including **audit contests**, **bug bounties**, and **accelerator programs**, delivering security solutions that cover every stage of your project lifecycle—from initial launch and on-chain deployment, to token issuance and ongoing iteration, ensuring comprehensive protection throughout the entire Web3 journey.

### Trusted By Leading Projects

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FeVBMH3qSLtIVXBPL0YvO%2FA1A4BogphI.png?alt=media&amp;token=3045bfc3-ab6d-4038-b566-2f2f2f67d978" alt=""><figcaption></figcaption></figure>

### Backed By Top-Tier Capitals

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FRw4glorvSP6PcwKtgzvt%2FEN-2%20(1).png?alt=media&amp;token=b6d40b0f-c7d3-40ae-8ff8-8bf50661f10d" alt=""><figcaption></figcaption></figure>


# What We Do

The Secure3 Audit Contest is a decentralized security competition where projects sponsor rewards for auditors to identify vulnerabilities. Auditors compete based on the severity and uniqueness of their findings, ensuring comprehensive security coverage and enhancing project safety.

Our Audit Contest supports Web3 projects by delivering security solutions that cover every stage of the project lifecycle—from initial launch and on-chain deployment to token issuance and ongoing iterations, effectively safeguarding against bugs and technical threats.

{% hint style="success" %}
[Request a Free Quotation to Sponsor an Audit Contest](https://tally.so/r/mOlevY).
{% endhint %}

### What Our Audit Contest Serves

Our Audit Contest encompasses a wide range of security assessments to ensure the integrity and safety of your project. We provide Audit Contests for:

| Smart Contract | L1/L2 Blockchain Protocol | dApp     |
| -------------- | ------------------------- | -------- |
| Wallet/Tool    | Cross-chain Bridge        | Codebase |
| Tokenomics     | Business Logic            | ...      |

We have conducted **200+ audit contests** for leading crypto projects across various technology stacks, including:

<table data-header-hidden><thead><tr><th width="241"></th><th></th></tr></thead><tbody><tr><td>ZK Circuit</td><td>Circom, ZoKrates, Cairo</td></tr><tr><td>L1/L2, Bridge, Wallet</td><td>Go, Rust, Solidity, TypeScript/JavaScript</td></tr><tr><td>Smart Contract</td><td>Backend &#x26; API, Mobile App, Frontend App</td></tr><tr><td>...</td><td>...</td></tr></tbody></table>

We have already provided services to projects in DeFi, NFT, Bridge, Staking, GameFi, L1/L2, Modular, Oracle, and many others across various ecosystems, including:

| zkSync  | Ethereum | Polkadot  | Solana |
| ------- | -------- | --------- | ------ |
| Polygon | Mantle   | Optimism  | BSC    |
| Base    | Arbitrum | Avalanche | Neo    |
| IoTeX   | Aptos    | Manta     | Blast  |
| zkLink  | Celo     | Linea     | ...    |

{% hint style="success" %}
Explore more about our audit contest cases [here](https://app.secure3.io/).
{% endhint %}


# Fusion Accelerator Program

At Secure3, we believe that secure growth and scaling are the foundations of mass adoption in the Web3 space. To support promising projects from early-stage development to scaling, we provide Accelerator Programs that help navigate the complexities of blockchain development.

### Fusion Program

The [Fusion Program](https://secure3.io/fusion) is designed to fuel the growth of early-stage projects by offering comprehensive security support and essential resources. Our initiative empowers projects to scale securely and confidently in an ever-evolving landscape.

Traditionally, the Audit Contest model has focused solely on the whitehat community. Now, we are expanding to enable everyone to contribute in various ways. This approach adds value to both projects and their user communities, ensuring everyone has a stake and contribution in securing the future of Web3 mass adoption.

Leave your email here to stay updated on the Fusion Program and learn how to get involved <https://secure3.io/fusion>.


# FAQs

Find answers to your most common questions and get the support you need

### General

<details>

<summary>What is Secure3?</summary>

Secure3 is a Web3 security audit platform that utilizes a decentralized approach to protect the Web3 ecosystem from bugs and technical threats. With a global community of certified auditors and security experts, we provide comprehensive security solutions to safeguard every stage of your Web3 journey. Learn more [here](/).

</details>

<details>

<summary>What is an audit contest?</summary>

An audit contest is a decentralized security competition where projects sponsor rewards for auditors identifying vulnerabilities in their smart contracts, protocols, and code. Auditors compete based on the severity and uniqueness of their findings, driving comprehensive security coverage to strengthen project safety.&#x20;

Learn more about [how audit contests work here](/projects/audit-quality-assurance).

</details>

<details>

<summary>How is Secure3 Audit Contest different from Centralized Audits?</summary>

The Secure3 Audit Contest redefines traditional auditing with a decentralized, performance-driven model. Unlike centralized audits, which often face challenges like high costs, limited auditor engagement, and lack of transparency, Secure3 provides a superior solution through:

* **Affordable Pricing**: Flexible fees tailored to your project, avoiding the high fixed costs associated with centralized firms.
* **Transparency**: Full visibility into every audit stage, enabling you to track progress and verify auditors’ expertise.
* **Fast Turnaround:** Audits start within 24 hours, ensuring rapid and effective security coverage.
* **Comprehensive Coverage**: Secure3 engages 5-50x more auditors than centralized audits—more eyes, more security—bringing diverse expertise and thorough analysis to your project.
* **Incentive Alignment**: Performance-based rewards motivate auditors to deliver focused, high-quality results—no findings, no rewards.
* **Ongoing Security Support**: Post-audit assistance ensures continued security beyond the initial assessment.

By eliminating inefficiencies and prioritizing performance, Secure3 delivers audits that are faster, more transparent, and tailored to your Web3 project’s unique needs. [Read more here](/#secure3-audit-contest-vs-traditional-audit).

</details>

<details>

<summary>How is Secure3 Audit Contest different from Bug Bounty?</summary>

The Secure3 Audit Contest is a pre-launch audit designed as the final security check before your project goes live, while Bug Bounty programs run after launch.

* **Incentive Model**: Secure3 rewards auditors based on performance—no findings, no rewards—ensuring auditors focus on uncovering high-value insights, while Bug Bounties often use a winner-takes-all model.
* **Participation Model**: Secure3 only matches certified auditors with relevant expertise to your project, ensuring quality and consistency, while Bug Bounties are open to anyone, , often resulting in varying skill levels.
* **Focus of Effort**: Secure3 auditors dedicate their attention to a single project at one time, providing thorough security and business analysis. In Bug Bounties, auditors juggle multiple projects, often lacking focus.
* **Efficiency of Findings**: Secure3 handles cross-examination and validation in-house, ensuring a quicker turnaround and actionable results.&#x20;

[Read more here.](/#secure3-audit-contest-vs-bug-bounty)

</details>

<details>

<summary>What contests has Secure3 held before?</summary>

You can view all our published contests [here](https://secure3.io/contest/) and explore our public contest reports [here](http://secure3.io/reports).

Secure3 has conducted over 200 audit contests for leading projects across various ecosystems and languages, including zkSync, Mantle, IoTeX, dappOS, Manta, Polkadot, zkLink, Neo, Merlin Chain, Aark, FBTC, OKX, Stakestone, Doodles, Shardeum, Mirror World, Aki Network, Zeek, and many more.

Please note that some contests are currently private and not publicly visible. They will be published once the hosts decide to make them available.

</details>

### Project

<details>

<summary>How soon can I start my audit with Secure3?</summary>

Based on your demand and timeline, we can kick off your audit contest in as fast as 24 hours.

</details>

<details>

<summary>How can I request an audit for my project with Secure3?</summary>

Head over to this [link](https://tally.so/r/mOlevY) and complete the form. Our team will get in touch with you shortly after you submit your request.

</details>

<details>

<summary>Do auditors check the fixes?</summary>

Your fixes will be verified by the Secure3 team, and we will discuss and double-check with auditors if clarification is needed.

</details>

<details>

<summary>Does Secure3 utilize AI or automated tools to audit?</summary>

We, along with our auditors, strictly refrain from using any AI tools that could expose project code without the project team’s explicit written consent. With permission, select in-house AI tools may be utilized to support the audit process.

However, we recognize that current AI tools cannot yet meet the quality standards for comprehensive audits, which require an understanding of business logic and in-depth security analysis.

Our strict [submission policy](/auditors/submission-and-grading) also enforces penalties for unhelpful or automated findings to maintain the integrity of our audits.

</details>

<details>

<summary>How's the audit contest cost structured and determined?</summary>

1. A small cut will be taken by Secure3 to maintain platform operations, such as auditor screening, submission grading, and validation, fix verification, and report preparation.
2. The majority of the contest costs go to the reward pool, which will eventually distributed to all the auditors based on their performance. The reward pool is mainly determined by:
   1. Amount of the code that needs to be audited
   2. The complexity of the code, such as external dependencies
   3. The nature of the business logic - some protocols are intrinsically more vulnerable than others
   4. Contest time
   5. Number of auditors to participate in the contest

Due to high demand, we are only able to lock the audit schedule after receiving the full deposit from the projects. We are unable to make scheduling commitments otherwise.

</details>

<details>

<summary>How do you ensure the quality of the audit?</summary>

We ensure the quality of audits through our incentive model, auditor matching, a transparent severity standard, and rigorous grading. Learn more [here](/projects/audit-quality-assurance#how-secure3-ensures-better-audit-quality).

</details>

<details>

<summary>What options are available to try Secure3 audit contests at a lower cost?</summary>

We welcome all projects to do a trial audit contest with us to experience our service firsthand. We are confident you can find value for your project. Some ways to mitigate your costs on the first try:

1. Extract an independent or standalone module for audit
2. Try a contest plan that has fewer auditors, meanwhile also do a head-to-head comparison with other auditing firms

</details>

<details>

<summary>How does Secure3 handle feature updates and incremental audits?</summary>

For Secure3's returning projects:

1. We will figure out the scope for incremental audits together with you
2. For the audit contest, we will retain half of the auditors from the previous contest to ensure continuity, while the other half will be new, providing fresh insights and perspectives.

For new projects:

1. Please provide your code and your previous audit report, we will figure out the scope for incremental audits together with you

</details>

<details>

<summary>Where can I track my audit progress?</summary>

Once the contest is kicked off, we will provide you with a private portal for you to track the progress of your audit contest

You will also receive graded and consolidated weekly finding summaries if your contests last longer than 2 weeks.

</details>

### Auditor

<details>

<summary>How do I sign up to become a Secure3 auditor?</summary>

To sign up as a Secure3 auditor, [create your account](https://secure3.io/contest/signup) and [set up your profile](https://secure3.io/contest/settings). Include your performance data and relevant experience. You can also apply to become certified to gain access to private contests. Learn more about the guidelines [here](/auditors/become-a-secure3-auditor).

</details>

<details>

<summary>Can I work with my friend as a team?</summary>

You can choose to audit individually or as part of a team; however, if you collaborate with colleagues, please ensure all findings are submitted under the same account, as different accounts will be treated as separate participants. This means your team will receive rewards as individual participants.

</details>

<details>

<summary>How do I get my rewards?</summary>

You need to verify grading results and file an appeal if necessary, complete the Tax Verification Process, and confirm your wallet address along with the reward amount. Learn more about the guidelines [here](/auditors/how-to-get-your-rewards).

</details>

<details>

<summary>How does the contest grading work?</summary>

Contest grading starts with an initial review from Secure3’s internal team and a secondary review from the project’s engineering team. Issue severity is assessed based on the degree of damage and the difficulty of exploitation — see our [Severity Standards](/features/severity-standard) for more details. Secure3 values client feedback and maintains technical neutrality throughout the grading process.

</details>

If you have any more questions, feel free to [follow us on](https://twitter.com/secure3io) [X](https://twitter.com/secure3io) and join our [Discord](https://discord.gg/n2dRfnVgPZ) for the latest updates and support.


# Audit Quality Assurance

{% hint style="success" %}
[Request a Free Consultation to Sponsor an Audit](https://tally.so/r/mOlevY).
{% endhint %}

Our Audit Contests support your project's security needs at every stage, from preparing for the mainnet launch to updating and enhancing existing code. With an adaptable approach that spans smart contracts, blockchain protocols, dApps, cross-chain bridges, and codebases, we deliver tailored insights to protect your Web3 project from bugs and vulnerabilities.

### How Secure3 Ensures Better Audit Quality

1. Performance-Based Incentive model
2. Intelligent Auditor Matching
3. Transparent and Iterative Severity Standard
4. Rigorous and Consistent Grading and Appeal Standard

**Performance-Based Incentive Model**

Secure3 rewards auditors based on performance, focusing on those who uncover significant, unique issues and offer actionable, constructive solutions.

[Learn more about our Incentive Model](/features/incentive-model).

**Intelligent Auditor Matching**

Using an intelligent matching mechanism, we carefully match auditors to your project based on their technical expertise and proven track record, ensuring each audit team is highly aligned and customized to your specific needs.

[Learn more about our Intelligent Auditor Matching system.](/features/intelligent-matching)

**Transparent Severity Standard**

Our severity standards are transparent and iterative, encouraging community feedback to continuously improve. This open model transforms security standards from a monopoly into an inclusive, collaborative platform that fosters shared learning and contributions.

[Learn more about our Severity Standard](/features/severity-standard).

**Rigorous and Consistent Grading and Appealing Standard**

All grading is conducted internally to be fully obliged to severity standards. Constructive feedback and appeals from both projects and auditors are thoughtfully integrated into our assessments, with our internal team navigating all technical debates, discussions, and consolidations.

[Learn more about our Grading Standard](/auditors/submission-and-grading).

***

We welcome[ your feedback and suggestions](https://github.com/Secure3Audit/Secure3Academy/blob/main/IssueSeverityDefinition.md). Our issue severity database will also be open in the future, so stay tuned and [follow us on X for the latest updates](https://x.com/secure3io).<br>


# How Audit Contest Works

The Secure3 Audit Contest ensures that every step is tailored to your needs, providing a seamless experience from start to finish. Our customizable approach offers a streamlined and efficient auditing process, allowing you to focus on your project's development while we manage all security aspects. With ongoing support and a commitment to thorough validation, we help you maintain a secure and robust project.

### Efficiency Comes From Each Step

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FZQdPY42j7I8TegDoJJUT%2Fimg_v3_02ga_00d4e422-518d-4072-8226-700bdc70ee5h.png?alt=media&amp;token=98cbe598-a2c6-4e33-8475-ac0d839cc2e3" alt=""><figcaption><p>Audit Contest Process with Secure3</p></figcaption></figure>

### How the Audit Contest Works

#### Before the Audit Contest

1. [**Contact us**](https://tally.so/r/mOlevY) **and send**:
   * Your code and scope
   * Supporting materials (designs, diagrams, etc.)
   * Specific requirements (timeline, budget, etc.)
2. You will receive a **suggested audit plan** that includes:
   1. Contest Duration
   2. Number of Auditors
   3. Prize Pool

#### During the Audit Contest

1. **Contest Schedule & Kick-off**&#x20;
   * Begins within 24 hours of finalizing the plan
2. **Auditor Competition**
   * Code freezes
   * Auditors submit findings confidentially
   * Regular updates for contests over 2 weeks
3. **Issue Submission & Review**
   * Secure3 validates and grades submissions, sharing results before the deadline
   * Your engineering team verifies the findings
4. **Final Audit Report Delivery**
   * We integrate your feedback to deliver a comprehensive report with actionable insights

#### After the Audit Contest

1. **Ongoing Marketing Support**
   * We're here to support your ongoing Marketing & PR initiatives, tailored to your needs
2. **Continuity on Your Incremental Changes Audits**
   * Half of the previous auditors will be involved in your next audit to ensure continuity.
   * Half of the auditors will be new faces to ensure different and all-around inspection angles.

{% hint style="success" %}
Find more details in our [Project FAQs](/faqs#project).
{% endhint %}


# Audit Preparation

Before engaging with an audit team, consider the following key questions to ensure the audit process is focused and effective. This checklist is valuable not only for the Secure3 team and auditor community but also for other reputable auditing firms.

### Checklist

* [ ] **Project Architecture**: What is the project's general architectural structure and system design?
* [ ] **Roles & Workflows**: What are the roles in the product and the use cases and workflow for each role?
* [ ] **Critical Attack Vectors**: Which function's or module's attack vector do you have the most concern about?
* [ ] **Focus Areas**: Which parts of the system that you want the auditors to focus on?
* [ ] **Trust Model**: What is the trust setup of the system? Should all centralized roles and components be trusted?
* [ ] **Known Vulnerabilities**: List all the vulnerabilities that are not accepted or already known to the team.
* [ ] **Additional Documentation**: Is there any other information or docs the auditor should know?


# Project FAQ

### What is the difference between you and centralized firms?

Secure3's audit contests represent a new generation of auditing, overcoming many of the flaws ingrained in traditional centralized auditing. For more details on how Secure3 is better, please see our comparison chart ->[ ](/)[Secure3](/)

### How soon can I start my audit with Secure3?

Based on your demand and timeline, we can kick off your audit contest in as fast as 24 hours.

### Do auditors check the fixes?

Your fixes will be verified by the Secure3 team, and we will discuss and double-check with auditors if clarification is needed.

### Does Secure3 utilize AI or automated tools to audit?

1. We and the auditors will **NOT** use any AI tools that can leak projects' code without prior written permission from projects
2. With the projects' permission, there are certain in-house AI tools will be utilized to assist in audit contests.
3. However, we don't see any AI tools that can perform quality audits yet, as our audit requires understanding the business logic and in-depth security analysis.
4. We also have a strict submission policy that also penalizes submitting useless automatic findings. More details -> [Submission Policy](/auditors/submission-and-grading)

### How's the audit contest cost structured and determined?

1. A small cut will be taken by Secure3 to maintain platform operations, such as auditor screening, submission grading, and validation, fix verification, and report preparation.
2. The majority of the contest costs go to the reward pool, which will eventually distributed to all the auditors based on their performance. The reward pool is mainly determined by:
   1. Amount of the code that needs to be audited
   2. The complexity of the code, such as external dependencies
   3. The nature of the business logic - some protocols are intrinsically more vulnerable than others
   4. Contest time
   5. Number of auditors to participate in the contest

\
Due to high demand, we are only able to lock the audit schedule after receiving the full deposit from the projects. We are unable to make scheduling commitments otherwise.

### How do you ensure the quality of the audit?

We ensure the quality of audits through our incentive model, auditor matching, a transparent severity standard, and rigorous grading. Please see more details -> [Projects](/projects/audit-quality-assurance)

### What options are available to try Secure3 audit contests at a lower cost?

We welcome all projects to do a trial audit contest with us to experience our service firsthand. We are confident you can find value for your project. Some ways to mitigate your costs on the first try:

1. Extract an independent or standalone module for audit
2. Try a contest plan that has fewer auditors, meanwhile also do a head-to-head comparison with other auditing firms

### How does Secure3 handle feature updates and incremental audits?

For Secure3's returning projects:

1. We will figure out the scope for incremental audits together with you
2. For the audit contest, we will retain half of the auditors from the previous contest to ensure continuity, while the other half will be new, providing fresh insights and perspectives.

For new projects:

1. Please provide your code and your previous audit report, we will figure out the scope for incremental audits together with you

### Where can I track my audit progress?

1. Once the contest is kicked off, we will provide you with a private portal for you to track the progress of your audit contest
2. You will also receive graded and consolidated weekly finding summaries if your contests last longer than 2 weeks


# Become a Secure3 Auditor

A healthy and growing auditor community is the cornerstone of Secure3's efforts to build a more transparent and secure Web3. At Secure3, we prioritize equal opportunities for all auditors, regardless of their background, ensuring they receive:

1. Equal opportunities to access Secure3 Audit Contests.
2. Measurement under **a fair, consistent, transparent,** and **constructive** technical evaluation standard.
3. Rewards that appropriately match the efforts and results of their contributions.

Follow us on [X](https://twitter.com/secure3io) and [GitHub](https://secure3.io/reports) to stay informed about new audits and updates.&#x20;

***

### Contest & Auditor Types

At Secure3, there are two types of audit contests:

1. **Open Contest**: any registered auditors can participate
2. **Intelligent Contest**: only matched and invited auditors can participate

Secure3 mainly focuses on intelligent contests, the main reasons are:

1. To make audit contests more accessible for a broader project base.
2. To reduce excessive competition, ensuring ROI for participants.

We are diligently refining our unique approach to ensure that more auditors can earn rewards more efficiently.

### How to Become an Auditor

Given the reason above, the Secure3 platform recognizes auditors into various categories:

<table><thead><tr><th width="135" align="center">Category</th><th width="316">What do you need to do?</th><th>Features</th></tr></thead><tbody><tr><td align="center"><strong>User</strong></td><td><ol start="1"><li><a href="https://secure3.io/contest/signup ">Create your account</a> on the Secure3 platform</li></ol></td><td><ol start="1"><li>Notified when there are new audits</li><li>Notified when there are updates</li><li>Can submit issues for <strong>Open Contests</strong></li><li>Participate in Future Features</li></ol></td></tr><tr><td align="center"><strong>Auditor</strong></td><td><p></p><ol><li>Have a total payout of at least $100 from other platforms. You can try to <a href="https://docs.secure3.io/auditors/profile-and-leaderboard#integrate-your-code4rena-and-sherlock-public-record">integrate your performance data from other contest platform</a></li><li>Connect your GitHub and Discord accounts.</li></ol></td><td><p></p><ol start="1"><li>Unique Identity Badge</li><li>Advantage in Future Features</li></ol></td></tr><tr><td align="center"><strong>Certified Auditor</strong></td><td>Auditors are invited to complete the certification process by Secure3 based on their profile and public record. Follow the <a href="#how-to-become-a-certified-auditor">guidelines below</a>.</td><td><p></p><ul><li>Get invited to <strong>Intelligent Contests</strong> based on <a href="/features/intelligent-matching">auditor matching</a></li><li>Choose to participate in the invited contest or not</li></ul></td></tr></tbody></table>

All upgrade options are available on the **Settings** of the[ Secure3 App](https://app.secure3.io/).

***

### How to Become a Certified Auditor

Certified auditors gain exclusive access to invite-only Intelligent Contests. To become certified, follow these steps:

1. Establish Your Track Record:
   1. [Add verifiable data to your profile](/auditors/profile-and-leaderboard).
   2. Participate in more Secure3 Open Contest to demonstrate your competency.
2. Verification:
   1. Verify your GitHub and Discord accounts.
   2. Join our [Discord](https://discord.gg/Dh6hFsmp) channel for community engagement.
3. Sign an NDA:&#x20;
   1. Sign a mutual NDA with Secure3, as clients often prefer auditors who maintain confidentiality.
   2. Provide your:&#x20;

      1. Real Name
      2. Email
      3. ID Number

      *We don't store this data; you only need to fill it out once on the E-Sign PDF sent via* [*eversign*](https://eversign.com/)*.*

Once you complete the certification process, you will be invited to Intelligent Contests based on your preferences and the project's needs.

*Note: To access an introduction about becoming a certified auditor, look for the corresponding button on your profile page.*

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FqnsnWzXSqR2rF6ThfZGf%2Fimage.png?alt=media&amp;token=1abac01b-ce00-4e2f-97c4-2f6178231036" alt=""><figcaption></figcaption></figure>

<br>


# Participate in Audit Contests

At Secure3, we have two types of contests: Open Contests and Intelligent Contests. Here’s how you can participate in each.

### Participating in the Open Contest

1. All registered auditors will receive notifications when an Open Contest is live. Open Contests can be viewed at [Secure3 Contests](https://secure3.io/contest).
2. [Auditors](/auditors/become-a-secure3-auditor#how-to-become-an-auditor) can participate and submit issues in open contests.

### Participating in the Intelligent Contest

1. [Certified Auditors](/auditors/become-a-secure3-auditor#how-to-become-a-certified-auditor) will be invited to participate in the intelligent audit contest based on their preferences and performance track record.
2. Invited auditors have the option to accept or decline the contest invitation.

To learn more about out the auditors are selected for the intelligent contests, please read more on [Auditor Matching](/features/intelligent-matching).

### Submitting Issues

1. Before submitting your issue, please review the [submission policy](/auditors/submission-and-grading).
2. How to submit your findings:
   1. Go to the Audit Contest page
   2. Click the Submit Issue button to submit your findings
3. Ensure you submit all findings before the contest deadline; the submission button will disappear after the deadline.
4. **Do not submit your findings as issues in the code repo** shared with you, as this will disclose your findings to other participants.
5. **Always submit issues on the contest detail page on the Secure3 website to avoid losing your submission data.**

### Understanding Grading

1. All submissions will be initially reviewed by Secure3's internal security team and passed to the projects' engineering team for secondary review and verification.
2. The severity of the issue is assessed from two dimensions: the **degree of damage** and the **difficulty of exploitation**. Please refer to [Severity Standard](/features/severity-standard) for more details.
3. The Secure3 team will honor client feedback and judgment, but will also maintain technical neutrality in the evaluation process.

**Why We Grade Internally**:

1. To ensure a speedy and consistent turnaround for both projects and auditors.
2. To more effectively and efficiently navigate through the technical debates, discussions, and consolidations.

### Appeals Process

We invite all participants to review and assess our final contest grades. Should you have any concerns, we encourage you to submit appeals along with meaningful and constructive feedback whenever possible.

* **Appeal Submission**: Once contest results are returned to auditors, the Create Appeal button will show up at the right of the submission page.

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FQj40YNYVv7CP2M8NHIlZ%2Fimage.png?alt=media&amp;token=72a2b203-b261-4627-854b-a770fe9cbdc9" alt=""><figcaption><p>Create Appeals</p></figcaption></figure>

* **Appeal Limitations**: You may appeal findings from other auditors, but each submission allows only one appeal opportunity. The final interpretation rests with Secure3.

### Get Your Rewards

Once all the appeals have been resolved, the final rewards will be shared with participants and ready to distribute. We do rewards distribution in a monthly manner. At the beginning of each month, we will distribute rewards for all contests that are finalized.

For more details on rewards, please visit the [Get Your Rewards](/auditors/how-to-get-your-rewards).

<br>


# Submission and Grading

As the Secure3 platform thrives and evolves, our commitment to maintaining the highest quality standards remains unwavering. Ensuring an optimal experience for all our clients and auditors is at the forefront of our mission.

### Submission and Grading Standard

#### **1. Automated Findings**

* All submissions generated by automation tools and **not verified by human moderation** **will be directly rejected.**
* The auditors who intentionally submit **unverified** automated findings will face a possible ban.

#### **2. Gas Optimization**

* **Detailed evidence with supporting data** is mandatory for submissions about gas optimizatio&#x6E;**. This evidence should demonstrate that your suggestion leads to significant gas savings**.

#### **3. Coding Style**

* Suggestions highlighting coding styles such as documentation discrepancies, comment clarifications, compiler versions, naming conventions, custom error replacing require or assert, library versions, test modules, etc. are not eligible for rewards.
* **Exception**: if you can present concrete proof—either through a proof of concept (PoC) or factual data—indicating that a particular coding style issue can inflict substantial damage

#### **4. Excluded issue**

The following vulnerabilities are not accepted by Secure3:

* Lack of Zero Address Validation.
* Insufficient validation for the parameter zero.
* Unlocked Pragma Version.
* Some events miss the Keyword index.
* Inconsistent solidity compiler version.
* Missing error message in required statements.
* Unfinished TODOs and missing implementation.
* Typo in function/variable name or otherwise.
* Unuse the latest solidity version.
* hardcoding chain address.
* Potential divided by zero error.
* Remove Renounce Ownership

{% hint style="warning" %}
*Note： If the above vulnerabilities are submitted, they must be able to directly cause loss, which would potentially be accepted.*
{% endhint %}


# How to Get Your Rewards

Before we distribute rewards, there are three key steps for auditors:

1. Verify grading results, and file an appeal if you disagree. Learn more about the [Appeals Process](/auditors/participate-in-audit-contests#appeals-process).
2. Complete your [Tax Verification Process](#tax-verification-process).
3. Confirm your wallet address and your reward.

<br>

{% @mermaid/diagram content="flowchart LR
A(Email Confirmation with Reward and Wallet)-->C{Tax ID Verified?}
C--Yes-->D(Confirm Wallet Address and Reward Amount)
C--No-->E(Tax Verification Details)
D-->F(Receive Rewards)
E-->F" %}

### Tax Verification Process

The managing company of Secure3 (OpenZoo Tech, Inc.) is incorporated in the US and regulated by the [IRS](https://www.irs.gov). Per IRS requirements, before we distribute the rewards, you are required to fill in either W8BEN or W9 forms to identify your residence. W9 is for US residents, and W8BEN is for internationals.\
The form only needs to be completed every 3 years unless you have a residence change. The information will be collected on the forms are:

1. Name
2. Date of birth
3. Country of residence
4. Mailing address
5. TIN (W9) or foreign tax ID (W8BEN)

\
Secure3 will not store any of your private data in our system. The information will be collected via an IRS-certified service provider [https://www.track1099.com/ ](<https://www.track1099.com/ >)\
Learn more about the W8BEN or W9 forms:

1. <https://www.irs.gov/forms-pubs/about-form-w-9>
2. <https://www.irs.gov/forms-pubs/about-form-w-8-ben>

**If any fraudulent or false information is identified during the NDA or tax verification process, we reserve the right to deny your service. Ensuring compliance and the accuracy of provided information is mandatory for all participants.**

#### Form Samples - How to Fill?

| W9                                                                                                                                                                                                                                                        | W8BEN                                                                                                                                                                                                                                                     |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FNYqWD558yFbTWccr1xAC%2Fimage.png?alt=media&amp;token=0dd3928b-f6d2-4b1c-bfc4-443a0a8ea0d1" alt="" data-size="original"> | <img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FPzHTvTq4M5MaFwFGfM6f%2Fimage.png?alt=media&amp;token=eb338f52-4faa-431a-9784-dc25c675bc89" alt="" data-size="original"> |

### Reward Distribution

The reward will be distributed on a monthly basis at the beginning of each month for all the finalized (graded, reviewed, and appeal completed) contests.<br>


# Profile and Leaderboard

Secure3's open leaderboard aims to improve community transparency and foster a culture where everyone is encouraged to learn from each other, and collectively elevate web3 security with decentralized intelligence.&#x20;

{% hint style="info" %}
🏆 Check out your ranking and accolades on our [leaderboard](https://secure3.io/contest/leaderboard)!
{% endhint %}

### Public Record Integration

We've integrated public data from Code4rena, Sherlock and Cantina to ensure that every contribution from our community's security experts is recognized. This step reinforces our commitment to valuing and acknowledging the vital work the community members do.&#x20;

*\*Be aware that all the data may have delays.*

#### **How do we combine Public Records?**

If you have a Secure3 auditor account, you can integrate your public records into your account following this [instruction](#integration-guidelines).

If you don't have a Secure3 auditor account, you are more than welcome to [sign up for an account ](https://secure3.io/contest/signup)and integrate your existing Code4rena, Sherlock and Cantina records. Learn more about [what you can audit on Secure3](/auditors/become-a-secure3-auditor) if you are interested.

If the public record from Code4rena, Sherlock or Cantina is not integrated with any Secure3 account, the data that has the same handle name will be displayed together. For example:

1. The Code4rena handle `xyz` public records will be displayed and aggregated together on the leaderboard page if both `xyz` are not integrated by any Secure3 accounts.
2. Only the exact matched handles will be displayed together.

#### **Severity Mapping**

<table><thead><tr><th>Secure3</th><th>Code4rena</th><th width="150">Sherlock</th><th>Cantina</th><th>CodeHawks</th></tr></thead><tbody><tr><td>High (previously Critical)</td><td>High</td><td>High</td><td>High</td><td>High</td></tr><tr><td>Medium</td><td>Medium</td><td>Medium</td><td>Medium</td><td>Medium</td></tr><tr><td>Low</td><td>Low</td><td><br></td><td>Low</td><td>Low</td></tr><tr><td>Informational</td><td>Gas, Non Critical</td><td><br></td><td>Informational, Gas</td><td></td></tr><tr><td>Solo High</td><td>Solo High</td><td>Solo High</td><td></td><td></td></tr><tr><td>Solo Medium</td><td>Solo Medium</td><td>Solo Medium</td><td></td><td></td></tr></tbody></table>

Provide feedback to Secure3 severity definition at [Severity Standard](/features/severity-standard).

{% hint style="success" %}
If you have any questions or concerns about your data, please contact us at <https://secure3.io/help>.
{% endhint %}

### Integration Guidelines

#### Get the verification text

1. Log in to your Secure3 account.
2. Click  "Settings".

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2Fx4dffFxhpOhza9xE7IpU%2Fimage.png?alt=media&amp;token=d63249d4-17b6-4d8f-8e73-e4cccc27c3d5" alt=""><figcaption></figcaption></figure>

3. In the "Link Code4rena & Sherlock & Cantina" section, Copy the verification text.

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FG5gzjGRteOnMv8K90hJn%2Fimage.png?alt=media&amp;token=36f4b224-5130-4d96-9768-34bbd22c0302" alt=""><figcaption></figcaption></figure>

#### Make sure the verification text is publicly visible on your profile page

{% tabs %}
{% tab title="Code4rena" %}
Go to your Code4rena profile page, edit the "Bio" section **or** "About" section, paste the verification text, and save it to make sure the unique string of verification text is publicly visible on your profile page.

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FGDCqoJ7bvpvXbXpUmbvu%2Fimage.png?alt=media&amp;token=c5584dc9-c1c6-4c9a-8d26-d481d705220a" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Sherlock" %}
Go to your Sherlock profile page, find the "Bio" section, paste the verification text, and click "Update."

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FpWaMFrFY4Uezh7hjpZn8%2Fimage.png?alt=media&amp;token=62074e6e-093a-462b-9816-831c2fbafe1e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FtkVFYoZyvutXzIahTaDk%2Fimage.png?alt=media&amp;token=57bef5fe-d2d9-4926-9f0c-f51c7d13e91a" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Cantina" %}
Go to your Cantina setting page, edit the "Tagline" in "profile" section, paste the verification text, and save it to make sure the unique string of verification text is publicly visible on your profile page.

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FTI4bWbhneLaiWgB096ns%2Fimage.png?alt=media&amp;token=d802517e-2fa9-4a59-904d-9ed20732e448" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="CodeHawks" %}
Go to your Codehawks profile page, edit the "Username", paste the verification text after or replace it, and save it to make sure the unique string of verification text is publicly visible on your profile page.

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FprsTywklFkXeiWgDvcGi%2Fimage.png?alt=media&amp;token=ea0b37b3-ee4a-4bf3-8bee-5123ac66bc69" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

Please note that you don't need to completely modify your bio/About; just add the text to the end. After successfully verifying (which typically takes less than 10 seconds), you can promptly revert your bio/About to its original state.

#### Verify your handle

Return to the Secure3 settings,  enter your handle and click "Verify".

<figure><img src="https://4135437255-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FU883ZaJ6TMYRz2S8K52U%2Fuploads%2FE5OV7bEncH17c6bUtAlI%2Fimage.png?alt=media&amp;token=8f8eb0dd-9747-44b2-9c54-8bf14d646362" alt=""><figcaption></figcaption></figure>


# Auditor FAQ

## What contests has Secure3 held before?

1. You can find all the published contests here: <https://secure3.io/contest/>
   1. You can also find our public contest reports here: <http://secure3.io/reports>
2. Some contests are still private and not publicly visible yet. They will be published when the hosts decide so.

## Can I work with my friend as a team?

1. You can audit alone or as part of a team. It is entirely up to you.
2. We do not currently support team accounts, if you work with your colleagues, **please ensure you submit all your findings in the same account**. Different accounts will be treated as different participants.
3. Your team will receive the rewards as an individual participant.

## How do I get my rewards?

Learn more details at [Get Your Rewards](/auditors/how-to-get-your-rewards).

## How does the contest grading work?

Learn more about [grading](/auditors/participate-in-audit-contests#understand-grading).


# Incentive Model

### Changelog

**Jan 9th, 2024** - test new distribution algorithm, changes include:

1. Base share change from 10% to **5%**
2. **No more** separate pool for informational issues
3. **New** weight of Critical: Medium: Low: Informational -> **64 : 16 : 4 : 1**

***

### How to Win More Rewards - Cheat Sheet

To maximize your rewards, consider the following strategies:

1. Find **more critical** bugs
2. Find **Solo** bugs that **no other auditors find**
3. Write a **high-quality summary** of the findings
   * Clear root cause or reproduce logic or PoC
   * Actionable fix proposal
4. Submit **as many valid findings** as possible

***

### How do Secure3 Graders determine the reward?

#### Bug Categorization & Reward Share

Everyone who finds a valid bug will split **10%** of the total rewards. Bugs are categorized as follows:

* **High**, **Medium**, and **Low**: earn **81%** of the reward pool
* **Informational**: earn **9%** of the reward pool

The rewards ratio of High, Medium, and Low findings is **4: 0.6: 0.4**

#### Scoring System for Findings

Auditors' findings are rated on a scale of 0-3:

* **0**: Not a bug.
* **1**: Bug found, but no clear explanation or actionable fix provided.
* **2**: Average quality.
* **3**: Bug verified, with clear explanations, reproduction steps and actionable fix proposals.

Rewards for each bug are shared based on the score, ensuring that auditors who find the same bug split the reward according to their respective scores.

### Reward Distribution Logic

The final reward you can get as an auditor will solely depend on three dimensions:

* [**Your effort**](#id-1.-reward-efforts)
* [**The severity of your findings**](#id-2.-reward-severity)
* [**The quality of your findings**](#id-3.-reward-quality-of-findings)

#### **1. Reward Efforts**

If nobody can find a single bug in an audit contest, every participant equally splits 10% of the total pool to reward your efforts.

We believe in the capabilities of our auditors and are confident that bugs will be discovered. Therefore, as long as you identify verified issues, you will be entitled to an equal share of the 10% base reward.

> **Example**: If the total reward is $15,000 and there are 15 auditors who find verified bugs, each auditor will receive: Reward per auditor= $15000 \* 10% / 15 = $100

#### 2. Reward Severity

We reward your findings based on severity and quality. The performance portion (90% of the total reward) will be divided into two pools:

* **Critical/Medium/Low**: 81%
* **Informational**: 9%

> For the **definition of severity**, please refer to [Security Vulnerability Severity](/features/severity-standard). Feedback on the severity level definition is welcomed!

As the total number of bugs found in each project varies, we define the ratio of earnings between **Critical: Medium: Low** bugs to be **4: 0.6: 0.4,** and **Informational** bugs are equally divided by the number of findings.

Let's say there are in total of **x** critical bugs, **y** medium bugs, **z** low bugs, and **i** informational bugs found, the reward pool for each criticality is:

* Criticalshare = TotalRewards \* 81% \* 4x / (4x + 0.6y + 0.4z)
* Mediumshare = TotalRewards \* 81% \* 0.6y / (4x + 0.6y + 0.4z)
* Lowshare = TotalRewards \* 81% \* 0.4z / (4x + 0.6y + 0.4z)
* Infoshare = TotalRewards \* 9%

Empirically, *x < y < z << i.*

#### 3. Reward Quality of Findings

We value auditors who provide findings that are:

* **Unique**: No one else found the same issue.
* **High quality**: Includes a clear explanation of the root cause (or reproduction logic) along with an actionable fix plan.

Hence, to determine the reward for the quality of the finding, we have 2 layers of calculation:

* Within the same findings
* Within the same severity level

**Within the Same Findings**

To ensure trustworthy security audits and a competitive incentive model for auditors, we have established clear rubrics for evaluating the validity and quality of each bug. After submission, your findings will be reviewed and graded on a scale of **0-3**:

* **0:** The finding is **NOT** a bug.
* **1:** The bug is found, but there are **no clear or actionable suggestions** provided.
* **2:** Average quality—the finding meets some but not all quality criteria.
* **3:** The finding is valid, with clear explanations, reproduction steps, and actionable fix proposals.

The severity of the bug will also be adjusted during the review. In cases where multiple auditors receive the same score, we guarantee that they will earn equal rewards.

**Within the Same Severity Level**

When the quality of suggestions does not merit a score of 3, we weigh individual findings based on the highest score received for that finding:

* If there exist 3-point findings, reward weight *w* = *1.2.*
* If the highest point of all reported bugs on this finding is 2, *w* = *1.*
* If the highest point of all reported bugs on this finding is 1, *w* = *0.8*.

In simpler terms, if your suggestions are the most concise and actionable, you have the potential to earn **up to 50% more** than those with less effective suggestions.


# Intelligent Matching

At Secure3, we're committed to transforming audit contests through a precision-based auditor matching system, aligning auditors’ unique skills and preferences with the most suitable projects. By integrating advanced algorithmic solutions, we’re not only enhancing match precision but also significantly boosting overall audit effectiveness.

## **Key Criteria for Intelligent Matching**

1. **Auditor Preferences**: We prioritize individual preferences, including:

   * Time availability
   * Reward requirements&#x20;

   (Set your Audit Preferences by logging into your account).
2. **Performance in Past Contests**: We evaluate, including but not limited to:
   * Submission validity, severity, and ratings
   * Uniqueness of identified issues
   * Number of findings
   * Overall auditing experience and background
3. **Engagement and Activeness**: Engagement metrics include:
   * Early submissions
   * Number of submissions
   * Ensure submission when promised to participate
   * Meaningful appeals
   * Providing constructive feedbacks

Auditors seeking to increase their project visibility can improve in these areas to enhance their rankings and boost their invitation frequency for audit contests, optimizing opportunities for successful outcomes.


# Severity Standard

> If you have any feedback or suggestions: <https://secure3.io/feedback>

Blockchain security vulnerabilities are flaws and risks that emerge during the design, implementation, configuration, and operation of blockchain systems. These weaknesses can appear in various aspects, including system architecture, business logic, algorithm design, and code implementation. If exploited by attackers, such vulnerabilities can inflict substantial damage on the security of blockchain funds, data, networks, and nodes, disrupting the system's normal operations.

To objectively and quantitatively assess the threat level of these vulnerabilities, Secure3 has developed a set of comprehensive vulnerability grading rules based on CVSS 2.0 (Common Vulnerability Scoring System). Tailored specifically to the characteristics and application scenarios of blockchain systems, these methods are particularly suited for grading the security vulnerabilities of smart contracts.

## Severity Rating System

Vulnerabilities are essentially unintended security flaws or risks, which can be classified into four threat levels: "High", "Medium", "Low" and "Informational". The rating is mainly based on the **degree of damage** and **effort to exploit**:

<table><thead><tr><th width="235"></th><th width="150">high damage</th><th>medium damage</th><th>low damage</th></tr></thead><tbody><tr><td>low effort to exploit</td><td><mark style="color:red;"><strong>High</strong></mark></td><td><mark style="color:orange;"><strong>Medium</strong></mark></td><td><mark style="color:yellow;"><strong>Low</strong></mark></td></tr><tr><td>medium effort to exploit</td><td><mark style="color:orange;"><strong>Medium</strong></mark></td><td><mark style="color:orange;"><strong>Medium</strong></mark></td><td><mark style="color:green;"><strong>Informational</strong></mark></td></tr><tr><td>high effort to exploit</td><td><mark style="color:yellow;"><strong>Low</strong></mark></td><td><mark style="color:green;"><strong>Informational</strong></mark></td><td><mark style="color:green;"><strong>Informational</strong></mark></td></tr></tbody></table>

## **Degree of Damage**

### **High Damage**

High damage generally refers to the vulnerability that can have a bad impact on confidentiality, integrity, availability or its economic model of a smart contract, and can cause a lot of economic losses to the contract business features, large-scale data issue, privilege access compromise, failure of critical functions, and loss of credibility, or affecting the normal operation of other smart contracts interacting with it and cause a lot of losses and irreversible damage. Including but not limited to:

#### **Financial**

* **Permanent Asset Freezing:** The smart contract facilitates the permanent freezing of assets, rendering them inaccessible indefinitely, causing irreversible loss and financial hardship for affected users.
* **Significant Fraud:** Large-scale fraud that results in substantial financial losses.
* **Transaction Manipulation:** Alteration or interception of transactions resulting in significant financial losses.
* **Market Manipulation:** Exploits causing severe market price fluctuations and financial damage, such as Oracle Manipulation.
* **Critical Transaction Failures:** Failures in high-value transactions leading to major financial loss.
* **Economic Model Design Invalidity:** The core economic model design of smart contracts is invalid or can be altered, for example, introducing mining incentives with serious problems in the mechanism, leading to economic instability and distrust among stakeholders.
* **Major Fund Theft**: Unauthorized withdrawal or spending of large sums of assets from the smart contract.
* **Unauthorized Issuance**: Unauthorized large-scale additional issuance or overspending of assets, such as unauthorized minting of tokens.
* **Liquidity Draining:** Vulnerabilities that allow attackers to drain liquidity from decentralized exchanges or liquidity pools.
* **Systematic Double-Spending:** Large-scale double-spending attacks causing substantial economic loss.
* **Others:** Operations result in a large amount of assets locked or lost (please specify).

#### **Functional**

* **Core Functionality Compromise**: The core business functions are arbitrarily tampered with or bypassed, rendering the projects cannot operate as expected, such as signature verification, proof verification, etc.
* **Denial of Service(DoS):** The vulnerabilities can be exploited to exhaust resources such as gas, CPU cycles, or storage, etc., rendering the contract unusable.
* **RPC API Crash:** RPC API crash affects projects with greater than or equal to 25% of the market capitalization on top of the respective layer.
* **Governance Voting Manipulation:** Manipulation of Governance voting results deviating from the voted outcome and resulting in a direct change from the intended effect of the original results, undermining the democratic process.
* **Network Downtime:** Network not being able to confirm new transactions, resulting in total network shutdown, halting all transaction processing activities.
* **Hard Fork:** Unintended permanent chain split requiring a hard fork, leading to network partition and divergence in consensus, disrupting network operations.
* **Chain Split:** Unintended chain split causing network partition, leading to inconsistency in transaction validation and potential data inconsistencies.
* **Critical** **Data Integrity Compromise:** Vulnerabilities that compromise the integrity and reliability of data stored within the smart contract, allowing unauthorized modification, deletion, or exposure of sensitive information, compromising user trust and confidentiality.
* **Transaction Processing Overload:** Causing network processing nodes to process transactions from the mempool beyond set parameters, leading to congestion, delays, and potential network instability.
* **Fairness Design Invalidity:** The core fairness design of smart contracts is invalid, such as voting, lottery, auction, etc., leading to unfair outcomes and loss of trust among participants.
* **Non-Standard Interface Significant losses Issues:** Certain types of smart contracts use non-standard interfaces or implementations(e.g. EIP), affecting safe calls or interface compatibility, resulting in significant losses and operational disruptions.
* **Others:** Other flaws of functions can cause a severe system crash and cannot be recovered, resulting in significant losses(please specify).

### **Medium Damage**

Medium damage generally means that vulnerability can have a bad impact on confidentiality, integrity, availability or its economic model of the smart contract, and can cause moderate economic losses to the contract business system, partial function unavailability, and reduced credibility. Including but not limited to:

#### **Financial**

* **Temporary Asset Freezing:** The smart contract allows for the temporary freezing of assets, disrupting normal operations and causing inconvenience to users.
* **Minor Fund Freezing**: Temporary/Permanent locking of minor funds(e.g., unclaimed royalties, yield, etc.), resulting in moderate financial inconvenience for users.
* **Minor Fund Theft:** The smart contract enables the theft of minor funds(e.g., unclaimed royalties, yield, etc.), resulting in financial losses for rightful owners.
* **Partial Fee Skimming:** Exploits that allow attackers to skim a moderate but not total portion of transaction fees from users without immediate detection, leading to increased costs for users and reduced revenue for the platform. For example, an attacker could manipulate gas fees for transactions in a decentralized exchange to collect excess fees.
* **Interest Rate Manipulation:** Partial Interest Rate Manipulation: Manipulating interest rates in DeFi applications to partially benefit certain users or exploit arbitrage opportunities, resulting in moderate financial losses for others. For example, an attacker could manipulate interest rates in a lending protocol to attract borrowers and lenders to their advantage.
* **Unfair Airdrop Distribution:** Exploits that allow certain users to receive a disproportionate share of airdropped tokens.
* **Others**: Other operations result in a moderate amount of assets locked or lost (please specify).

#### **Functional**

* **Non-Standard Interface Moderate losses Issues:** Certain types of smart contracts use non-standard interfaces or implementations(e.g. EIP), affecting safe calls or interface compatibility, resulting in moderate losses and operational disruptions.
* **Unintended Alteration of NFT Representations:** Vulnerabilities that result in the unintended alteration of what a non-fungible token (NFT) represents, such as its token URI, payload, or artistic content. For example, a vulnerability in a decentralized marketplace for NFTs could allow an attacker to modify the metadata associated with NFTs, leading to misrepresentation or loss of value for affected tokens.
* **Unbounded Gas Consumption:** Vulnerabilities in smart contracts that allow for unbounded gas consumption, leading to denial-of-service (DoS) attacks or causing the contract to become unusable. This could occur due to recursive function calls, complex looping structures, or other factors that result in excessive gas usage without termination.
* **Smart Contract Funds Depletion:** Smart contracts becoming unable to operate due to a lack of funds, leading to disruptions in service or functionality. For example, a decentralized lending protocol may run out of reserves, preventing users from borrowing or lending assets.
* **Unexpected leakage of data:** Unexpected leakage of non-critical data that will not directly cause moderate harm.
* **Operation Stability Issues:** Issues affecting contract stability, such as high invocation failure rates or resource consumption. For example, such as a contract experiencing frequent transaction failures.
* **Others:** Other flaws of functions can cause a severe system crash and cannot be recovered, resulting in significant losses(please specify).

### **Low Damage**

Low Damage generally refers to the risks and hazards that the vulnerability can have a slight impact on the smart contract, can pose a security threat to the contract business system, and need to be improved. Including but not limited to:

#### **Financial**

* **Minor Fee Miscalculations:** Slight discrepancies in transaction fee calculations that result in minimal financial impact. For example, such as rounding errors causing users to overpay by a negligible amount.
* **Tiny Token/Fund Accumulation:** Accumulation of tiny, negligible amounts of tokens or funds left over from transactions.
* **Incorrect Exchange Rate:** The contract uses an outdated or inaccurate exchange rate for calculations, leading to minor discrepancies in token values.
* **Incorrect Interest Calculation:** The contract calculates interest payments with minor errors, resulting in slightly higher or lower payouts than intended.
* **Dust Theft:** An attacker can exploit the contract to steal small amounts of tokens that are considered "dust" due to their insignificant value.
* **Others**: Other operations result in a tiny amount of assets locked or lost (please specify).

#### **Functional**

* **Minor UI/UX Glitches:** User interface issues that do not affect the underlying smart contract operations.
* **Gas Optimisation:** Small issues with gas optimization that cause minor inefficiencies. For example, functions or variables that consume gas but serve no purpose.
* **Non-Critical Function Deprecation**: Deprecation of non-critical functions, for example, outdated features that are rarely used.
* **Minor Validation Errors**: Small errors in data validation processes, for example, occasional incorrect validation messages.
* **Event Emission Errors:** Emitting events incorrectly or missing events affects monitoring but not core functions.
* **Intermittent Function Failures:** Vulnerabilities causing intermittent failures of smart contract functions. For example, such as a function that occasionally fails under specific conditions.
* **Non-Standard Interfaces**: Certain types of smart contracts use non-standard interfaces or implementations, which affect safe calls or interface compatibility without causing losses.
* **Display Data Mistakes**: Mistakes in how data is displayed to users without affecting the actual data.
* **Transaction Fee Modification:** Modification of transaction fees outside of design parameters.
* **Block Stuffing:** Deliberate actions aimed at disrupting normal network operations by filling blocks with excessive transactions, leading to congestion and increased transaction fees.
* **White Paper/Comment Implementation Errors**: Code logic does not implement the content of the white paper, or code implementation conflicts with the white paper or comment.
* **Attacker forced other users to take action**: The attacker forced other users to take action, but the users did not incur any financial loss.
* **Useless data:** Test or useless data in the contract.
* **Panics:** Improper error handling implementation causes the program to panic.
* **Others:** Other flaws of functions can cause intermittent or minor system failures and severely impact the user experience (please specify).

## **Degree of Exploitability**

### **Low Effort to Exploit**

Low effort to exploit generally means that the cost of exploiting a vulnerability is low, there is no special exploitation threshold, and the vulnerability can be triggered consistently. Including but not limited to:

#### **Cost**

* **0 capital cost:** The Attack requires a small or close to 0 capital cost, such as gas fee, protocol fee, flash loan fee, etc.
* **0 resource cost:** The Attack requires a small or close to 0 resource cost, such as bandwidth, computation, etc.
* **Small amount of asset:** The Attack needs to hold a small amount of a certain asset.
* **Others:** Other operations that qualify for low cost (please specify).

#### **Complexity**

* **Without any attack:** Once the contract is successfully deployed, the vulnerability will occur without any attack.
* **Attack path is straightforward:** The attack path is very straightforward. To be specific, the call flow consists of 1-2 functions.
* **Bypass security checks:** Vulnerabilities that can be exploited without needing to authenticate or bypass any form of security check.
* **Lack of access control:** Permissions or access control mechanisms that are too lenient, allowing unauthorized users to gain access to restricted areas or functionalities.
* **Common Web3 Attack Methods:** The attack methods are very common and have been disclosed many times in past web3 security events, such as flash loan, etc.
* **Other:** Other operations that qualify for low complexity (please specify).

### **Medium Effort to Exploit**

Medium effort to exploit generally means that the vulnerability requires a certain cost, or there are certain exploitation conditions, and the vulnerability is not easily triggered consistently. Including but not limited to:

#### **Cost**

* **Costs lower than profit:** It requires a certain amount of capital cost that is less than the profit of the attack.
* **A certain amount of assets:** It requires the attacker's own account assets or assets in the contract to reach a certain scale.
* **Higher transaction fees:** It requires attackers to use higher transaction fees, such as higher gas for front-running.
* **Others:** Other operations that qualify for moderate costs (please specify).

#### **Complexity**

* **Normal conditions of attacker:** It requires the attacker to meet certain normal conditions, such as collaboration with a miner or block producing node, or the ability to package transactions and produce blocks to rearrange or filter transactions.
* **Normal conditions of victim:** It requires the victim to meet certain normal conditions, such as the asset amount being in a certain range.
* **Common attack methods in non-smart contracts:** It needs to be combined with common attack methods in non-smart contracts, such as attacking off-chain data sources.
* **Attacking other contracts on the chain:** It needs to be combined with known attack methods in smart contracts, such as attacking other Oracle contracts on the chain.
* **A certain time frame:** It needs to be triggered within a certain time frame, such as a specific block height.
* **Transactions to be executed in specific scenarios:** It requires transactions to be executed in specific scenarios, such as specific transactions packaged in Uncle Block.
* **A certain time cost:** It requires a certain time cost, such as several days.
* **A minimal amount of resources:** It requires a minimal amount of network/computing resources.
* **Predictable random number/Hash:** Predictable or manipulable random number or hash generation.
* **The path of attack is a bit complicated:** The path of attack is a bit complicated. To be specific, the call flow consists of 3-6 main functions.
* **Uncommon attack methods :** These attack methods are uncommon and have rarely been disclosed in past web3 security events.
* **Other:** Other operations that qualify for moderate complexity (please specify).

### **High Effort to Exploit**

High effort to exploit generally means that the vulnerability requires a higher cost, or the exploitation conditions are very strict, and the vulnerability is difficult to trigger. Including but not limited to:

#### **Cost**

* **Costs equalling/exceeding the profit:** It requires significant capital expenditure, which may closely equal or exceed the potential profit from the attack.
* **Required** **a** **lot** **of assets:** The attacker's own account or contract needs to hold assets at a scale equivalent to hundreds or more normal users.
* **Others:** Operations that qualify for high cost (please specify).

#### **Complexity**

* **Difficult-to-fulfill conditions of attacker:** The attacker needs to meet certain difficult-to-fulfill conditions, such as obtaining particularly crucial admin-like permissions within the contract.
* **Difficult-to-fulfill conditions of victim:** It requires the victim needs to meet certain difficult-to-fulfill conditions, such as reaching a specific value threshold in assets.
* **Substantial time expenditure:** It requires a significant time investment, such as several months or even longer.
* **Required** **substantial resources:** It requires a substantial amount of resources (e.g. network, computing, etc.)
* **Unpredictable random number/Hash:** Unpredictable random number or hash generation.
* **Unexpected operation:** Attacks that rely on unexpected operations by administrators or users.
* **Low Probability:** Any factor that causes a really low probability of the attack occurring.
* **Others:** Operations that qualify for high complexity (please specify).

## Additional Notes

1. The above criteria may not encompass all potential cases, the final determination of severity will be adjudicated by the Secure3 team on a case-by-case basis.
2. Any issue that is not exploitable within the scope of the contest is defined as speculating on future code. Any such speculation only has the potential to be valid if the root cause is demonstrated to be in the contest scope.
3. When an in-scope contract composes/inherits with an out-of-scope (OOS) contract, and the root cause exists in the OOS contract, the finding is to be treated as OOS. Exceptional scenarios are at the discretion of the Secure3 team.
4. Please note the location of the submitted code. If it is not the link to the repository provided by secure3, it will be considered invalid. The format is as follows:
   1. Example: <https://github.com/Secure3Audit/code_Mantle_V2_Public/blob/c8af0be0bca90dbffe2106afd5830c04ed355029/code/mantle-v2/packages/contracts-bedrock/contracts/L1/L1CrossDomainMessenger.sol#L250-L258>
5. For the **out-of-scope** issue, unless the severity is **high** or **medium** and the client accepts it, it will not be accepted by Secure3.
6. In most cases, we will make the final decision on the issue based on customer feedback.


# Bug Bounty

At Secure3, we recognize that maintaining security is a continuous endeavour. To support projects in fortifying their defences, we provide a robust Bug Bounty solution that enables ongoing identification and remediation of vulnerabilities.

{% hint style="success" %}
[Contact us](https://tally.so/r/mOlevY) if you're interested in launching a bug bounty for your project.
{% endhint %}

### Key Benefits of Our Bug Bounty Program

* **Flexible Reward Options**:&#x20;
  * Projects can issue rewards in your native tokens, aligning incentives with the project's ecosystem and encouraging active participation from security experts.
* **Access to a Skilled Auditor Community**:&#x20;
  * Engage with a diverse community of seasoned auditors and security experts, bringing a wealth of expertise to identify and mitigate vulnerabilities.
* **Continuous Improvement**:&#x20;
  * Our ongoing assessments enable prompt detection of new vulnerabilities, ensuring your project remains adaptable to evolving security challenges.

### Special Offer for Audit Contest Sponsors

For projects that sponsor a Secure3 Audit Contest, we are excited to provide a **FREE Bug Bounty** as an added benefit. This initiative includes all the general advantages listed above, along with:

* **Zero Take Rate**: Enjoy a **0% take rate** by Secure3, allowing you to maximize your budget and ensure all rewards go directly to the auditors.
* **Continuous Access**: Gain free access to our community of auditors, ensuring ongoing support and expertise in identifying and addressing potential vulnerabilities.


# Brand Kit

### **Brand Introduction**

#### About Secure3

Secure3 is an innovative platform revolutionizing the security landscape of Web3 through its decentralized approach to Web3 project auditing. Headquartered in Silicon Valley, Secure3 organizes audit contests that engage a diverse community of globally certified auditors, through the smart matching mechanism and incentive model, ensuring more effective, affordable, and high-quality auditing services for blockchain projects. Secure3's collaborative approach aims to enhance the security of the Web3 ecosystem by bringing together projects and auditors to work as a community.

Backed by Mirana Capital, HashKey Capital, Web3.com Ventures and more angel investors, Secure3 is poised to reshape the future of Web3 security by fostering a collaborative environment for auditors and projects. With its innovative contest model, commitment to transparency, and focus on community engagement, our mission is to build an efficient, reliable, and transparent Web3 security ecosystem.

### Brand Logos

Download here: <https://secure3-public-docs.s3.us-west-2.amazonaws.com/uploads/453/secure3_brand_kit.zip>


