# Cyfrin Docs > The complete platform for Web3 security researchers, developers, and learners. From competitive audits (CodeHawks) to professional certifications (Updraft), vulnerability research (Solodit), and unified identity (Cyfrin Profiles). --- ## Welcome ### Welcome to Cyfrin *Welcome to the Cyfrin ecosystem - Security audits, Web3 education, and vulnerability research* Powering the future of smart contract security # Cyfrin is: The complete platform for Web3 security researchers, developers, and learners. From competitive audits to professional certifications, Cyfrin powers the future of smart contract security. - [CodeHawks](/codehawks/overview): **Competitive Security Audits** Compete to find vulnerabilities in smart contracts. Earn rewards, build your reputation, and protect Web3. - [Updraft](/updraft/overview): **Web3 Education Platform** Learn smart contract development and security. Get certified and advance your career in blockchain. - [Solodit](/solodit/overview): **Vulnerability Research** Navigate 20,000+ security findings. Research, learn, and contribute to the community knowledge base. - [Aderyn](https://aderyn.cyfrin.io): **Static Analysis Tool** Lightning-fast Solidity static analyzer. Find vulnerabilities and build custom detectors for your codebase. - [Battlechain](https://docs.battlechain.com): **Security-First Blockchain** Coming soon - Revolutionary blockchain infrastructure for decentralized security and audit coordination. - [Cyfrin Profiles](/profiles/overview): **Unified Accounts** One profile across the entire ecosystem. Manage your settings, wallets, and credentials in one place. ## Quick Start **Create Your Profile** Sign up for a free Cyfrin account to access all platforms [Create account →](https://profiles.cyfrin.io) **Choose Your Path** - **Security Researcher?** Join CodeHawks competitions - **Learning Web3?** Start with Updraft courses - **Researching vulnerabilities?** Explore Solodit **Join the Community** Connect with 10,000+ developers and security researchers on Discord [Join Discord →](https://discord.gg/cyfrin) ## Popular Documentation - [Join a Competition](/codehawks/join-a-codehawks-contest): Start competing in CodeHawks - [Submit Findings](/codehawks/submit-a-finding): Learn how to report vulnerabilities - [Get Certified](/updraft/how-to-purchase-a-cyfrin-certification): Earn a professional certification - [First Flights](/codehawks/what-is-a-codehawks-first-flight): Beginner-friendly competitions - [Search Vulnerabilities](/solodit/search-for-a-finding): Explore the vulnerability database - [2FA Setup](/profiles/add-two-factors-authentication-2fa): Secure your account --- ## The Cyfrin Ecosystem CodeHawks revolutionizes smart contract security through competitive auditing. Security researchers compete to find vulnerabilities, earning rewards while protecting Web3 protocols. **Features:** - Competitive audit contests with prize pools - First Flights for beginners - Cyfrin Eagles elite program - Private audits for protocols - Transparent judging and appeals process [Explore CodeHawks →](/codehawks/overview) Learn smart contract development and security from industry experts. From beginner to advanced, Updraft offers comprehensive courses and professional certifications. **Features:** - Interactive video courses - Hands-on coding challenges - Professional certifications - Study guides and exam prep - Industry-recognized credentials [Start Learning →](/updraft/overview) The ultimate database of smart contract vulnerabilities. Search, filter, and learn from 20,000+ audit findings across multiple platforms. **Features:** - Advanced search and filtering - Aggregated leaderboards - Bug bounty aggregator - Personal note-taking - Community-driven ratings [Browse Solodit →](/solodit/overview) Lightning-fast Rust-based Solidity static analyzer. Find vulnerabilities in your smart contracts and build custom detectors tailored to your needs. **Features:** - Static vulnerability detection - Custom detector framework - CLI with millisecond execution - VS Code extension integration - CI/CD pipeline support [Explore Aderyn →](https://aderyn.cyfrin.io) Your single account across the entire Cyfrin ecosystem. Manage your profile, connect wallets, track achievements, and customize your experience. **Features:** - Single sign-on across all platforms - Wallet integration - Two-factor authentication - Third-party platform connections - Customizable settings [Manage Profile →](/profiles/overview) --- - [Need Help?](https://discord.gg/cyfrin): Join our Discord community for support, discussions, and updates. **10,000+ developers and security researchers are waiting to help.** > **Note:** These docs are open source. Found an issue? [Contribute on GitHub > →](https://github.com/Cyfrin/docs-main) --- ## Profiles ### Cyfrin Profiles *Unified cross-platform accounts for the Cyfrin ecosystem* ## Welcome to Cyfrin Profiles Cyfrin Profiles are your unified identity across the entire Cyfrin ecosystem. One account, seamless access to CodeHawks, Updraft, Solodit, and more. - [What is a Cyfrin Profile?](/profiles/what-is-a-cyfrin-profile): Learn about unified cross-platform accounts - [Create Your Profile](/profiles/create-a-cyfrin-profile): Get started in minutes - [Security Settings](/profiles/add-two-factors-authentication-2fa): Protect your account with 2FA - [Manage Wallets](/profiles/managing-wallet-and-payment-wallet): Connect and manage your crypto wallets ## Quick Links - [Profile Settings](/profiles/adjust-your-profile-settings): Configure your preferences - [Password & Login](/profiles/change-your-password): Update your credentials - [Connect Platforms](/profiles/connect-third-party-platforms): Link GitHub and more ### What is a Cyfrin Profile? ## Overview "Cyfrin Profiles are integrated, cross-platform accounts that combine individual Updraft, CodeHawks, and Solodit logins" into a unified experience. These profiles establish a personal space where users can engage across multiple Cyfrin platforms. ## Key Features The platform offers three main benefits: 1. **Unified Ecosystem** – Cyfrin Profiles connect the three primary platforms, enabling smooth navigation between them. 2. **Single Sign-On** – Users enjoy "one login for all Cyfrin products, enabling new users easy access to the Cyfrin ecosystem." 3. **Customized Account Space** – Users can display their accomplishments and development across Cyfrin's offerings in one location, making it suitable for sharing credentials with colleagues and recruiters. --- ## Related Resources - [Deactivating or Deleting Your Account](/profiles/deactivating-or-deleting-your-account) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [How to Download the Cyfrin Updraft Study Guide](/updraft/how-to-download-the-cyfrin-updraft-study-guide) - [What are Cyfrin Eagles?](/codehawks/what-are-cyfrin-eagles) - [What is a Cyfrin Updraft Certificate of Completion?](/updraft/what-is-a-cyfrin-updraft-certificate-of-completion) ### Create a Cyfrin Profile ## Overview "You must be at least 13 years old to create a Cyfrin Profile." ## Account Creation Steps To establish a Cyfrin account, follow these five steps: 1. Navigate to **profiles.cyfrin.io** 2. Provide your email address or select an authentication method you prefer 3. For email-based registration, confirm your email address 4. Wallet users will receive prompts for connection and optional email verification 5. Configure your name and username settings ## Troubleshooting Login Issues **Password Problems:** Access the password reset feature if you've forgotten your credentials. **Provider Mismatch Error:** This message indicates you're using a different login method than your original signup. Ensure consistency with your initial authentication choice. **Ongoing Problems:** Contact support through their Discord community for additional assistance. ## Email Confirmation Tips Check spam and social folders if your confirmation message doesn't appear. Verify you entered the correct email address; you can update it and resend the confirmation link through profile settings. ## Password Security Guidelines Strong passwords should: - Balance memorability with complexity - Differ from passwords on other accounts - Exceed typical length recommendations - Avoid personal information like birthdates - Skip common dictionary words - Utilize a password manager for storage If the system rejects your password, incorporate uppercase and lowercase letters, or extend the length using memorable phrases. ### Add and Edit Your Profile Info ## Basic Profile Information Cyfrin Profiles contain essential user details including username, name, bio, and social accounts. All profile information can be updated at any time, provided it complies with Cyfrin's Terms and Conditions. These profiles integrate across Cyfrin's ecosystem, connecting users to Updraft, CodeHawks, Solodit, and other platforms. ## How to Change Your Cyfrin Username and Name Follow these steps to modify your handle and display name: 1. Verify your new name adheres to Cyfrin's naming guidelines 2. Click your profile picture in the top-right corner of the dashboard 3. Select **Edit Profile** 4. Update your username or name 5. Click **Save Changes** to apply **Note:** "Usernames can be changed every 60 days." Contact support via Discord if problems occur. ## Add or Edit Your Bio To create a bio reflecting your expertise and interests: 1. Navigate to **Edit Profile** in account settings 2. Locate the **Bio** section and add text (maximum 150 characters) 3. Click **Save Changes** **Tip:** Emphasize distinctive skills or interests to enhance profile visibility. ## Managing Social Accounts Add social media links through these steps: 1. Go to your profile edit page (https://profiles-dev.devcyfrin.com/u/your-username/edit) 2. Scroll to **Social Accounts** 3. Add or update links and select **Save Changes** Supported platforms include Twitter and LinkedIn. ## Adding Company and Job Title Display professional information by: 1. Accessing **Edit Profile** 2. Scrolling to **Company & Job Title** section 3. Entering relevant details and clicking **Save Changes** ## What to Do If Your Handle Is Rejected Handles must meet Cyfrin guidelines. If rejected: - Attempt resubmission with an adjusted name - Contact support through Discord if you believe the rejection was an error ### Your Profile Picture and Cover Photo ## Add or change your Cyfrin profile picture 1. Click your profile picture in the top right of Cyfrin, then click your profile name. 2. Click Edit profile 3. Click on your profile picture 4. Upload and resize your new profile picture 5. Click on the "save changes" button **Note:** "Your profile picture should be at least 320 pixels wide and 320 pixels tall for best quality." ## Add or change your cover photo A cover photo is the larger image displayed at the top of your profile, positioned above your profile picture. Like your profile picture, cover photos are public, meaning anyone visiting your profile can see them. 1. Click your profile picture in the top right of Cyfrin, then click your profile name. 2. Click Edit profile 3. Click on your cover photo 4. Upload and resize your new cover photo 5. Click save changes **Note:** "For best quality, your cover image should be at least 1500x500 pixels." ## Troubleshooting: Can't change your profile picture or cover? If you're having trouble changing your profile picture, try these steps: - Check if you're connected to a reliable data or Wi-Fi network. - Delete your cache and cookies and login again - Refresh the page and try again. ## Related Articles - [How to share your Cyfrin certification](/updraft/how-to-share-your-cyfrin-certification) - [Change your password](/profiles/change-your-password) - [Add and Edit Your Profile Info](/profiles/add-and-edit-your-profile-info) - [Add Two-factors Authentication (2FA)](/profiles/add-two-factors-authentication-2fa) - [Managing Wallet and Payment Wallet](/profiles/managing-wallet-and-payment-wallet) ### Change Your Password ## Overview Users can modify their Cyfrin Profile password through account settings. A verified email address is required to complete this process. ## Steps for Logged-In Users If already logged in, follow these steps: 1. Select the dropdown menu in the top-right navigation area 2. Choose **Settings** 3. Click **Security** in the left sidebar 4. Enter your account's email address 5. Click **Change** 6. Check your email for a password reset link 7. Complete the password update on the provided page ## Password Reset Without Login Users who aren't logged in should click **Forgot Password?** on the login screen and follow the prompts provided. Email access to the associated account is necessary. ## Creating a Strong Password When setting a new password, consider these recommendations: - Balance memorability with difficulty for others to guess - Use a unique password—avoid reusing credentials from email, banking, or other accounts - Longer passwords offer better security - Never use personal identifiers like your email, phone number, or birthdate - Avoid common terms such as "Password" - Consider using a dedicated password manager application - Never share passwords with anyone; change them immediately if compromised If the system indicates insufficient password strength, try combining uppercase and lowercase letters or extending the length using a memorable phrase. ## Additional Security The platform supports two-factor authentication for enhanced account protection. ### Fix a Login Problem ## If you can access the email address or mobile phone number you use to log in "If you can still get emails and text messages from us, try following the steps to reset your password." If you aren't receiving verification codes: - Verify the code hasn't landed in spam or junk folders - Ensure you have an active signal to receive the code - Wait several minutes before requesting another code ## Didn't receive a password reset email When a password reset email doesn't arrive: - Check spam and junk mail folders in all email accounts connected to your Cyfrin profile - "Try to reset your password again" ## Can't access recovery email "If you can't reset your password because you can't access the email on your account, contact support" through the Discord community link provided. --- ## Related Articles - [Create a Cyfrin Profile](/profiles/create-a-cyfrin-profile) - [Change your password](/profiles/change-your-password) - [Add Two-factors Authentication (2FA)](/profiles/add-two-factors-authentication-2fa) - [Fix a problem playing videos](/updraft/fix-a-problem-playing-videos) - [How to redeem the SSCD+ certification code (RocketPool)](/updraft/how-to-redeem-the-sscd-certification-code-rocketpool) ### Add Two-Factor Authentication (2FA) ## Overview "Enhance your Cyfrin account security by enabling Two-Factor Authentication (2FA)." This security feature mandates an extra verification step beyond your password when signing in. ## Setting Up 2FA ### Access 2FA Settings Follow these steps to configure 2FA on your account: 1. Click your profile picture in the top-right corner of the Cyfrin dashboard 2. Select "Settings" 3. Navigate to security settings using the sidebar on the right 4. In the Two-Factor Authentication section, click "Enable 2FA" 5. Scan the QR code with your preferred authenticator app 6. Enter the code generated by the authenticator ## Using 2FA After completing setup, "you'll need to enter a code when logging in." You can receive this code via SMS or from your authenticator app. You'll also need it for secure actions, such as modifying settings or accessing sensitive information. ## Troubleshooting & Support If you've lost access, don't worry. Reach out to the Cyfrin Support Team via Discord for assistance with recovery. --- ## Related Articles - [Create a Cyfrin Profile](/profiles/create-a-cyfrin-profile) - [Change your password](/profiles/change-your-password) - [Submit a First Flight](/codehawks/submit-a-first-flight) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [Adjust Your Profile Settings](/profiles/adjust-your-profile-settings) ### Adjust Your Profile Settings ## Overview This article explains how to access and manage your Cyfrin profile settings across multiple configuration categories. ## To Find Your Settings Follow these steps to locate your settings: 1. "Click the drop down menu on top right of the navigation bar" 2. "Select **Settings**" 3. "Click on the settings category you'd like to update from the options in the left sidebar" ## To Manage Your Settings The platform offers four main setting categories: - **General**: "Link and verify your email, wallet and third party accounts such as GitHub" - **Security**: "Change your profile password, link two-factor authentication and manage devices/browsers currently connected to your account" - **Appearance**: "Set your Light/Dark Mode UI preferences" - **Beta**: "Sign up to be the first to experience new and experimental features coming to the Cyfrin Ecosystem" ## Related Articles The help center provides additional resources covering: - [Add and Edit Your Profile Info](/profiles/add-and-edit-your-profile-info) - [What is a Cyfrin Profile?](/profiles/what-is-a-cyfrin-profile) - [Opt-in to beta updates](/profiles/opt-in-to-beta-updates) - [Managing Wallet and Payment Wallet](/profiles/managing-wallet-and-payment-wallet) - [Change the platforms appearance](/profiles/change-the-platforms-appearance) --- *Last updated over 2 months ago* ### Connect Third-Party Platforms ## Overview "Cyfrin Profiles allow a user to connect third-party platforms and applications to expand on features and accessibility." Currently, only GitHub integration is available, with plans for additional platforms in the future. ## How To Connect a Third-Party Platform The process for linking external services to your Cyfrin Profile is straightforward: 1. Click the dropdown menu in the top right of the navigation bar 2. Select **Settings** 3. Under the **General** category, locate **Connect** next to your desired platform 4. Complete the on-screen authentication steps to finalize the connection ## Related Articles - [How to share your Cyfrin certification](/updraft/how-to-share-your-cyfrin-certification) - [Add and Edit Your Profile Info](/profiles/add-and-edit-your-profile-info) - [What is a Cyfrin profile?](/profiles/what-is-a-cyfrin-profile) - [Adjust Your Profile Settings](/profiles/adjust-your-profile-settings) - [Managing Wallet and Payment Wallet](/profiles/managing-wallet-and-payment-wallet) --- **Last Updated:** Over a year ago ### Managing Wallet and Payment Wallet ## Overview Cyfrin Profiles supports two distinct wallet types to streamline user experience: - **Primary Wallet**: "Used for account creation and login." - **Payment Wallet**: "Receives rewards from CodeHawks." ## Changing Your Primary Wallet To update your primary wallet, follow these steps: 1. Click your profile picture in the top-right corner of the Cyfrin navbar 2. Select **Settings** 3. Choose **Connect Your Wallet** and follow the prompts **Note**: "Multi-signature wallets aren't currently supported." ## Updating Your Payment Wallet The payment wallet must be compatible with ZKsync: 1. Click your profile picture in the top-right corner of the Cyfrin navbar 2. Insert the address of a ZKsync-compatible wallet ## Disconnecting Wallets ### To Disconnect the Primary Wallet 1. Click your profile picture in the top-right corner of the Cyfrin navbar 2. Select **Settings** 3. Find the Wallet address field and click the Disconnect button **Important**: "Before disconnecting your primary wallet, you must have linked" an email or Google account to your profile. ### To Remove the Payment Wallet 1. Go to **Settings** and choose **Disconnect** under the Payment Wallet section If you encounter any issues, contact Cyfrin support. ## Troubleshooting & Support "Lost access to your wallet? Don't worry—reach out to the Cyfrin Support Team" via their Discord community for assistance. ### Change the platforms appearance ## Overview The Cyfrin platform offers two methods to adjust Light/Dark mode settings for customizing your interface appearance. ## Method 1: Drop Down Menu Access the theme toggle quickly through the navigation bar: 1. "Click on the drop down menu in the top right of the navigation bar" 2. "Select the Light/Dark mode toggle to configure your preferred UI" ## Method 2: Settings Page For more detailed configuration options: 1. "Click on the drop down menu in the top right of the navigation bar" 2. Select **Settings** 3. Choose **Appearance** from the left navigation panel 4. Configure your preferred mode or enable system-based appearance settings This second approach allows users to have their interface automatically match their device's system configuration, providing additional flexibility beyond manual selection. --- **Last Updated:** Over a year ago **Related Articles:** - [Change your password](/profiles/change-your-password) - [Deactivating or Deleting Your Account](/profiles/deactivating-or-deleting-your-account) - [Connect Third-Party Platforms](/profiles/connect-third-party-platforms) - [Adjust Your Profile Settings](/profiles/adjust-your-profile-settings) - [Opt-in to beta updates](/profiles/opt-in-to-beta-updates) ### Opt-in to beta updates ## Overview Users who want early access to experimental features can participate in Cyfrin's beta program. This provides the opportunity to "test the latest features and upgrades coming to the Cyfrin Ecosystem." ## How to Enable Beta Access Follow these four steps: 1. Access the dropdown menu in the top-right corner of the navigation bar 2. Select **Settings** 3. Navigate to **Beta** in the left sidebar 4. Enable the **Join Beta** toggle to participate in experimental deployments ## Providing Feedback Users are encouraged to share their experiences with beta features. The platform includes a **Give us Feedback** button located in the lower right corner of any Cyfrin Ecosystem page for submitting comments and suggestions. --- ## Related Resources - [Add Two-factors Authentication (2FA)](/profiles/add-two-factors-authentication-2fa) - [Connect Third-Party Platforms](/profiles/connect-third-party-platforms) - [Managing Your Notes](/solodit/managing-your-notes) - [Adjust Your Profile Settings](/profiles/adjust-your-profile-settings) - [Change the platforms appearance](/profiles/change-the-platforms-appearance) ### Deactivating or Deleting Your Account ## What Happens When You Permanently Delete Your Cyfrin Profile? Permanent deletion carries significant consequences: - "You won't be able to reactivate your profile" - All associated data disappears permanently, including profile information, rewards, builder score, and course completions - Access to Cyfrin Updraft, CodeHawks, and Solodit becomes unavailable - "Some information, like findings, reports, and rewards, may still be visible to other users after you delete your account" ## How to Delete Your Cyfrin Profile Follow these steps from your Profile Settings: 1. Click the dropdown menu in the top right navigation 2. Select **Settings** 3. Locate the **Danger Zone** within the **General** category 4. Click the **Delete Account** button 5. Enter your username in the modal window 6. Confirm deletion by clicking **Delete** **Important:** "This profile _will not_ be recoverable." ## Can You Cancel Account Deletion? No. Once confirmed, deletion cannot be reversed. Users would need to create an entirely new profile to regain access. ## Deleting Your Data Cyfrin allows users to delete all stored personal data in compliance with regional regulations. To remove your data: 1. Open the dropdown in the top right navigation 2. Select **Settings** 3. Find **Danger Zone** in the **General** section 4. Click **Delete all my data** 5. Enter your username and confirm via the modal --- ## CodeHawks ### CodeHawks *Competitive security audits and first flights* ## Competitive Security Audits CodeHawks is Cyfrin's competitive audit platform where security researchers compete to find vulnerabilities in smart contracts and earn rewards. - [What is CodeHawks?](/codehawks/what-is-a-competitive-audit): Learn about competitive audits - [Join a Contest](/codehawks/join-a-codehawks-contest): Start competing today - [Submit Findings](/codehawks/submit-a-finding): Report vulnerabilities - [Cyfrin Eagles](/codehawks/what-are-cyfrin-eagles): Join the elite program ## Get Started **Join a Competition** Browse active competitions and join one that interests you **Hunt for Vulnerabilities** Analyze the codebase and identify security issues **Submit Your Findings** Write detailed reports with proof of concept **Earn Rewards** Get paid for valid, high-quality findings ## First Flights New to security auditing? Start with [First Flights](/codehawks/what-is-a-codehawks-first-flight) - beginner-friendly competitions designed to help you learn. - [What is a First Flight?](/codehawks/what-is-a-codehawks-first-flight): Learn about our beginner-friendly competitions ### What are Cyfrin Eagles? ## Overview Cyfrin Eagles represents an exclusive initiative that identifies and nurtures top-tier security researchers within the Cyfrin ecosystem. These "Eagles" are high-performing auditors who assume leadership positions in CodeHawks contests and gain priority access to Cyfrin's private audit opportunities. The program cultivates a specialized security community dedicated to comprehensive protection of blockchain and smart contract systems. ## Key Characteristics **Leadership in Audits** Eagles function as lead auditors for numerous CodeHawks competitions, leveraging their proven expertise. **Monetary Incentives** These professionals receive premium compensation packages called "Eagle Rewards," structured as either guaranteed payments or performance-based compensation depending on contest magnitude. **Professional Growth** Members enjoy exclusive opportunities to engage with private audits and receive recognition as primary contributors in Cyfrin's audit documentation. **Community & Independence** While Eagles benefit from prioritized access to contests and audits, they maintain freedom to collaborate with other platforms and operate without exclusivity constraints. ## Program Objectives The initiative aims to: - Retain elite audit talent within Cyfrin's community - Recognize exceptional performance through visibility and special incentives - Ensure competitions and private audits benefit from experienced, specialized professionals - Foster long-term professional development partnerships for committed auditors ## Related Resources - [What is a Cyfrin profile?](/profiles/what-is-a-cyfrin-profile) - [What is a competitive audit](/codehawks/what-is-a-competitive-audit) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [Eagle Payments](/codehawks/eagle-payments) - [How to Become an Eagle](/codehawks/how-to-become-an-eagle) ### How to Become an Eagle ## Eligibility & Selection The Eagle program recognizes top performers in Web3 Security. Selection focuses on high-achieving CodeHawks auditors evaluated over 1/3/6/12-month timeframes. "Eligibility for the program emphasizes consistent excellence, a strong track record of findings, and deep technical expertise." --- ## Ongoing Admission The Cyfrin Audit Team Leader may admit members demonstrating exceptional performance or specialized skills, allowing the program to evolve with industry needs. "Consistently ranking in the top 20 on CodeHawks leaderboards" represents a notable benchmark, though innovative security approaches and significant contributions also merit consideration. --- ## Exclusivity and Status Eagle membership isn't restricted to CodeHawks alone—members may contribute across multiple platforms and communities. **Important:** Continued excellence is required. "Eagles who fail to meet performance expectations may lose their status, particularly by consistently falling outside the top 20 rankings." --- ## Related Articles - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [What are Cyfrin Eagles?](/codehawks/what-are-cyfrin-eagles) - [Eagle Payments](/codehawks/eagle-payments) - [Payout Scenarios](/codehawks/payout-scenarios) - [AI First Flights](/codehawks/ai-first-flights) ### Eagle Payments ## Overview Eagles participating in CodeHawks contests receive distinct compensation separate from standard prize distributions. The "Eagle Reward" system aims to recognize their specialized expertise and leadership contributions to security audits. ## Eagle Reward Structure ### 1. Lead Eagle Guaranteed Reward - **Payout**: 7.5% of the prize pool for major contests; 10% for smaller ones - **Timing**: Paid at the audit's start - **Purpose**: Ensures baseline compensation for time and leadership responsibilities ### 2. Eagle Pool Reward - **Eligibility**: Only available when the prize pool equals or exceeds $40,000 - **Allocation**: 7.5% of the total prize pool - **Distribution**: Awarded to the highest-ranked Eagle meeting leaderboard criteria: - Top 5 for contests with ≤100 competitors - Top 5% for contests with >100 competitors - **Contingencies**: If no Eagle qualifies, funds roll into the primary prize tier. Multiple equally-ranked qualifying Eagles split the reward equally. ### 3. Capped vs. Uncapped Rewards - Typically uncapped, though very large contests (e.g., $1M+ pools) may have caps applied ## Key Restrictions - Eagle rewards do not contribute toward standard CodeHawks leaderboard rankings - Eagles cannot serve as Paid Judges in contests they lead or participate in, maintaining judging integrity **Related resources**: [How Payouts Work](/codehawks/how-payouts-work) | [What are Cyfrin Eagles?](/codehawks/what-are-cyfrin-eagles) ### Payout Scenarios ## Overview This article outlines how Eagle Rewards are distributed across CodeHawks contests using two primary scenarios based on prize pool size. ## Scenario A: Prize Pool < $40,000 **Example:** A $30K contest **Payout Structure:** - Lead Eagle receives 10% guaranteed reward ($3K) - No additional Eagle Pool Reward applies **Distribution Timeline:** 1. Lead Eagle receives $3K at audit start 2. Remaining $27K distributed among standard high/medium/low prize tiers at contest conclusion ## Scenario B: Prize Pool ≥ $40,000 **Example:** A $100K contest **Payout Structure:** - Lead Eagle Guaranteed Reward: 7.5% ($7.5K) - Eagle Pool Reward: 7.5% ($7.5K) - General Prize Pool: $85K **Timeline:** 1. Lead Eagle paid guaranteed reward ($7.5K) at audit start 2. After contest results announced: "The Eagle Pool Reward ($7.5K) is awarded to the best-performing Eagle" (top 5 rank or top 5% if >100 competitors) 3. If no Eagle qualifies, the $7.5K adds to the highest general prize tier **Possible Outcomes:** - Lead Eagle wins pool reward if highest-ranking - Another Eagle receives reward if outperforming lead - Tied Eagles split reward equally - Unqualified Eagles: $7.5K increases top tier to $92.5K --- **Related Resources:** [Join a CodeHawks contest](/codehawks/join-a-codehawks-contest) | [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) | [How Payouts Work](/codehawks/how-payouts-work) | [What are Cyfrin Eagles?](/codehawks/what-are-cyfrin-eagles) | [Eagle Payments](/codehawks/eagle-payments) ### What is a Competitive Audit ## Overview A smart contract security auditing competition represents a crowdsourced approach where specialized security researchers (called Hawks) examine codebases to identify vulnerabilities, inefficiencies, and potential issues. Participants submit their discoveries and receive compensation based on "validity, quality, and severity" of their findings. The platform encourages participation by noting: "Don't want to miss any of our competition announcements? Make sure to follow us on Twitter and join our Discord server!" ## Seven-Phase Competition Structure ### 1. **Competition Announcement** The initial phase introduces the upcoming audit, detailing which smart contracts will be reviewed. Newcomers can reference the quick start guide for submission procedures. ### 2. **Kick-Off** (48 hours) The official launch period begins, during which participants access the contract repository and commence vulnerability hunting. Submissions are processed through the web portal's contest page. Auditors may also raise concerns about code, scope, or contest specifics during this window. ### 3. **Auditing** Security professionals conduct in-depth analysis to uncover bugs and recommendations. This time-bound phase ensures competitive fairness, with duration primarily determined by codebase size. ### 4. **Judging** The Cyfrin team or appointed judges review submissions, validate findings, rank by severity, and prepare for appeals. ### 5. **Appeals** (48 hours) Participants can challenge judging decisions, promoting transparency and fairness. ### 6. **Rewards** Final results are announced with compensation distributed based on finding quality and significance. "Payouts are distributed within 72 hours of the escalation period's closure and are currently paid in USDC on ZKsync." ### Join a CodeHawks Contest ## Quick Start Welcome to Cyfrin CodeHawks! Here's a comprehensive guide to getting started as an auditor and submitting your initial vulnerabilities. ### 1. Create an Account on CodeHawks Begin by visiting [codehawks.cyfrin.io](https://codehawks.cyfrin.io) and selecting the "sign up" button located in the top right corner. ### 2. Subscribe to Your First CodeHawks Competition Navigate to the competitions page and search for contests marked as "Live" or "Upcoming." **Stay Informed About Competitions:** Make sure to follow the team on [Twitter](https://twitter.com/CyfrinAudits?s=20) and join their [Discord](https://discord.gg/cyfrin) server to receive timely announcements. When you click on a competition, you'll access its details page containing: - Prize pool severity breakdowns - Start and end dates - nSLOC and scope information - Scoring methodology - GitHub repository link (for active competitions) Each contest includes documentation covering the codebase, scope, compatibility details, and setup instructions. New competitions launch nearly every week. Once you find a suitable opportunity, click the subscribe button to participate. ### 3. Submit Your First Finding After identifying a vulnerability, visit the competition page and click the "submit a vulnerability" button. Required submission details: - **Title:** A descriptive heading under 250 characters - **Severity:** Rate using a likelihood and impact matrix; consult "[How to Evaluate a Finding Severity](https://intercom.help/cyfrin/en/articles/10059195-findings-severity)" for guidance - **Description:** A thorough explanation of the vulnerability and reproduction steps ### 4. Await Judging Results After the auditing period concludes, "judges evaluate each submission carefully to determine its validity, severity, and overall quality." Progress updates will appear on the platform and via [Discord](https://discord.gg/cyfrin) announcements. Learn more about "[the judging process](https://intercom.help/cyfrin/en/articles/10059206-judging-process)." ### 5. Appeal Judging Results For 48 hours post-judging, "[appeals](https://intercom.help/cyfrin/en/articles/10060153-what-are-appeals) will be accepted to contest judgments." GitHub submissions enable commenting during this window for escalation requests. ### 6. Get Rewarded Upon final report release, results get announced and "[payouts](https://intercom.help/cyfrin/en/articles/10064018-how-payouts-work) will be sent to the winners." Rewards distribute as USDC via the ZKsync chain. A connected ZKsync wallet in your profile is required to receive payments. --- ## Related Articles - [What is a competitive audit](/codehawks/what-is-a-competitive-audit) - [Findings validity](/codehawks/findings-validity) - [Judging process](/codehawks/judging-process) - [What are Appeals?](/codehawks/what-are-appeals) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) ### Kick-off period ## Overview The kick-off period represents "a 48-hour window" designed to orient participants with the contest framework, clarify the codebase specifications, and address initial questions before the main competition begins. ## Key Events ### Contest Commencement Announcements An official notification marks the start of the kick-off window, providing essential information about upcoming activities during this phase. ### Kick-Off Live Stream (Optional) Participants receive "a thorough walkthrough of the codebase" and can engage directly with sponsors and team members. The organizers encourage attendance, as it offers valuable insights to resolve uncertainties before diving into the audit work. ### Clarification & Feedback Window Throughout the entire 48-hour period, participants may: - Request clarifications regarding contest specifications - Discuss and propose feedback about potential inconsistencies in the specification documentation "By the end of the Kick-Off period, the contest spec will be finalized based on the discussions and feedback." ## Critical Points - **Specification Finalization**: "After the 48-hour Kick-Off period, no changes to the contest spec will be accepted." Participants should voice concerns during this window. - **Competition Decisions**: All judgments and determinations will rely upon the finalized specification, so familiarity with the final version is essential for strategy alignment. ## Related Resources - [What is a competitive audit](/codehawks/what-is-a-competitive-audit) - [Join a CodeHawks contest](/codehawks/join-a-codehawks-contest) - [Findings validity](/codehawks/findings-validity) - [Judging process](/codehawks/judging-process) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) ### Private Competition ## Overview **Private Competitions** on CodeHawks operate similarly to public competitions, with key distinctions regarding vulnerability visibility and appeals processes. ## Submission Visibility In private competitions, access to findings is restricted to your own submissions. Participants cannot view, comment on, or appeal other competitors' submissions. Additionally, "preliminary and final reports may or may not be made available, pending the discretion of the competition sponsors." ## Appeals The limited visibility of submissions means that appeals are confined to your own submissions only. --- ## Related Articles - [What is a competitive audit](/codehawks/what-is-a-competitive-audit) - [Judging process](/codehawks/judging-process) - [View Private Competitions Findings](/codehawks/view-private-competitions-findings) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [Appeals eligibility criteria](/codehawks/appeals-eligibility-criteria) ### View Competition Results ## Overview To access closed competition results, navigate to the contest details page on CodeHawks. The article guides users through a two-step process to find leaderboards and reports. ## Steps to View Results **Step 1: Navigate to Contest Details** Start by going to the contest details page on CodeHawks where you'll see a list of competitions with their statuses and end times. **Step 2: Access Results Page** The contest details page contains "two links which will bring you to the results page." Either link works to proceed. ## Results Page Features Once on the results page, users encounter two tabs: - **Leaderboard Tab** (Default): Displays participant rankings by default - **Report Tab**: Shows "the final report of the contest, summarizing the identified, valid submissions contributed" From the Report tab, you can download a Markdown version of the competition report. ## Related Resources - [Submit a finding](/codehawks/submit-a-finding) - [View Private Competitions Findings](/codehawks/view-private-competitions-findings) - [Aggregated Leaderboard](/solodit/aggregated-leaderboard) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [What are Cyfrin Eagles?](/codehawks/what-are-cyfrin-eagles) --- **Last Updated:** Over a year ago ### What is a Finding ## Main Content A **Finding** represents any identified vulnerability discovered within an audited smart contract protocol in the CodeHawks context. The term **"Finding"** is interchangeable with **"Submission."** ### Validity and Severity Findings undergo evaluation and receive classifications as either **Valid** or **Invalid**. For detailed guidance on submission validity, consult the [Finding Validity](https://intercom.help/cyfrin/en/articles/10059196-findings-validity) resource. Each finding or submission receives a severity rating based on its potential impact to the protocol. Reference [Finding Severity](https://intercom.help/cyfrin/en/articles/10059195-findings-severity) for severity determination details. ### Submission and Learning Resources For submission instructions, see [Submit a Finding](https://intercom.help/cyfrin/en/articles/10059191-submit-a-finding). To develop vulnerability identification skills, the [Security Course](https://updraft.cyfrin.io/courses/security) on Updraft offers comprehensive training. ## Related Articles - [Join a CodeHawks contest](/codehawks/join-a-codehawks-contest) - [Findings severity](/codehawks/findings-severity) - [Findings validity](/codehawks/findings-validity) - [Judging process](/codehawks/judging-process) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) ### Submit a Finding ## Overview To submit a finding on CodeHawks, users should navigate to an active contest's details page (either Competitive Audit or First Flight format). ## Submission Methods **Primary Method:** At the top of the contest details page, locate a "bright orange button to 'Submit a Vulnerability'" and click it to access the finding submission form. **Alternative Method:** Users can navigate to the submissions section at the bottom of the contest page. If no prior submissions exist, there's a link stating "Click here to submit your first vulnerability" which routes to the submission form. ## Finding Submission Form The submission interface offers two distinct options: - **Individual submissions** — attributed to a single person - **Team submissions** — attributed to a team Users toggle between these modes at the top of the form to change submission attribution. **Final Step:** Complete the provided template with finding details and select the appropriate button to submit. ## Related Resources - [Join a CodeHawks contest](/codehawks/join-a-codehawks-contest) - [Findings validity](/codehawks/findings-validity) - [View Private Competitions Findings](/codehawks/view-private-competitions-findings) - [What is a Finding](/codehawks/what-is-a-finding) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) --- *Last Updated: Over a year ago* ### Findings Severity ## Overview Cyfrin categorizes vulnerability findings into three severity levels to help stakeholders prioritize remediation efforts. Auditors who identify higher-severity vulnerabilities improve their contest rankings and earn higher payouts. ## Severity Categories The framework uses three tiers: - **High** - **Medium** - **Low severity** ## Evaluation Framework Severity classification depends on three factors: 1. **Impact on the protocol** — potential damage if exploited 2. **Likelihood of exploitation** — probability an attacker could succeed 3. **Judge/protocol subjectivity** — discretionary assessment ### Impact vs. Likelihood Matrix | | High Impact | Medium Impact | Low Impact | |---|---|---|---| | **High Likelihood** | H | M | M | | **Medium Likelihood** | M | M | L | | **Low Likelihood** | M | L | L | ## Impact Definitions **High Impact:** "Funds are directly or nearly directly at risk" or severe protocol disruption occurs. **Medium Impact:** Indirect fund risk or moderate functionality disruption. **Low Impact:** "Funds are not at risk" but functions may be incorrect or state handling inadequate. ## Likelihood Definitions **High:** Easily exploitable (direct function calls extracting funds) **Medium:** Requires specific conditions (unusual token parameters) **Low:** Unlikely scenarios (hard-to-change variables at specific blocks) *Note:* Claims of "computationally infeasible" attacks require proof of feasibility. ## Finding Examples **High severity** features straightforward attack paths with direct fund impact. **Medium severity** involves indirect impact requiring specific conditions. **Low severity** shows minimal real-world damage potential with improbable exploitation paths. ## Non-Acceptable Submissions As of August 18, 2023, CodeHawks rejects "Gas, QA, or Informational" severity submissions—focus on vulnerabilities directly impacting protocols, not optimization insights. ### Findings Validity ## Overview To qualify as valid, findings must satisfy all listed properties: - **Timing**: Submissions occur during official contest duration only - **Legitimacy**: Identify genuine vulnerabilities in the codebase - **Severity**: Gas/QA/Informational issues ineligible for rewards regardless of accuracy - **Documentation**: Provide substantial details and proof; submissions "relying solely or primarily on AI responses" face invalidation ## Contest-Specific Guidelines Two criteria determine finding validity: 1. Official contest specification on CodeHawks platform 2. In-scope code Sponsors receive a 48-hour kick-off period to clarify ambiguities via Discord. Post-deadline, the updated specification becomes definitive. Sponsors cannot retroactively invalidate submissions through "moving the goalposts" tactics—only when submissions fail predefined criteria. ## Vague Generalities Vague claims receive automatic rejection. Examples include asserting potential reentrancy without demonstrating actual vulnerability or suggesting hash collision risks without proof. Auditors must create a proof-of-concept (PoC) proving significant system damage or denial-of-service impact. Only auditors submitting actual exploits with PoCs receive rewards for proving vague submissions valid. ## Typically Invalid Categories Issues commonly rejected include: - Gas optimizations - Zero-address validation - Admin input mistakes - Front-runner initializer attacks (if redeployment possible) - UX/design preferences - User self-harm through blacklisting - EIP non-compliance without external integrations - Accidental token transfers - Reward loss outside protocol design - View function errors (unless causing fund loss) - Mock contract problems - Slippage (unless showing definite loss) - Out-of-gas scenarios **Note**: This table provides guidance only; judges retain discretion on final determinations. ### Write a Proof of Concept (PoC) ## Overview A Proof of Concept (PoC) demonstrates a concept's feasibility. In smart contract auditing contexts, it illustrates a vulnerability or flaw within a smart contract. Properly constructed PoCs help developers understand issues and their impacts, facilitating resolutions. ## Key Components ### 1. Working Test Case "This is the most direct way to demonstrate a vulnerability. It should be executable and should clearly show the flaw in action." The test case should be runnable and visibly expose the problem. ### 2. Line-by-Line Comments Each line requires accompanying explanatory comments detailing its purpose, helping readers understand the PoC's flow and reasoning. ### 3. Clear Separation of Actors Define distinct roles involved: - **Attacker**: The entity exploiting the vulnerability - **Victim**: The entity affected by the exploit - **Protocol**: The system or platform housing the smart contract ### 4. Detailed Exploit Scenario When test cases are impractical, provide step-by-step scenarios including: - **Initial State**: System's starting condition - **Step 1, 2, etc.**: Sequential attacker actions - **Outcome**: Exploit results - **Implications**: Potential consequences ## Recommendations 1. Suggest fixes addressing the vulnerability 2. Link to vulnerable code and relevant resources ## PoC Template ``` ## Proof of Concept for [Vulnerability Name] ### Overview: Briefly describe the vulnerability. ### Actors: - **Attacker**: Description of the attacker's role. - **Victim**: Description of the victim's role. - **Protocol**: Description of the protocol's role. ### Working Test Case (if applicable): ```solidity // Solidity code demonstrating the vulnerability // Line 1: Explanation // Line 2: Explanation ``` ### View Private Competitions Findings ## Overview **Private Competitions** on CodeHawks are confidential by design. "Any public release of findings or reports will be at the discretion of the contest sponsor at the time and by the means of their choosing." ## Accessing Your Findings If you've submitted findings in a Private Competition, you can view them anytime. However, access is limited to your own submissions only. There are two ways to locate your findings: 1. **CodeHawks Dashboard** — Browse competitions you're subscribed to and view your findings there 2. **Contest Page** — Navigate to any active or completed competition and scroll to the bottom to find your submissions ## Related Resources - [Submit a Finding](/codehawks/submit-a-finding) - [Findings Validity](/codehawks/findings-validity) - [Judging Process](/codehawks/judging-process) - [Private Competition](/codehawks/private-competition) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) ### Judging Process ## Overview The judging phase represents a critical component of Cyfrin CodeHawks' competitive audits, designed to maintain "integrity, transparency, and fairness" across contests. ## How the CodeHawks Judging Process Works ### Submission and Initiation Once a competition's submission period closes, the judging period commences. ### Lead Judging Phase A Cyfrin team member or appointed community expert serves as Lead Judge. The typical judging duration is approximately 2.5 weeks, though submission volume affects timeline. During this phase, the Lead Judge evaluates each submission's validity and severity. **Valid Findings:** When a submission is deemed valid, judges assign a "Finding Tag" that categorizes the vulnerability and indicates its type and severity level. **Invalid Findings:** Submissions deemed invalid receive an "invalidation reason" label. Judges may provide additional explanatory comments about the rejection. ### Competition Conclusion Following preliminary judgments on all submissions, competitions advance to the Appeals Period. After appeals are considered and final reviews completed, a "final report" is generated and the competition closes. ## Standards CodeHawks maintains "the highest standards of fairness and clarity" in judging methodology, continually refining processes to reflect best practices and provide participants with thorough, unbiased evaluation. ## Related Resources - [Join a CodeHawks contest](/codehawks/join-a-codehawks-contest) - [Findings validity](/codehawks/findings-validity) - [What are Appeals?](/codehawks/what-are-appeals) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [Appeals eligibility criteria](/codehawks/appeals-eligibility-criteria) ### What are Appeals? ## Overview Cyfrin CodeHawks maintains a transparent competition environment through an **Appeals Period**. "For 48 hours following judging, escalations will be accepted to contest judgments." During this window, participants can comment on GitHub submissions to request re-assessment of their work. ## Eligibility Requirements To challenge another auditor's submission, applicants must satisfy two conditions: 1. **Earnings threshold**: "Have earned at least $200 USDC from previous CodeHawks competitions" to reduce low-quality challenges and prevent manipulation. 2. **Quality ratio**: Maintain "a total submission to valid submission ratio greater than or equal to 0.2" demonstrating commitment to high standards. **Note**: Auditors may always appeal their own submissions regardless of these criteria. ## Process After judging concludes, preliminary results release immediately, triggering a two-day appeals window. Participants can: - Raise concerns about their submissions - Provide additional context or clarification - Challenge findings they believe contain errors ## How to Appeal Locate your judged submission (marked with a red notification dot) in the CodeHawks portal. Review judge feedback in the comment section, then add detailed comments explaining your position. "Low-effort appeals risk being disregarded." ## Key Principles **Quality matters**: Appeals require solid evidence and clear reasoning. Hasty submissions face dismissal. **Restraint recommended**: Excessive low-merit appeals may undermine credibility, potentially disqualifying even legitimate concerns. Lead Judges assess all appeals during this phase. Use the [Feedback Form](https://app.deform.cc/form/992e3c6a-b817-49f5-8075-1e50fb2e2d0f/) for additional concerns. ### Appeals Eligibility Criteria ## Overview To participate in appealing third-party submissions in CodeHawks competitions, auditors must satisfy specific eligibility requirements designed to maintain fair judging standards. ## Three Required Criteria Auditors seeking to appeal submissions from other participants must meet all of the the following conditions: 1. **Active Contest Participation**: "Have at least one submission in the Contest they would be judging" to demonstrate familiarity with the codebase and competition context. 2. **Earnings Threshold**: "Have earned at least $200 USDC from previous CodeHawks competitions" to filter out inexperienced judges and prevent sybil attacks. 3. **Quality Ratio**: Maintain "a total submission to valid submission ratio greater than or equal to 0.2" to ensure alignment with Cyfrin's quality standards. ## Important Exception The eligibility requirements apply exclusively to appealing others' work. The document clarifies: "An auditor will always be eligible to appeal their own submissions." ## Related Resources - [What is a competitive audit](/codehawks/what-is-a-competitive-audit) - [Join a CodeHawks contest](/codehawks/join-a-codehawks-contest) - [Judging process](/codehawks/judging-process) - [What are Appeals?](/codehawks/what-are-appeals) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) ### How to Appeal ## Article Summary This guide explains the process for appealing CodeHawks judging decisions through the platform's submission portal. ## Key Steps **Initiating an Appeal:** Users must navigate to their judged submission marked with a red notification dot on the CodeHawks portal to begin the appeals process. **Reviewing Feedback:** Before appealing, contestants should carefully read all community judge and lead judge comments provided in the comment section. **Submitting Your Appeal:** When disagreeing with a decision, users can add a new detailed comment explaining "in greater detail" why they believe an issue is valid or invalid. When challenging other entries, provide concise reasoning for identified discrepancies. ## Important Guidelines **Quality Standards:** The platform emphasizes that "low-effort appeals risk being disregarded." Appeals must be well-reasoned with substantial evidence. Hasty or unclear appeals will be closed promptly. **Appeal Frequency:** While valid concerns are welcome, excessive appeals with minimal merit can result in even legitimate future concerns being dismissed. Participants are encouraged to be thoughtful and selective. ## Process Oversight Lead judges assess all appeals during the designated appeals phase. For additional concerns, participants may use the official Feedback Form. ## Related Resources - [Judging process](/codehawks/judging-process) - [What are Appeals?](/codehawks/what-are-appeals) - [Appeals eligibility criteria](/codehawks/appeals-eligibility-criteria) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [Eagle Payments](/codehawks/eagle-payments) ### How Payouts Work ## Overview Auditor compensation is determined by shares of the prize pool based on finding severity and quantity submitted during smart contract auditing competitions. ## High/Medium Findings Calculation **Formula:** - Medium-Risk Shares: `1 * (0.9^(findingCount - 1)) / findingCount` - High-Risk Shares: `5 * (0.9^(findingCount - 1)) / findingCount` **Worked Example:** With a $30,000 H/M prize pool containing 3 highs and 2 mediums: | Finding | Count | Shares | |---------|-------|--------| | Medium A | 3 | 0.27 | | Medium B | 2 | 0.45 | | Medium C | 1 | 1.00 | | High A | 3 | 1.35 | | High B | 1 | 5.00 | | High C | 1 | 5.00 | **Results:** - Auditor A (6.62 total shares): 39.5% = $11,850 - Auditor B (7.07 total shares): 42.2% = $12,660 - Auditor C (3.07 total shares): 18.3% = $5,490 ## Low Findings Uses formula: `1 * (0.9^(findingCount - 1)) / findingCount` with considerably smaller prize pools. ## Payment Details - **Currency:** USDC - **Network:** ZKsync chain - **Requirement:** ZKsync wallet connection to user profile - **Tolerance:** ±0.0001 USDC margin of error ## Discontinued Categories As of August 18, 2023, gas optimization, QA, and informational submissions are no longer accepted. ## Duplicate Issues Duplicates share identical root causes, regardless of severity differences. Different root causes constitute separate findings. ### KYC Rewards ## Overview "Specific competitions will need auditors to KYC to receive their rewards." Participation in certain competitive audits requires completing Cyfrin's identity verification process beforehand. ## KYC Verification Steps To complete the identity verification process, follow these steps: 1. Access the navigation bar dropdown menu 2. Select **Settings** 3. In the **General** category, choose **Verify Identity** under **ID Verification** 4. A modal will appear requesting: - Identity Documentation - A liveness check (selfie) Follow the on-screen instructions to complete verification, which typically processes quickly but may take up to 24 hours. ## Supported Documents For documentation accepted in your region, visit the [Sumsub supported documents list](https://sumsub.com/supported-documents/). ## Support "Should you have issues completing the verification process, please reach out the Cyfrin's dedicated support team." ## Related Resources - [The auditing process](/codehawks/the-auditing-process) - [What are Appeals?](/codehawks/what-are-appeals) - [Invoice Your Rewards](/codehawks/invoice-your-rewards) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [How to redeem the SSCD+ certification code (RocketPool)](/updraft/how-to-redeem-the-sscd-certification-code-rocketpool) ### Invoice Your Rewards ## Overview This article provides invoicing information for Cyfrin competition winners who need documentation for tax purposes. ## Invoice Details **Company Information:** - Company Name: Cyfrin Inc. - Tax ID: 92-1600150 **Mailing Address:** 9066 Cascada Way #102 Naples, FL 34114 United States ## Important Disclaimer The organization explicitly states: "Cyfrin is unable to provide any advice pertaining to the filing of taxes." Winners are advised to "reach out to a tax professional in your jurisdiction" for guidance on properly reporting competition earnings. --- **Note:** This resource is designed to help competition participants obtain necessary documentation. For specific tax implications and filing requirements, individuals should consult with qualified tax professionals in their respective jurisdictions. ### What is a CodeHawks First Flight? ## Overview CodeHawks First Flights represents "a Cyfrin flagship initiative to introduce the next generation of web3 developers to smart contract security audits." The program transcends conventional learning by providing emerging auditors practical experience auditing actual web3 systems while receiving constructive evaluation on their vulnerability submissions. ## Program Description First Flights are auditing challenges featuring smaller codebases and distinct reward structures compared to standard competitions. They function as ideal practice environments for aspiring smart contract security specialists. The community contributes codebases for these competitions. New challenges launch weekly and are hosted on the CodeHawks platform. Unlike regular competitions, First Flights provide no monetary prizes but award participants experience points through submission of findings. ## Getting Started Participants can join by: 1. Creating an account at codehawks.cyfrin.io 2. Subscribing to upcoming competitions via the platform interface 3. Receiving launch notifications through email, the platform, Twitter, and Discord 4. Analyzing the released codebase upon competition start ## How They Function The process involves four stages: **Discovery Phase**: Teams receive guidelines and access to the codebase when contests launch. **Submission Phase**: Participants identify vulnerabilities, develop proofs-of-concept, and submit findings through the portal. **Evaluation Phase**: Judges review, test, and validate each submission, determining severity levels. **Recognition Phase**: XP points are awarded to successful participants, enabling leaderboard progression. ## Key Benefits - Weekly challenges exposing participants to diverse scenarios - Progressive skill development through increasing complexity - Recognition and ranking on community leaderboards - Direct feedback from professional judges For those needing foundational knowledge, Cyfrin Updraft provides free smart contract learning resources. ### Join a CodeHawks First Flight ## Overview Participation in CodeHawks First Flights is accessible to everyone. According to the article, "A new First Flight begins **every second week on Thursday.**" ## Steps to Join ### Step 1: Navigate to First Flights From any location on the CodeHawks platform, select **First Flights** in the top navigation bar. This view displays the currently active First Flight competition and provides access to historical contests. ### Step 2: Subscribe for Notifications Click the **Subscribe** button to receive alerts about the current First Flight. ### Step 3: View Contest Details Select **View Contest** to access comprehensive information about the specific First Flight you're interested in. ### Step 4: Submit Your Findings When a First Flight is active, you can submit your findings at the bottom of the contest page. ## Related Resources - [Join a CodeHawks contest](/codehawks/join-a-codehawks-contest) - [Submit a finding](/codehawks/submit-a-finding) - [Submit a First Flight](/codehawks/submit-a-first-flight) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [AI First Flights](/codehawks/ai-first-flights) ### Submit a First Flight ## Overview "Community First Flights are Cyfrin's most recent expansion to our First Flight initiative." This program offers an excellent opportunity for developers to contribute engaging codebases while honing their security skills. ## Submission Requirements ### Project Specifications Your submission must meet these criteria: 1. **Thematic Project**: Develop something fun with a theme (holidays are popular choices) 2. **Code Size**: In-scope contracts should be approximately 100-200 nSLOC 3. **Complexity**: Maximum project complexity of 200 ### Required Vulnerabilities Your codebase must intentionally include: - One or two easy-to-find bugs - One medium-difficulty bug - One hard-to-find bug - One High/Critical severity issue - One Low severity issue You must also "write up an answer key detailing the intentional bugs you've placed in your code!" ### Documentation Include a properly formatted README using the provided template to describe your protocol. ## Submission Process Once your repository is ready, complete the submission form and contact @**equious.eth** on Discord. The team will arrange private code sharing, conduct vetting, and provide feedback on necessary adjustments. ## Timeline & Scheduling Submissions follow a first-come, first-served basis with these considerations: - Submissions must be fully vetted and accepted before entering the queue - "First Flights are held twice/month" - Three days' notice minimum is required before launch - Submissions with less notice are scheduled for the next available contest Note: "Cyfrin retains the right to shift to a lottery selection process should the pending submissions grow too large." ### AI First Flights ## Overview Cyfrin CodeHawks has introduced AI-powered First Flights, which operate similarly to standard First Flights but incorporate significant AI automation capabilities. ## Getting Started To access AI First Flights: 1. Navigate to **First Flights** in the CodeHawks navigation bar 2. Select the **AI Judged First Flight** tab 3. Browse the available challenges and select one to begin ## Challenge Details Once you initiate a challenge by clicking "Start Challenge," you'll have **one week** to identify and report vulnerabilities. Information about submitting findings is available in the dedicated submission guide. ## Key Differences from Regular First Flights AI First Flights differ in three important ways: - **Flexible timing**: Participants can start at any point, rather than during designated windows - **No appeals process**: Decisions are final without appeal opportunities - **Instant evaluation**: The AI judge provides immediate performance feedback ## Purpose These challenges offer an opportunity to develop security expertise while receiving actionable, specific feedback on your analytical approach and findings quality. ## Related Resources - [Join a CodeHawks contest](/codehawks/join-a-codehawks-contest) - [Submit a First Flight](/codehawks/submit-a-first-flight) - [Judging process](/codehawks/judging-process) - [What are Appeals?](/codehawks/what-are-appeals) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) ### The Auditing Process ## Overview Cyfrin CodeHawks employs "an innovative private and community code review process" to secure protocols. The company prioritizes both protocol security and developer experience. ## Key Stages ### 1. Request an Audit Teams submit requests via codehawks.com and receive contact within two days for a screening call to evaluate the project. ### 2. Screening Interview and Code Base Assessment CodeHawks discusses audit scope, timeline, and requirements while recommending the optimal auditing approach. ### 3. Pricing and Timelines An initial assessment determines project complexity and generates a quote based on required audit duration. ### 4. Code Freeze "At least 2 days before the audit starts, protocol's teams are required to send CodeHawks the final: commit, branch, known issues, contracts." A code freeze then prevents changes to ensure consistent review scope. ### 5. Audit Begins For competitions, protocol teams provide dedicated Discord support via a "sponsor" role. Community managers remain available throughout. ### 6. Judging and Appeals After contests conclude, security experts evaluate submissions. The appeal period allows flagging of potentially miscategorized findings. ### 7. Initial Report CodeHawks delivers "a curated, de-duplicated list of all High, Medium and low-severity findings" organized for prioritization. ### 8. Mitigation Phase (Competitive/Private Audits Only) Teams implement fixes within an agreed timeframe. Optional mitigation review contests verify implementations faster than initial audits. ### 9. Final Report Post-fix review confirms all vulnerabilities addressed and code readiness for deployment. --- ## Updraft ### Updraft *Learn Web3 security and smart contract development* ## Web3 Education Platform Updraft is Cyfrin's comprehensive learning platform for Web3 security, smart contract development, and blockchain technology. - [Find Courses](/updraft/find-courses-to-take): Explore our course catalog - [Get Certified](/updraft/what-is-a-cyfrin-updraft-professional-certification): Earn professional certifications - [Study Guides](/updraft/what-is-a-cyfrin-updraft-certification-study-guide): Download certification guides - [Share Your Achievement](/updraft/how-to-share-your-cyfrin-certification): Showcase your credentials ## Certifications Prove your expertise with Cyfrin certifications recognized across the Web3 industry. Industry-recognized credentials that demonstrate deep technical knowledge and hands-on skills. Requires passing a rigorous exam. [Learn more →](/updraft/what-is-a-cyfrin-updraft-professional-certification) Show you've completed specific Updraft courses. Perfect for documenting your learning journey. [Learn more →](/updraft/what-is-a-cyfrin-updraft-certificate-of-completion) Access comprehensive study guides to prepare for certification exams. [Download guides →](/updraft/how-to-download-the-cyfrin-updraft-study-guide) ## Learning Resources - [Course Settings](/updraft/change-video-settings): Customize your learning experience - [Quizzes](/updraft/complete-a-course-quiz): Test your knowledge - [Troubleshooting](/updraft/fix-a-problem-playing-videos): Get help with technical issues ### What is a Cyfrin Updraft Professional Certification? ## Overview A **Cyfrin Updraft Professional Certification** represents "an industry-recognized credential that proves you have advanced, real-world skills in smart contract development and blockchain security." Unlike standard course completion certificates, these are "proctored, exam-based certifications built to verify and validate your ability to work at a professional level." ## Why It Matters Top protocols, security firms, and development teams across Web3 recognize and trust Cyfrin certifications. Earning a professional certification enables you to: - Demonstrate expertise in Solidity and smart contract security - Differentiate yourself in job applications, freelance opportunities, and DAO contributions - Establish lasting credibility within the blockchain developer community ## Getting Started If you're not yet prepared for a professional certification exam, Cyfrin offers a **Certificate of Completion** as an alternative pathway to begin your learning journey. --- ## Related Resources - [What is a Cyfrin profile?](/profiles/what-is-a-cyfrin-profile) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [What are Cyfrin Eagles?](/codehawks/what-are-cyfrin-eagles) - [What is a Cyfrin Updraft Certificate of Completion?](/updraft/what-is-a-cyfrin-updraft-certificate-of-completion) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### What is a Cyfrin Updraft Certificate of Completion? ## Overview A Certificate of Completion demonstrates that a learner has finished a course on Cyfrin Updraft and successfully passed the required end-of-course examination. ## Key Distinction These credentials are **not professional certifications**. Rather, they serve as evidence that individuals have invested effort in learning course material and completed their respective courses. ## Purpose and Value Whether beginning smart contract development or enhancing specific technical skills, these certificates provide a meaningful way to document progress through Cyfrin's educational programs. ## How to Use Certificates Learners can leverage their certificates of completion by: - Tracking learning progression across the Updraft platform - Including them on resumes or personal websites - Demonstrating acquired knowledge to prospective employers or clients - Sharing achievements on LinkedIn and other professional networks ## Professional Certification Alternative For individuals seeking advanced, exam-based credentials that formally validate expertise, Cyfrin offers professional certifications such as SSCD+, which provide a higher level of industry recognition. --- **Related Resources:** - [What is a Cyfrin profile?](/profiles/what-is-a-cyfrin-profile) - [How to Download the Cyfrin Updraft Study Guide](/updraft/how-to-download-the-cyfrin-updraft-study-guide) - [What is a Cyfrin Updraft Professional Certification?](/updraft/what-is-a-cyfrin-updraft-professional-certification) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### Professional Certifications vs. Certificates of Completion ## Certificate of Completion A Certificate of Completion demonstrates completion of a course and passing the final proficiency exam. **What it means:** You have: - Completed the course curriculum - Passed the end-of-course exam - Built foundational knowledge of the material **Good for:** - Tracking personal progress - Adding to resume, website, or profiles - Sharing on social media **How to get it:** - Complete all course lessons, including quizzes - Successfully pass the course's final proficiency exam - Download certificate as PDF from the course page --- ## Professional Certification "A professional certification shows that you passed a standalone, proctored exam designed to test your ability to apply skills in real-world scenarios." **What it means:** You have: - Demonstrated expertise, skill, and mastery with ability to build - Passed a rigorous, expert-level exam - Achieved recognized industry standard - Established qualification to work professionally in the field **Good for:** - Proving job-ready skills for immediate impact - Building credibility with employers or clients - Standing out on recruiting, hiring, and freelance platforms **How to get it:** - Select and purchase a Certification voucher (e.g., SSCD+) - Schedule and pass the proctored exam - Receive formal, shareable credential --- ## Comparison Table | Aspect | Certificate of Completion | Professional Certification | |--------|---------------------------|----------------------------| | **What it is** | Proof of course completion and material understanding | Proof of rigorous professional skills and capability | | **Skill level** | Beginner to intermediate | Advanced, real-world scenarios | | **Exam format** | 40-75 minutes | 90 minutes | | **Industry recognition** | Informal | Yes, industry standard | | **Used for hiring** | Sometimes | Frequently | | **Downloadable** | Yes (PDF + public credential) | Yes (PDF + public credential) | --- ## Which Should You Choose? - **Just starting out?** Take a course and earn a certificate of completion - **Proving job or freelance skills?** Pursue professional certification like SSCD+ "Many learners start with completion certificates and then level up to professional credentials." --- **Related Resources:** - [Professional Certifications](https://updraft.cyfrin.io/certifications) - [Cyfrin Updraft Courses](https://updraft.cyfrin.io/courses) ### How to purchase a Cyfrin certification ## Overview This guide walks users through the complete process of purchasing a Cyfrin certification on the Updraft platform. ## Step-by-Step Process 1. **Navigate to the Certifications Page** - Access certifications via the top navigation bar 2. **Select Your Certification** - Browse available options and click "Go to Certification" for your chosen program 3. **Start the Enrollment Process** - Click the green "Get Certified" button in the certification page summary 4. **Customize Your Order** - Review pricing and optional add-ons available at discounted rates: - **Practice Book**: "Get access to 270+ practice questions tailored for your certification" - **Retake Voucher**: Enables retesting if needed - Option to gift the voucher to another person 5. **Proceed to Payment** - Click the green "Proceed to Payment" button after finalizing your order 6. **Complete the Purchase** - Enter payment details and click "Pay" in the bottom right corner - Follow on-screen instructions to finalize the transaction 7. **Prepare for Your Exam** - Review resources post-purchase and begin exam preparation ## Related Resources - [What is a Cyfrin Updraft Certification Study Guide?](/updraft/what-is-a-cyfrin-updraft-certification-study-guide) - [How to Download the Cyfrin Updraft Study Guide](/updraft/how-to-download-the-cyfrin-updraft-study-guide) - [How to redeem the SSCD+ certification code (RocketPool)](/updraft/how-to-redeem-the-sscd-certification-code-rocketpool) - [What is a Cyfrin Updraft Certificate of Completion?](/updraft/what-is-a-cyfrin-updraft-certificate-of-completion) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### What is an Exam Voucher? ## Article Overview **Title:** What is an Exam Voucher? **Last Updated:** Over a year ago --- ## Content An exam voucher functions as "a unique code that allows you to schedule your certification exam." When you buy a certification while logged into your Cyfrin account, the voucher is automatically placed in your profile for convenient redemption. ### How to Purchase an Exam Voucher 1. Navigate to https://updraft.cyfrin.io/certifications 2. Choose your desired certification program 3. Complete the purchase transaction, and your voucher becomes available immediately --- ## Related Resources - [What is a Cyfrin Updraft Certification Study Guide?](/updraft/what-is-a-cyfrin-updraft-certification-study-guide) - [How to Purchase a Cyfrin Certification](/updraft/how-to-purchase-a-cyfrin-certification) - [How to Retake a Certification Exam](/updraft/how-to-retake-a-certification-exam) - [How to Download the Cyfrin Updraft Study Guide](/updraft/how-to-download-the-cyfrin-updraft-study-guide) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### How to Gift a Certification ## Overview "Gifting a certification is a thoughtful way to support someone's professional growth." ## Steps to Gift a Certification 1. **Visit the Certification Page** - Navigate to [updraft.cyfrin.io/certifications](https://updraft.cyfrin.io/certifications) 2. **Select the Certification** - Choose your desired certification and click the "Go to Certification" button 3. **Choose "Purchase as a Gift"** - Select the "Purchase as a Gift" option during the checkout process 4. **Enter Recipient Details** - Provide the recipient's email address - Optionally include a personalized message with the gift 5. **Complete the Purchase** - Finalize payment to complete the transaction - The recipient will receive an email containing your personalized message and a unique voucher code for redemption ## Related Resources - [What is a Cyfrin Updraft Certification Study Guide?](/updraft/what-is-a-cyfrin-updraft-certification-study-guide) - [How to Purchase a Cyfrin Certification](/updraft/how-to-purchase-a-cyfrin-certification) - [How to Retake a Certification Exam](/updraft/how-to-retake-a-certification-exam) - [How to Download the Cyfrin Updraft Study Guide](/updraft/how-to-download-the-cyfrin-updraft-study-guide) - [How to Redeem a Certification Coupon?](/updraft/how-to-redeem-a-certification-coupon) ### How to redeem a certification coupon? ## Overview Coupons offer discounts on certification purchases. The redemption process involves four straightforward steps completed during checkout. ## Steps to Redeem **1. Select Your Certification** Visit [updraft.cyfrin.io/certifications](https://updraft.cyfrin.io/certifications) and choose your desired certification. Click "Get Certified" and add any optional add-ons you want. **2. Proceed to Payment** After finalizing your selection, click "Proceed to Payment" to advance to the checkout page. **3. Apply Your Coupon** On the order summary (right side of screen), enter your coupon code in the input field and select "Apply". The discount will instantly reduce your total. **4. Important Note** Even if your coupon covers 100% of the cost, you must still provide credit card information. This requirement stems from limitations by payment processor Stripe. ## Support For assistance with coupon redemption, reach out via: - [Discord](https://discord.gg/cyfrin) - Email: support@cyfrin.io ## Related Articles - [How to gift a certification](/updraft/how-to-gift-a-certification) - [How to purchase a Cyfrin certification](/updraft/how-to-purchase-a-cyfrin-certification) - [How to redeem the SSCD+ certification code (RocketPool)](/updraft/how-to-redeem-the-sscd-certification-code-rocketpool) - [How to redeem the SSCD+ certification code (GMX)](/updraft/how-to-redeem-the-sscd-certification-code-gmx) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### How to retake a certification exam ## Overview If you didn't pass your certification exam, don't worry—you can retake it after a brief waiting period. ## Key Points to Note - You can retake the exam **once every 2 weeks**. - To retake the exam, you'll need either an **Exam Retake Voucher** or a new **Exam Voucher**. ## How to Retake the Exam ### If You Have an Exam Retake Voucher: 1. Navigate to the certification page on [updraft.cyfrin.io/certifications](https://updraft.cyfrin.io/certifications). 2. The **Start exam** button will be activated once the waiting period expires. ### If You Don't Have an Exam Retake Voucher: 1. Navigate to the certification page on [updraft.cyfrin.io/certifications](https://updraft.cyfrin.io/certifications). 2. Purchase a new **Exam Voucher**. 3. The **Start exam** button will be activated once the waiting period expires. --- ## Related Articles - [What is an exam voucher?](/updraft/what-is-an-exam-voucher) - [What is a Cyfrin Updraft Certification Study Guide?](/updraft/what-is-a-cyfrin-updraft-certification-study-guide) - [How to purchase a Cyfrin certification](/updraft/how-to-purchase-a-cyfrin-certification) - [Certification Policies](/updraft/certification-policies) - [What happens if I purchase a "retake" and then pass?](/updraft/what-happens-if-i-purchase-a-retake-and-then-pass) ### What happens if I purchase a "retake" and then pass? ## Article Content If you buy a retake option for your Cyfrin certification exam and pass on your first try, the retake will not be refunded or credited. "All sales are final, and no refunds are issued once the retake option is purchased, regardless of whether it is used." The platform recommends carefully assessing your preparation level before purchasing a retake to ensure the purchase aligns with your actual needs. ## Support Options For additional questions, you can reach out through: - The [support page](https://support.cyfrin.io) - The Discord Community ## Related Articles - [What is an exam voucher?](/updraft/what-is-an-exam-voucher) - [What is a Cyfrin Updraft Certification Study Guide?](/updraft/what-is-a-cyfrin-updraft-certification-study-guide) - [How to purchase a Cyfrin certification](/updraft/how-to-purchase-a-cyfrin-certification) - [How to retake a certification exam](/updraft/how-to-retake-a-certification-exam) ### Certification Policies ## All Sales Are Final "All sales are final. Once a purchase has been completed, refunds or cancellations are not permitted." Buyers should thoroughly review their orders before completing payment. ## Voucher Validity "Each exam voucher is valid for 365 days from the date of purchase." After this expiration window closes, purchasers must buy another voucher to schedule their examination. --- ## Related Resources - [What is a Cyfrin Updraft Certification Study Guide?](/updraft/what-is-a-cyfrin-updraft-certification-study-guide) - [How to purchase a Cyfrin certification](/updraft/how-to-purchase-a-cyfrin-certification) - [How to retake a certification exam](/updraft/how-to-retake-a-certification-exam) - [What happens if I purchase a "retake" and then pass?](/updraft/what-happens-if-i-purchase-a-retake-and-then-pass) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### What is a Cyfrin Updraft Certification Study Guide? ## Overview The **Cyfrin Updraft Certification Study Guide** is a customized preparation resource designed to help candidates ready themselves for certification exams. ## Key Features The study guide includes: - **Resource Links**: Comprehensive links to all materials needed for exam preparation - **Sample Questions**: "270+ sample questions designed to closely resemble the types of questions you'll encounter on your certification exam" ## Purchase Options Candidates can acquire the preparation book through two methods: 1. **During Checkout**: Purchase alongside an Exam Voucher 2. **After Redemption**: Buy directly from the certification page after redeeming a voucher ## Purpose The preparation book serves as a confidence-building tool to ensure candidates are adequately prepared for their exam. --- ## Related Resources - [How to purchase a Cyfrin certification](/updraft/how-to-purchase-a-cyfrin-certification) - [How to Download the Cyfrin Updraft Study Guide](/updraft/how-to-download-the-cyfrin-updraft-study-guide) - [How to redeem the SSCD+ certification code (RocketPool)](/updraft/how-to-redeem-the-sscd-certification-code-rocketpool) - [What is a Cyfrin Updraft Certificate of Completion?](/updraft/what-is-a-cyfrin-updraft-certificate-of-completion) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### How to Download the Cyfrin Updraft Study Guide ## Overview Accessing your certification study materials involves a straightforward process through the Cyfrin Updraft platform. ## Steps to Download 1. **Navigate to Your Certification Page** - Visit the certification page for your selected exam on Cyfrin Updraft - Use the certifications section or search bar to locate it 2. **Locate the Study Guide Card** - Find the "Study Guide" card positioned in the screen's top-right corner 3. **Click the Download Button** - Select the download option to access your study guide 4. **Check Your Email for Backup Link** - After redeeming your voucher, you'll receive an email containing an alternative download link ## Important Requirement **Exam Voucher Redemption:** The download button only appears after you schedule your exam voucher. Complete the exam scheduling step first to unlock study material access. ## Support Resources For technical difficulties or additional assistance, reach out through: - The official support page - The Cyfrin Discord Community ## Related Resources - [What is a Cyfrin Updraft Certification Study Guide?](/updraft/what-is-a-cyfrin-updraft-certification-study-guide) - [How to purchase a Cyfrin certification](/updraft/how-to-purchase-a-cyfrin-certification) - [How to redeem the SSCD+ certification code (RocketPool)](/updraft/how-to-redeem-the-sscd-certification-code-rocketpool) - [What is a Cyfrin Updraft Certificate of Completion?](/updraft/what-is-a-cyfrin-updraft-certificate-of-completion) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### How to redeem the SSCD+ certification code (RocketPool) ## Overview Cyfrin Updraft has partnered with Rocket Pool to provide "SSCD+ certification vouchers to the first 25 students who complete the Rocket Pool course." ## Redemption Steps ### 1. Join the Rocket Pool Discord Server Click the green "Join Discord" button and follow the prompts to access the Rocket Pool server. ### 2. Contact the Verification Admin Once in the server, send a direct message to **ShfRyn** (User ID: 152043366719160320) with your Cyfrin account email address. **Important:** Verify you're contacting the correct person before messaging. See verification instructions below. ### Eligibility Requirements Before issuing vouchers, the teams will verify: - Completion of all course lessons - Quiz score assessment - Request authenticity "The Rocket Pool and Cyfrin Updraft teams reserve the right to reject any voucher request that fails to meet these requirements." ## Verification Process 1. ShfRyn validates your eligibility 2. Upon approval, you receive your certification code ## How to Verify User ID To confirm you're contacting the right ShfRyn: 1. Search for ShfRyn in Rocket Pool Discord 2. Click their profile 3. Select "Copy User ID" from the menu 4. Confirm the ID matches: **152043366719160320** ### How to Redeem the SSCD+ Certification Code (GMX) ## Overview Cyfrin Updraft partnered with GMX to offer SSCD+ certification vouchers to the first 25 students who complete the GMX Perpetuals Trading course and demonstrate practical application of the material. ## Step-by-Step Process ### 1. Join the GMX Discord Server Click the green "Get SSCD+ certified" button and follow the prompts to access the GMX Discord community. ### 2. Contact the Verification Admin Enter the Community Developers Group channel and direct message **@Jonezee** (jonezee_gmx, User ID: 736344623013953706). **Important**: Verify you're messaging the correct person by confirming their User ID matches the number above. ### 3. Choose a Project Select from these options to demonstrate your learning: - Trading integration development - GMX arbitrage bot/tool creation - Delta-neutral funding fee farming vault - Positive price impact capture vault - Copy-trading bot/tool - Liquidity rebalancing automation tool - AI Agent for GMX trading **Note**: Contact jonezee_gmx *before* starting your project, as each category has limited slots. ### 4. Verification Process Submit your completed project to jonezee_gmx for validation. They will verify: - All course lessons completed - Quiz score performance - Request authenticity Upon approval, you'll receive your certification coupon code. ## Verifying User ID To confirm the correct contact: 1. Search for jonezee_gmx in the GMX Discord server 2. Click their profile 3. Select "Copy User ID" 4. Confirm it matches: **736344623013953706** ### How to Share Your Cyfrin Certification Sharing your Cyfrin certification is a great way to showcase your skills and achievements. Here's how you can share it: ## 1. Download Your Certification - Log in to your Cyfrin account and navigate to the certification page. - Click the **"Download Certification"** button to save your certificate as a PDF. ## 2. Share on LinkedIn - Log in to your LinkedIn profile and go to the **Licenses & Certifications** section. - Click the **"+"** icon to add a new certification. - Fill in the following details: - **Certification Name**: Enter the name of your certification (e.g., "Solidity Smart Contract Developer Certification (SSCD+)"). - **Issuing Organization**: Select **Cyfrin**. - **Issue Date**: Enter the date you passed the exam. - **Credential ID**: If applicable, use the unique ID on your certification. - **Credential URL**: Include the direct link to your Cyfrin profile or the certification page. - Save your changes to display the certification on your LinkedIn profile. ## 3. Share on Social Media or Email - Attach your downloaded certification PDF or include a link to your Cyfrin profile. - Share it directly on platforms like Twitter, Facebook, or Instagram, or email it to your network. ## 4. Add to Your Resume or Portfolio - Include your Cyfrin certification in the **Certifications** section of your resume. - If you maintain a portfolio, add the certification to showcase your expertise. ### How do I download a PDF copy of my certification? ## Overview After successfully completing a certification exam, you have two convenient methods to obtain your PDF certificate. ## Method 1: From the Certification Page 1. Visit [updraft.cyfrin.io/certifications](https://updraft.cyfrin.io/certifications) 2. Select your passed certification 3. Click the green "Download Certification" button to retrieve your PDF ## Method 2: From Your Email 1. You'll receive a confirmation email after passing your exam 2. The email contains a link for downloading your certificate as a PDF 3. Follow the provided instructions to access and save your certificate --- ## Related Resources - [How to share your Cyfrin certification](/updraft/how-to-share-your-cyfrin-certification) - [How to purchase a Cyfrin certification](/updraft/how-to-purchase-a-cyfrin-certification) - [How to Download the Cyfrin Updraft Study Guide](/updraft/how-to-download-the-cyfrin-updraft-study-guide) - [What is a Cyfrin Updraft Certificate of Completion?](/updraft/what-is-a-cyfrin-updraft-certificate-of-completion) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### Share a Completed Course ## Article Content You've put in the work and the results speak for themselves! If you've completed a course and are excited to share the achievement, Updraft allows you to do this smoothly! ### Steps to Share Your Achievement 1. **Navigate to the course summary page** of the course you've completed. 2. **Click the Share achievement button** on the course page (as shown in the screenshot of the "Introduction to Python and Vyper" course). 3. **Select your preferred sharing platform** or download your own PNG image to share your accomplishment. A congratulations pop-up will appear with options to share your completion across various social media platforms or save the certificate as an image file. --- ## Related Resources - [Find courses to take](/updraft/find-courses-to-take) - [Complete a Course Quiz](/updraft/complete-a-course-quiz) - [How to redeem the SSCD+ certification code (GMX)](/updraft/how-to-redeem-the-sscd-certification-code-gmx) - [What is a Cyfrin Updraft Certificate of Completion?](/updraft/what-is-a-cyfrin-updraft-certificate-of-completion) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### Find courses to take ## Overview Updraft hosts diverse content for all skill levels. The platform helps learners discover appropriate courses through an organized browsing system. ## Finding Courses To locate courses on the Cyfrin Updraft platform: 1. **Navigate to Courses**: "Click on **Courses** in the top navigation bar." 2. **Browse by Level**: "Select a course, or click **view all courses** for your specific level of skill." The browsing interface presents beginner, intermediate, and advanced course sections. Selecting "view all courses" displays a comprehensive summary page of available offerings at that difficulty level. ## Enrollment Process Once you've identified an interesting course: 1. Select **Go to course** to access the course summary page 2. Click **Continue course** to begin from the start or resume your previous progress ## Related Resources - [Complete a Course Quiz](/updraft/complete-a-course-quiz) - [How to redeem the SSCD+ certification code (RocketPool)](/updraft/how-to-redeem-the-sscd-certification-code-rocketpool) - [What is a Cyfrin Updraft Certificate of Completion?](/updraft/what-is-a-cyfrin-updraft-certificate-of-completion) - [What is a Cyfrin Updraft Professional Certification?](/updraft/what-is-a-cyfrin-updraft-professional-certification) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) ### Change Video Settings ## Overview Cyfrin Updraft's video players provide customization features at the bottom to enhance your learning experience. ## Video Player Controls The player includes the following controls: 1. **Play/Pause Button** - Start or stop video playback 2. **Volume Control** - Adjust audio levels 3. **Auto-play Toggle** - "Toggle this on to start the next video automatically after completing one" 4. **Closed Captions** - Enable or disable subtitles 5. **Keyboard Shortcuts** - Display available keyboard commands for player control 6. **Settings Menu** - Access advanced options including: - **Speed** - Increase or decrease playback velocity - **Quality** - Customize video resolution for your connection type - **Captions** - Select from 14 language options for subtitles 7. **Full Screen Toggle** - Expand video to full screen ## Supported Caption Languages The platform supports closed captions in the following languages: - English, Bulgarian, Spanish, Persian, French - Indonesian, Italian, Japanese, Korean, Portuguese - Russian, Turkish, Vietnamese, Chinese ## Related Resources - [Fix a problem playing videos](/updraft/fix-a-problem-playing-videos) ### Fix a problem playing videos ## Requirements To watch videos on Cyfrin Updraft, ensure you have: - The newest version of Google Chrome, Firefox, or Safari - Internet connection with 500+ Kbps ## Recommended Internet Speeds by Resolution | Video Resolution | Recommended sustained speed | |------------------|----------------------------| | 4K UHD | 20 Mbps | | HD 1080p | 5 Mbps | | HD 720p | 2.5 Mbps | | SD 480p | 1.1 Mbps | | SD 360p | 0.7 Mbps | ## Troubleshooting Steps Verify your connection quality using [downforeveryoneorjustme.com](https://downforeveryoneorjustme.com/). This service helps determine whether connection issues are specific to your setup or widespread. If you've confirmed adequate connection speed and verified the problem isn't site-wide, reach out through the Support channel in the [Cyfrin Discord](https://discord.gg/Cyfrin) community for additional assistance. ## Related Articles - [Fix a Login Problem](/profiles/fix-a-login-problem) - [Change video settings](/updraft/change-video-settings) ### Complete a Course Quiz ## Overview Cyfrin Updraft courses include **quizzes** as optional checkpoints throughout the curriculum. These assessments help learners evaluate their comprehension of course material. ## How Quizzes Work Quizzes appear among course lessons and serve as self-assessment tools. As explained in the help article, these checkpoints allow you to "test your skills and see how closely you've been following the course content." ## Feedback and Results Upon completion, the system provides immediate feedback. You receive information about your performance strengths and areas warranting further review. Results display your score (e.g., 80%) alongside constructive guidance. ## Optional Participation Quizzes are completely optional. The article notes: "feel free to challenge yourself as you go, or come back to the quizzes later." Learning pace and approach remain entirely within your control. --- ## Related Resources - [Find courses to take](/updraft/find-courses-to-take) - [What is a Cyfrin Updraft Certificate of Completion?](/updraft/what-is-a-cyfrin-updraft-certificate-of-completion) - [Professional Certifications vs. Certificates of Completion](/updraft/professional-certifications-vs-certificates-of-completion) - [How to redeem the SSCD+ certification code (RocketPool)](/updraft/how-to-redeem-the-sscd-certification-code-rocketpool) ### Reset a Quiz ## Overview If a quiz attempt doesn't meet expectations, there's a straightforward recovery option available through the platform. ## Instructions On the **Quiz Summary Screen**, locate and select the **Retry** button. This action will mark the quiz as incomplete and return you to the starting point, allowing for another attempt. ## Result The retry function essentially resets your progress, giving you the opportunity to retake the assessment from the beginning. --- **Last Updated:** Over a year ago **Category:** [Quizzes](https://support.cyfrin.io/en/collections/10770470-quizzes) under [Updraft](https://support.cyfrin.io/en/collections/10770061-updraft) --- ## Solodit ### Solodit *Navigate 20,000+ security vulnerabilities and bug bounties* ## The Ultimate Security Research Platform Solodit aggregates over 20,000 vulnerability reports from top audit platforms, providing searchable, categorized insights for security researchers and developers. - [Search Vulnerabilities](/solodit/search-for-a-finding): Find relevant security issues - [Browse Bug Bounties](/solodit/search-for-a-bounty): Discover active bounty programs - [Rate Findings](/solodit/rate-a-finding): Contribute to the community - [Add Findings](/solodit/add-new-finding): Submit new vulnerabilities ## Features **Advanced Search** Filter by protocol, vulnerability type, severity, and more **Community Ratings** See how the community rates findings based on quality and impact **Personal Notes** Take notes on findings for future reference **Leaderboards** Track top researchers across platforms ## Tools & Resources - [Vulnerability Tags](/solodit/tags-list-and-descriptions): Understand security terminology - [Note Taking](/solodit/managing-your-notes): Organize your research - [Leaderboard](/solodit/aggregated-leaderboard): View top performers > **Note:** Solodit aggregates data from CodeHawks, Code4rena, Sherlock, and other leading audit platforms. ### Navigate Vulnerabilities ## Findings Viewer Your filtered results display on the right side in the Findings Viewer interface. ### Components Overview **1. Findings Viewer** An itemized list showing findings matching applied filters. Results can be further refined by Bookmarked, Read, and Unread status. **2. Result Card Display** Each finding card shows: - **Title of the finding** - **Date found** - **Protocol impacted** - **Finding authors** To the right are options to copy links and bookmark items. **3. Finding Detail Viewer** The details section provides an explicit breakdown including: - **Description** - Overview of the vulnerability - **Severity** - Risk classification level - **Impact** - Consequences of exploitation - **PoCs** - Proof of Concepts (when applicable) - **Recommended mitigations** - Remediation guidance ### Additional Features The heading section displays community-submitted Rarities, Categories, and Tags. Action buttons (from top to bottom) enable: 1. Navigate to full report 2. Copy report link 3. Bookmark finding 4. Mark as Read Links to GitHub discussions are available, allowing users to actively participate in vulnerability discussions. --- ## Related Articles - [Search for a finding](/solodit/search-for-a-finding) - [Search for a bounty](/solodit/search-for-a-bounty) - [Join a CodeHawks contest](/codehawks/join-a-codehawks-contest) - [Findings validity](/codehawks/findings-validity) - [View Competition Results](/codehawks/view-competition-results) ### Search for a Finding ## Overview Solodit aggregates web3 security audit findings from various sources, offering a streamlined search experience through comprehensive filtering options. ![Filter sidebar for search results](https://downloads.intercomcdn.com/i/o/mtinxknm/1233000269/d15a7025dfc15a57de8e72f10ee3/2K1oMItrxeM5lbjrh3VO5szP-tkfEsAvbA.jpeg) *Solodit findings filters* ## Search Fields The platform provides multiple filtering mechanisms: - **Keywords**: "Enter specific terms or phrases to narrow down findings" - **Source**: Filter by audit origin or platform - **Impact**: Severity categorization including High, Medium, Low, and Gas options - **Author**: Find reports by specific individuals or entities - **Protocol Name**: Target findings for particular protocols - **Protocol Category**: Filter by type (Lending, NFT Marketplace, Oracles, Liquid Staking, Gaming, etc.) - **Forked From**: Focus on derived protocol findings - **Report Tag**: Labels for specific categorization ## Advanced Filtering Options Selecting the "View More" dropdown reveals additional filters: - **Number of Finders**: "Filter based on how many individuals identified a particular issue" - **Reported After**: Filter by report date - **Rarity Score**: Community-voted score indicating bug uniqueness; higher scores mean greater rarity - **Quality Score**: Community assessment of report quality ## Related Resources - [Navigate vulnerabilities](/solodit/navigate-vulnerabilities) - [Add new finding](/solodit/add-new-finding) - [Rate a finding](/solodit/rate-a-finding) - [Findings severity](/codehawks/findings-severity) - [The auditing process](/codehawks/the-auditing-process) ### Rate a Finding ## Overview Users can rate findings on a scale of 1 to 5 stars. "Findings rated by you, will show with the rating you've given." Community-based ratings appear for unrated findings, weighted by user credibility scores. ## Rating Calculation System The platform uses a weighted formula where each user's rating contribution is multiplied by their performance score, representing "their auditing performance across multiple platforms." **Formula Components:** - User scores reflect verified audit history - Higher-scored users have greater influence on final ratings - Community suggestions combine to create consensus scores ## Example Application Two users demonstrate the system in action: - User A (score: 2500) suggests 2 stars - User B (score: 7000) suggests 5 stars The calculation weights User B's input more heavily due to their superior track record, resulting in a final score closer to 5 than to 2. ## Key Principle "Ratings from users with higher scores have more weight in the final calculation of the score," ensuring experienced auditors shape community assessments. ## Related Resources - [Search for a finding](/solodit/search-for-a-finding) - [Add new finding](/solodit/add-new-finding) - [Rate a bounty](/solodit/rate-a-bounty) - [Findings validity](/codehawks/findings-validity) - [How Payouts Work](/codehawks/how-payouts-work) ### Add New Finding **Updated over a year ago** ## Overview Solodit welcomes contributions from auditors and auditing firms. The process involves forking a GitHub repository, preparing assets, formatting reports, and submitting a pull request. ## Step 1: Fork the Repository Navigate to the [Solodit Content GitHub repository](https://github.com/solodit/solodit_content/tree/main) and click the fork button in the top right corner. Clone your fork locally: ``` git clone https://github.com/your-user-name/solodit_content.git ``` Within the cloned repository's reports folder, create a new subfolder named after your audit firm or auditor profile. ## Step 2: Prepare Logo Assets Include two PNG logo files: **logo_256_256.png** - Appears in search results and finding detail pages - Specifications: 256px × 256px, transparent background **logo_450_225.png** - Displays on the Solodit landing page - Specifications: 450px × 225px - Brand name positioned on the right side - Colors: background #292634, logo #BBBABD, text #BBBABD ## Step 3: Format Your Reports Name report files using this pattern: `{Date}-{Protocol}.md` Structure each report with: - **Auditor details** at the beginning - **#Findings** header marking the start of findings - **Severity classifications**: High Risk, Medium Risk, Low Risk, Gas Optimizations, Informational - **Finding titles and content** organized under severity headings Use this template structure: ``` **Auditors** [Name](twitter-link) # Findings ## High Risk ### Finding Title [Content] ## Medium Risk [Continue pattern...] ``` ## Step 4: Submit Your Contribution Push your completed folder to your fork and [create a pull request](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/creating-a-pull-request). A Solodit team member will review and provide guidance if needed. ### Tags List and Descriptions ## Overview This Cyfrin Help Center article provides a comprehensive glossary of security-related terminology used in smart contract auditing and blockchain development. The resource contains alphabetically organized tags with detailed descriptions of vulnerabilities, standards, protocols, and technical concepts. ## Content Structure The article is presented as a large reference table with two columns: | **Title** | **Description** | |-----------|-----------------| ## Key Categories Covered **Vulnerability Types:** - Access control and authentication issues - Reentrancy and gas-related exploits - Data validation and exposure risks - Arithmetic errors (overflow/underflow) **Token Standards:** - ERC20, ERC721, ERC1155, ERC777 - EIP-4626 (Tokenized Vaults) - EIP-712 (Typed Structured Data) **Blockchain Concepts:** - Layer 2 solutions (Arbitrum, Optimism, zkSync) - Cross-chain communication - Oracle mechanisms **DeFi Protocols:** - Aave, Uniswap, Chainlink - Flash loans, liquidation processes - Vault and staking mechanisms ## Notable Entries The glossary includes definitions ranging from foundational concepts like "EOA" (Externally Owned Account) to specific vulnerabilities such as "First Depositor Issue" and "Share Inflation." **Related Resources:** The article links to supplementary guides on audit competitiveness, finding severity classifications, and proof-of-concept documentation. ### What is a Bug Bounty Program? ## Overview A bug bounty program represents "a monetary reward offered by software developers, websites, and organizations to ethical hackers" for reporting vulnerabilities. The primary objective involves uncovering security flaws before malicious actors can exploit them. ## How Bug Bounties Work These programs operate by incentivizing vulnerability discovery. Security researchers worldwide participate to identify and report issues in exchange for compensation and recognition. Once discovered, organizations verify vulnerabilities and award bounties based on severity and report quality. Programs may be public (open participation) or private (invitation-only). Many organizations maintain "Hall of Fame" pages acknowledging researcher contributions. ## Key Benefits Organizations gain access to diverse security talent pools, enabling faster vulnerability discovery than internal teams alone. Programs prove cost-effective since "the organization only pays when a valid vulnerability is found," reducing expenses compared to full-time security staff hiring. Additional advantages include: - Enhanced security through diverse researcher perspectives - Reputation strengthening via proactive vulnerability management - Regulatory compliance support through systematic vulnerability identification ## Program Structure 1. **Scope** — Defines testable systems and assets 2. **Disclosure Policy** — Outlines reporting procedures 3. **Rewards** — Monetary compensation based on severity 4. **Resolution & Feedback** — Protocol response and guidance 5. **Leaderboards & Recognition** — Public contributor acknowledgment ## Solodit Aggregator Solodit consolidates Web3 bug bounty platforms, enabling auditors to rate, comment on, and track programs across multiple platforms free of charge. ### Search for a Bounty ## Overview Solodit consolidates **bug bounties from multiple web3 platforms** into one searchable database, allowing users to filter and narrow results efficiently. ## Search Fields The bounty finder offers four primary filtering options: - **Keywords**: Search using specific terms or phrases to refine findings - **Platform**: Restrict results to Immunefi or Hats Finance - **Language**: Filter by programming languages (Solidity, Vyper, or Rust) - **Category**: Organize by protocol type (Lending, NFT Marketplace, Oracles, Liquid Staking, Gaming, and others) ## Bounty Viewer Results appear in a table format displaying available bounties. Users can: - Sort results by any column - Click entries to access the official bounty posting - Review consolidated details from multiple sources in one location ## Related Resources - [Search for a finding](/solodit/search-for-a-finding) - [Tags List and Descriptions](/solodit/tags-list-and-descriptions) - [What is a Bug Bounty Program?](/solodit/what-is-a-bug-bounty-program) ### Rate a Bounty ## Rating System Users can assign 1-5 stars to any finding. "Bounties rated by you, will show with the rating you've given." Unrated bounties display community-generated ratings that update as more people participate. ## How the Rating is Calculated The system uses a weighted formula where user reputation influences scoring impact. According to the guide, "Ratings from users with higher scores have more weight in the final calculation of the score." ### The Formula The final bounty rating combines: - **User scores**: Individual reputation metrics within the platform - **Suggested scores**: Star ratings (1-5) each user provides ### Example Calculation The documentation illustrates this with two hypothetical raters: - User A (reputation: 2500 points) suggests 2 stars - User B (reputation: 7000 points) suggests 5 stars User B's rating carries greater influence due to higher reputation, resulting in a final score weighted toward their suggestion. This incentivizes quality assessments from experienced community members while still incorporating broader feedback. --- **Related Articles:** - [Rate a finding](/solodit/rate-a-finding) - [What is a Bug Bounty Program?](/solodit/what-is-a-bug-bounty-program) - [How Payouts Work](/codehawks/how-payouts-work) ### Managing Your Notes ## Overview This guide explains how to access and organize notes within Cyfrin's Solodit platform. ## Steps to Access Notes 1. Navigate to your account dropdown in the top right corner 2. Select **notes** from the menu ## Managing Notes Users can manage existing notes through the left-side panel. New notes are created by clicking the "New Note" icon in the upper left area. The interface displays a note creation page where users can work with their content. ## Formatting Support "Solodit's notes feature supports Markdown formatting! Be sure to structure your notes as nicely as you'd like." ## Saving Your Work Once you've finished editing or creating a note, save your changes by clicking the **Save** button located in the lower right corner of the interface. ## Related Articles - [Change your password](/profiles/change-your-password) - [Add and Edit Your Profile Info](/profiles/add-and-edit-your-profile-info) - [Adjust Your Profile Settings](/profiles/adjust-your-profile-settings) - [Opt-in to beta updates](/profiles/opt-in-to-beta-updates) - [Formatting Your Notes](/solodit/formatting-your-notes) ### Formatting Your Notes ## Overview The Cyfrin Solodit platform supports Markdown formatting for note-taking purposes. Users can reference the Markdown Guide for basic syntax recommendations. ## Key Information **Supported Format:** "Cyfrin's Solodit platform supports Markdown formatting for your note taking needs." **Resource:** The help article directs users to https://www.markdownguide.org/basic-syntax/ for comprehensive guidance on leveraging Markdown syntax when composing notes within Solodit. ## Related Articles - [Add and Edit Your Profile Info](/profiles/add-and-edit-your-profile-info) - [Add new finding](/solodit/add-new-finding) - [Findings severity](/codehawks/findings-severity) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [Managing Your Notes](/solodit/managing-your-notes) --- **Last Updated:** Over a year ago **Collection:** Notes > Solodit ### Aggregated Leaderboard ## Overview The Solodit Leaderboard presents "a clear, aggregate, ranked display of auditors's performances across 3 competitive audits industry leading platforms": - CodeHawks - Code4rena - Sherlock DeFi ## Key Features **Platform Filtering** The leaderboard includes filter options at the top, allowing users to examine top-performing auditors on individual platforms. This enables comparison across the three major audit competition venues. **Purpose** The tool serves auditors by providing visibility into how "their performance stacks up against their peers or across platforms." ## Related Resources - [What is a Cyfrin profile?](/profiles/what-is-a-cyfrin-profile) - [Findings severity](/codehawks/findings-severity) - [What is a CodeHawks First Flight?](/codehawks/what-is-a-codehawks-first-flight) - [What are Cyfrin Eagles?](/codehawks/what-are-cyfrin-eagles) - [How to Become an Eagle](/codehawks/how-to-become-an-eagle) --- *Article updated over a year ago | Collection: Leaderboard → Solodit*