description |
---|
Cyfrin CodeHawks Quick Start Guide for Auditors |
Welcome to Cyfrin CodeHawks! Here's a quick and easy guide to get you started as an auditor and submit your first vulnerabilities.
First, create a new account by visiting codehawks.cyfrin.io and clicking the "sign up" button in the top right corner:
Navigate to the competitions page and look for "Live" or "Upcoming" contests:
{% hint style="success" %} Don't want to miss any of our competition announcements?
Make sure to follow us on Twitter and join our Discord server! {% endhint %}
Clicking on a competition will open its details page, with important information such as:
- Prize pool severity breakdowns
- Start and end dates
- nSLOC and scope
- Scoring
- Link to the GitHub repository (if the competition is live)
Every contest also comes with details that will help you understand:
- The codebase
- Scope
- compatibilities
- How to get the codebase up and running
New contests are announced almost every week. When you find a contest that fits your skills, click on the subscribe button to join it:
Once you've found your first vulnerability, navigate to the competition page, and click on the submit "submit a vulnerability" button:
To submit your vulnerability, you'll be asked to insert:
- Title - a <250 character descriptive title of your submission
- Severity - a matrix of likelihood and impact characterizing your finding. Read how-to-evaluate-a-finding-severity.mdfor a full explanation.
- Description - a detailed description of the vulnerability found and how to reproduce it.
Learn more on how-to-write-and-submit-a-finding.mdon the dedicated guide.
After the auditing period ends, judges will evaluate each submission carefully to determine its validity, severity, and overall quality.
Judging is done in two steps:
- Community Judging - a period where all eligible community judges can evaluate others' submissions
- Lead judging - a period where the lead judge confirms or not the community judges' decisions and issue the final pre-appeal judgments.
Every phase will be communicated on the platform and via announcements on Discord.
Learn more about the judging process.
For 48 hours following judging, appeals will be accepted to contest judgments. This period will be clearly announced across all channels.
During the 48 hours, interactions will be enabled on your GitHub submissions. During this time, you may leave comments detailing your escalation for re-assessment.
Once the final report is released, results will be announced, and payouts will be sent to the winners.
{% hint style="warning" %} Rewards are paid out in USDC through the ZKsync chain. Crediting the reward won't be possible without a ZKsync wallet connected to the user profile. {% endhint %}