what's cantina?
Cantina is a web3 security marketplace and platform specializing in smart contract audits, bug bounty programs, and code review competitions for blockchain projects. It enables crowdsourced security research by hosting high-reward competitions, such as those for Ethereum upgrades and protocols like Uniswap and EigenLayer, distributing millions in USDC to researchers. Key features include incident response services, high-touch audits, and tools for vulnerability discovery across DeFi and infrastructure codebases. The platform emphasizes transparency, rapid triage of issues, and collaboration with top crypto teams to secure on-chain assets and prevent exploits.
Cantina published a practical RWA security guide with Centrifuge, covering financial and admin security.
Links
x.com/cantinaxyzPublished a practical RWA security guide in collaboration with Centrifuge covering financial correctness, admin power constraints, continuous security, and offchain trust boundaries.
CEO presenting in Coinbase Security Series Episode 12 on December 20, 2025 at 1pm ET on the topic of launching effective onchain bug bounty programs.
Cantina integrates SEAL Safe Harbor into its bug bounty platform, providing legal frameworks for front-running active exploits to enable whitehats to rescue funds.
Cantina participates as a partner in Solana Consumer Day, a small-format gathering for founders and builders developing Solana's next-generation consumer applications.
Redstone launches a $250,000 bug bounty program on the platform for their multi-chain infrastructure that secures over $10B in DeFi markets and powers oracles for 80+ protocols.
Cantina and HypernativeLabs release a guide for protocols, foundations, and institutions on responding to security threats.
Mento Labs audit competition goes live with a $60,000 prize pool running through December 18, focusing on Mento V3's new AMM design with Fixed-Price Market Maker pools and programmatic rebalancing.
Uniswap's $15.5M bug bounty program on Cantina, described as the largest in DeFi, expands its scope to include the Protocol Fees repository.
Security audits for CapricornDEX are complete, with one engagement on CL pool core and oracle behavior, and another on pAMM pricing engine and pool contracts.
Cantina announces upcoming collaboration with Monad blockchain.
Cantina becomes a founding member of the Bitcoin Security Council, a new initiative by Midl_xyz focused on improving security standards for Bitcoin-based applications.
Cantina collaborates with Automata Network to secure verifiable AI agents using ERC-8004 framework, TEE-attested agents, and DCAP Attestation technology.
Cantina completed a $4M rescue operation for an unspecified project, marking a significant security incident response with quantified financial impact.
Cantina completed independent smart contract audits for HyperLend's contracts, with audit reports published on HyperLend's security page.
Cantina provided security consultation to Berachain during an active exploit response on their BEX pools, working alongside Zeroshadow, Zenith, and Seal 911 to help address the vulnerability and implement protective measures.
Cantina partners with Tadle, a Chainlink-incubated modular onchain execution system, to secure the parallel sandbox layer for Monad dApps through isolated invocations and entailment-based permissioning.
A partner announces collaboration with Cantina to secure IP programmability infrastructure, including validator execution, licensing coordination, and attribution logic systems that automate how intellectual property is licensed and monetized.
Cantina completes smart contract audit for Bond's Artist Token contracts, covering onchain vault integration and yield redemptions infrastructure.
Cantina becomes an official BNB Chain Kickstart Program service provider, offering smart contract audits, incident response, bug bounty programs, and crowdsourced competitions to organizations building on BNB Chain.
Cantina participates in Hack Seasons Singapore event alongside Mastercard, Mercuryo, and Babylon Labs to examine barriers to mainstream crypto adoption.
Cantina partners with Hypernative Labs to provide Managed Detection and Response (MDR) services, where Hypernative alerts teams to threats and Cantina neutralizes them.
Polygon's Agglayer launches a $1,000,000 bug bounty on the platform for its cross-chain infrastructure, now live for public review.
Monad includes select Cantina auditors in its airdrop eligibility as impactful crypto contributors, with deadline November 3, 2025.
Bounty platform pays out $10,000 to prominent security researcher el_hajin, demonstrating operational traction with high-value security contributions from experienced professionals.
Participates in SVM Summit 2025 in Singapore alongside Bank of Singapore and global partners including Reown, WalletConnect, and Vishwa_xyz to discuss how SVM is powering the future of global finance.
Launches Cantina Incident Command, a security incident response tool that logs all actions for accountability, compliance, and post-breach analysis.
Hiring security researchers to join their network for smart contract and protocol audits, seeking candidates experienced in Solidity and EVM vulnerabilities.
Adds SEAL Safe Harbor legal protections to bounty platform, enabling white hat researchers to participate in active exploit prevention without legal concerns.
Audit remediation reaches 66.6% completion with mainnet launch approaching. Community events and partnership campaigns are actively ongoing.
Publishes research article on sBridge, an SVM-native secure bridging solution featuring canonical PDA intents, on-chain replay protection, and guardian quorum attestations.
Launches new LockToVote Plugin to extend governance capabilities across the industry following collaboration with security researchers.
Partnership announced for SVM Summit in Singapore on October 2nd alongside WalletConnect and reown_, featuring institutional participation from Bank of Singapore.
Platform reports 3,130 vulnerabilities detected with $1.68M in researcher payouts and 534 new contributors.
Security researcher discloses smart contract vulnerability through bounty program; emergency response team successfully secures at-risk funds across 3 chains with no losses.
Third-party security audit of V3 vault mechanics completed, advancing institutional-ready infrastructure.
Active recruitment of Security Architects to bridge institutional DeFi security standards, expanding security infrastructure.
Platform releases unified organization profiles featuring verified identity and security metrics tracking.
Security review completed for Lorenzo Protocol partnership, focusing on stablecoin yield product with NAV updates and token routing.
Largest bounty payout to date ($100K) awarded to security researcher for continued work.
$5M bug bounty program launches for onchain products and Base smart contracts.
Security review completed for Angstrom DEX's Uniswap v4 hook implementation, focusing on LVR mitigation and MEV protection.
Security review completed for Superform partnership, covering router and vault deployment systems with cross-chain interactions.
Technical security review concludes for Infrared Finance partnership, focusing on consensus layer implementations.
Security researcher earns $75,000 bounty for technical contribution, demonstrating ongoing protocol security initiatives.
$100,000 security audit competition launches with dedicated reviewer, targeting July 2025 launch for USDaf protocol.
Security audit report released with no major issues identified in protocol review.
Security competition launched with Gauntlet USD Alpha and Aera Finance to strengthen onchain security mechanisms and strategy enforcement for Aera vaults and gtUSDa.
Security researchers reveal concerning platform policies including downgraded vulnerability severities and allowance for multiple client scams.
Web3SOC framework launches for institutional DeFi platform evaluation, partnering with Uniswap, Maple Finance, Kiln, and Steakhouse Fi, with Maple receiving highest rating in initial assessment.
Security researcher awarded $20,000 bounty for preventative security contribution.
ODXLabs security audit of zkEVM minting infrastructure identifies 13 vulnerabilities.
Security audit identifies 20 issues, differing from previous audits that found 25 and 11 issues.
Security audit reveals protocol collaboration with SeamlessFi and finds 11 issues, differing from the previous audit that found 25 issues.
Security audit reveals 25 issues in protocol; full report now public.
Major protocol upgrade Pectra successfully deployed on mainnet, enabling smart wallet programmability via EIP-7702.
$100K bug bounty program now live for identifying protocol vulnerabilities.
Record-breaking 882 participants engage in Liquity V2 development competition.
Security audit reveals 5 issues in paintswap-brush-token implementation.