Okay… we actually built it 😂
Been building our version of a Web3 security contest for 2026 for a while now.
And ngl… I’m pretty happy with where it landed.
You don’t just throw 100 auditors at the same code and hope for the best.
You get coverage to own.
Good work actually follows your name.
And when the contest ends, the review doesn’t just become history.
So… auditors 👀
Would you actually join a contest run like this?
@shibi_kishore Bro collecting duplicates like Pokémon at this point 😭
We need you at POA 😂
At least come fight for a spot on the leaderboard instead of fighting “internal duplicate vs Immunefi duplicate” lore.
https://t.co/rabco0E6ao
🎯 WHY WE'RE BUILDING THIS
I'm not trying to build another audit company.
I want to make it really damn hard for unaudited code to quietly reach user funds.
Tomorrow we go again.
Day 1/∞.
#BuildInPublic#Web3Security#DeFiSecurity
🧠 DAY 1 LESSON
I don’t need to explain our features better.
I need to explain what they actually do for the protocol.
Instead of saying:
→ 4× coverage
→ Audit Passport
→ Function-level attribution
→ Auditor reputation
→ Live-code verification
I need to say:
→ Which user funds are still exposed
→ Where audit money may have left gaps
→ Whether today’s live code is actually covered
→ What changed after the last audit
→ What needs reviewing before it becomes an expensive problem
Founders don’t care about the feature name.
They care about:
Keeping user money safe.
Avoiding another unnecessary full audit.
Protecting their treasury, users, and reputation.
That’s the pitch.
📨 THEN SALES HUMBLED ME 😂
Protocols contacted:
19
Replies:
1
The other 18 audited my ego for free.
No findings.
Just silence.
But those 18 non-replies taught me something important.
I was pitching:
→ 4× coverage
→ Audit Passport
→ Function-level attribution
→ Auditor reputation
→ Live-code verification
Cool features.
Wrong opening.
Because nobody wakes up thinking:
"Damn, I really need function-level auditor attribution today."
A founder has a much simpler question:
“I already paid for audits. What am I STILL exposed to?”
That is the question POA needs to answer first.
🐛 THEN WE FOUND SOMETHING
We went deeper into uncovered code from one protocol.
Found:
🚨 1 High
🟡 2 Lows
Keeping the protocol unnamed while disclosure is handled.
This was probably the biggest validation of Day 1.
The protocol already had security history.
But there was still live code outside the audit coverage we could actually prove.
Having audits ≠ every line running today was audited.
🔎 THE GAP
We picked 3 protocols and asked one simple question:
Does the code protecting users TODAY match the code auditors actually reviewed?
So we traced:
Audit → audited commit → current code → live deployment
Then asked:
What changed in between?
That’s the gap.
DAY #1 OF BUILDING PROOF OF AUDITS IN PUBLIC 🫡
Until DeFi attackers start protesting to get us shut down.
Today:
🔎 3 protocol gap reviews
📨 19 cold DMs
👋 1 reply
🐛 1 High + 2 Lows found
Not a bad first day.