CODESPECT Launches SpecSiege Audit Contest Platform for Web3 Security
Key Takeaways
- •SpecSiege is designed as a closed re-audit process for Web3 protocols after CODESPECT completes an initial audit.
- •Each contest is limited to as many as 50 vetted researchers, split between CODESPECT leaderboard participants and new applicants.
- •The platform uses fixed reward pools and severity-weighted scoring rather than per-finding billing.
- •The first completed contest reviewed an ERC-6909 bond platform, with payout details published on the SpecSiege website.
- •CODESPECT says SpecSiege excludes automated or AI-generated submissions and focuses on human-led security analysis.

Blockchain security firm CODESPECT has launched SpecSiege, a competitive audit contest platform built to add a second layer of review for Web3 protocols after their initial security assessments. The platform, which has already completed its first contest, is presented as a curated alternative to open bug-bounty programs by connecting selected security researchers with production codebases in a controlled competitive setting.
According to CODESPECT, SpecSiege functions as a closed-circle re-audit mechanism. After the company completes its standard audit of a protocol, the fixed codebase is made available to a vetted group of up to 50 researchers, who compete for a predetermined reward pool. The structure is designed to provide protocols with an independent second opinion at a fixed cost, while keeping findings confidential unless the protocol decides to disclose them.
That added review layer is particularly relevant for Web3 projects because deployed smart contracts can be difficult to modify and may directly control user assets or protocol logic. Audit contests have become one way for teams to broaden review beyond a single audit firm, but open contests and bug-bounty programs can vary widely in participant quality, disclosure process, and cost predictability.
The inaugural contest, centered on an ERC-6909 bond platform, has concluded. ERC-6909 is an Ethereum token standard for managing multiple token types within a single contract, making implementation details important for systems that depend on precise accounting. Results and payout distributions are publicly available on the SpecSiege website. Top performers in the first cohort received rewards ranging from approximately €118 to €3,902, depending on the severity and number of findings submitted.
1/4 The new SpecSiege website is live. Our audit contest platform is built to connect security researchers with real-world Web3 protocols. Every finding strengthens production systems before attackers get the chance. First contest: Completed pic.twitter.com/lQIc5M7aUz — CODESPECT (@CODESPECT) July 27, 2026
Curated Cohorts and Fixed Reward Pools
SpecSiege differs from conventional audit contests through its selective participation model. Instead of allowing unrestricted public participation, CODESPECT limits each event to 50 researchers. Half of the cohort is sourced from the company’s internal leaderboard, while the other half comes from new applicants.
CODESPECT describes this mix as an effort to balance proven expertise with “fresh eyes,” saying that new perspectives can be especially valuable when identifying edge-case vulnerabilities. The company says this approach is intended to maintain quality while still giving new researchers access to real-world Web3 codebases.
The platform also uses a fixed-pot model rather than traditional per-finding billing. This allows protocols to set their security-review budget in advance without being exposed to variable costs. Researchers apply through a unified account system, submit findings privately during the contest window, and are judged live by a lead judge. Payouts are then distributed according to a severity-weighted points system.
CODESPECT says SpecSiege excludes automated or AI-generated submissions and focuses on human-led security analysis. As more contests are opened, the company aims to create a standardized pipeline for post-audit validation, giving protocols an additional public double-check while offering researchers structured opportunities to demonstrate their skills in competitive audits. For teams evaluating the model, the key details to watch will be the number and type of future contests, the consistency of judging and payout disclosures, and whether curated participation can maintain enough researcher coverage across different protocol designs.