Explore the World's Best Ideas
Join today and uncover 100+ curated journeys from 50+ topics. Unlock access to our mobile app with extensive features.
Alright, so hereâs the deal: today, weâre still diving into Web3 security marketplaces, but focusing on Cantina.
Now, if youâre wondering, "What the heck is Cantina?" â think Code4rena or Omniscia, but with its own twist.
And no, itâs not an NFT marketplace.
Itâs a Web3 security marketplace, okay?
Basically, itâs a platform where organizations can book custom security services, and security researchers can do reviews.
Shoutout to Spearbit for incubating it.
To understand Cantina, weâre break
ing it down:
2
2 reads
Cantina Services: What they offer (security reviews, competitions, bounties, guides, etc.).
Cantina Code: A platform for code reviewers and clients to communicate, schedule, and sort out logistics.
Cantina Accounts & Reputation: This is for clients and researchers to manage projects, make payments, and build careers.
Cantina Referral Programs & Competitions: Opportunities for both companies and researchers.
Cantina basically makes it easier for security researchers and companies to connect, optimize code reviews, and communicate effectively.
2
0 reads
Imagine it like hiring a security team for your houseâyou want them to protect every room, but youâre too paranoid to give full access.
Thatâs where Cantina steps in, ensuring trust and better collaboration.
So, yeah, Cantina is here to make Web3 security seamless.
Letâs get into what theyâve got to offer.
yunno, hereâs the gist: Cantina Code is for both researchers and companies.
Simple, right?
For security researchers, Cantina Code is like their HQ.
2
0 reads
Itâs the interface where they can submit findings, chat with teammates, and talk to clients.
Think of it as their secret lab, but with tabs and settings to make everything smooth.
Now, letâs talk features (yeah, weâre going there):
Type Tab: Is it a public competition? A collaborative review? This tabâs got you covered.
Status Tab: This tells you whatâs going onâlive, judged, completed, escalated, whatever.
Time Frame: Wanna know how long the engagement lasts? Boom, right here.
2
0 reads
User Role: Are you a lead? A team member? This defines whoâs doing what in the repo.
Thereâs more, but letâs keep it light because tabs and details can be... a lot.
If youâre craving all the techy bits, just head over to Cantina Docs
Itâs got everything laid out for you, including those nitty-gritty details about tabs and settings.
So, yeah, Cantina Code is basically here to make life easier for researchers and companies, ensuring everyoneâs on the same page.
Alright, letâs break down Cantina Competitions (not "container competitions"âgotta get the names right).
2
0 reads
So, these are basically time-based code review battles.
Researchers compete to find the most valid vulnerabilitiesâlike a digital treasure hunt but with bugs instead of gold.
The companies, on the other hand, present the Researchers with top valid findings with tangible benefits like payouts, and bragging rights while receiving better security.
Now, these competitions run on Cantina Code (we already talked about this earlier)
Itâs that fancy tech that makes communication between clients and researchers seamless, filtering out spam, and optimizing everything using ML (machine learning)...
2
0 reads
...and manual reviews.
Plus, it helps researchers submit vulnerabilities easily.
Whatâs the point of Cantina competitions?
Itâs all about making blockchain security stronger.
Researchers also get a reputation boost, career opportunities, and more secure codebases to brag about.
Basically, everyone wins.
Oh, and thereâs this tweet from Hari who mentioned that SpearBit (the incubators of Cantina) recruit the top 10 competitors from Cantinaâs leaderboard twice a year.
2
0 reads
So yeah, winning these competitions can literally open career doors.
How to join Cantina competitions:
1. Create a researcher account.
2. Join their Discord server.
3. Check out these four tabs:
Finding Submission (how to submit findings).
Finding Format (make it readable, people!).
Judging & Severity Criteria (how findings are scored).
Payments (aka the fun part).
All the juicy details are in Cantina Docs, so check that out for the full scoop.
2
0 reads
Payments Process:
Planned: Your payment is in line to be scheduled.
Scheduled: Itâs queued for processing in the next batch.
Submitted: Itâs waiting for signatures (multi-sig wallets, yay).
Executed: Payment is done. Moneyâs on-chain. Congrats!
Disputed: Uh-oh. Something went wrong; itâs under review.
Cancelled: Itâs gone. Bye-bye payment.
2
0 reads
The usual flow is: Planned â Scheduled â Submitted â Executed.
Sometimes itâs: Planned â Scheduled â Disputed (and then back to the start).
And if the gods arenât smiling: Planned â Scheduled â Cancelled or so (haven't experienced that đ)
So yeah, thatâs how Cantina Competitions work.
Itâs like a chaotic yet rewarding rollercoaster for researchers.
Alright, letâs wrap up Cantina with its features and services. Ready?
So, account claiming is a thing in Cantina.
2
0 reads
Hereâs the deal: someone could open an account for you using your email (donât ask why).
You can swoop in, claim that account using said email, and change the password.
Have I tried it? Nope.
This is all âresearch modeâ with zero hands-on experience.
But hey, now you know.
Services Cantina Offers:
1. Security Reviews
This is for companies (or anyone building on Web3) who want their projects checked for vulnerabilities.
2
0 reads
The company reaches out to Cantina for a security review.
Cantina picks a team of top-tier researchers under their brand to carry out the review.
Why? Because Cantinaâs reputation is on the line, and they arenât about to hand over a subpar team.
So, if youâre a Web3 builder and need a solid security review, Cantinaâs got you.
2. Cantina Competitions
This is like a turbocharged version of a review.
Itâs for mass-scale code reviews.
Think of it as a Web3 talent hunt for the best researchers.
2
0 reads
A company puts up a prize, and researchers compete to find vulnerabilities.
Itâs all powered by Cantina Code, ensuring high coverage and top-notch results.
Bonus: This helps Cantina discover hidden talents in the space.
3. Bug Bounties
Okay, so bug bounties sound a lot like competitions, right?
Same vibe but slightly different.
While competitions feel like an open battlefield, bug bounties are more focused.
Itâs about tapping into Cantinaâs vast network of researchers for specific goals.
2
0 reads
Cantina claims their bug bounties have âhigher signalâ programs across Web3.
Whatever that means, it sounds fancy.
4. Public Good Reviews
This oneâs unique. Hereâs the gist:
Itâs for open-source projects that benefit everyone globally.
No one pays Cantina for this.
Instead, it relies on crowdfunding.
Think of it as the community chipping in to support researchers who secure these projects.
2
0 reads
Itâs all about giving back to the ecosystem, no strings attached (except maybe a pat on the back or a âthank youâ).
Need my wallet address?đ
0x943947Ee36c661A250431E77E12217B5177c896c
E(RC 20)
Danke!
Cantinaâs Playground Vibe:
Basically, Cantina is like a massive Web3 security hub.
Companies roll in, request reviews, and Cantina gathers different âbrandsâ of security researchers to get the job done.
Every researcher/team brings their unique quality standards, ensuring thorough code reviews.
2
0 reads
With their competitions, bug bounties, and all-star researcher lineups, Cantina is aiming to be the go-to for securing Web3 projects.
Itâs definitely setting itself apart from other marketplaces.
Umm, thatâs Cantina in a nutshell.
Itâs not just a Web3 security platformâitâs the stage, the talent scout, and the referee.
Thank you for sticking around 𫡠đŤ°.
2
0 reads
IDEAS CURATED BY
CURATOR'S NOTE
Lowkey hyped to be called up by Cantina Company or any of their stakeholders. Canât wait for that call!
â
Similar ideas
Read & Learn
20x Faster
without
deepstash
with
deepstash
with
deepstash
Personalized microlearning
â
100+ Learning Journeys
â
Access to 200,000+ ideas
â
Access to the mobile app
â
Unlimited idea saving
â
â
Unlimited history
â
â
Unlimited listening to ideas
â
â
Downloading & offline access
â
â
Supercharge your mind with one idea per day
Enter your email and spend 1 minute every day to learn something new.
I agree to receive email updates