Quick Answer
Cantina runs both open competitions and fixed-scope engagements with vetted researchers. Either format, the first move is the same: figure out what's actually custom in the codebase before you spend hours reading boilerplate.
Cantina competitions publish a scope and prize pool for a fixed window, judged after submissions close, similar in structure to other contest platforms. Cantina also runs invite-only fixed-scope reviews where a smaller group of vetted researchers work a codebase directly for a sponsor, without the broad open-competition format.
Confirm the scope and format
Check whether you're working an open competition (time pressure, other researchers on the same scope) or a fixed-scope review (more time, smaller researcher pool) — it changes how much orientation time is worth spending upfront.
Scan the in-scope contracts for a fast inventory
Function list, access-control modifiers, external call sites, and obvious pattern hits before you start reading manually.
Prioritize files that deviate from standard patterns
Custom logic is where competition-worthy findings come from — a scan helps you spot which files aren't just OpenZeppelin imports faster than skimming the whole diff.
Do the manual work on what's flagged as unusual
Business logic, protocol-specific invariants, and economic assumptions still need a human reading closely — the scan's job is done once it's pointed you at the right files.
An open competition has other researchers working the same scope in parallel — orientation speed matters because time spent mapping the codebase is time your competitors are also spending, and being slow to get oriented means less time on the manual work that actually finds something. A fixed-scope review with a smaller vetted group has less of that pressure, but the same underlying problem: you still need to know where the custom logic lives before you can review it carefully.