Quick Answer
Code4rena runs fixed-window contests where wardens compete on the same scope, and duplicate findings split the payout. Whoever maps the codebase fastest gets more shots at being the first unique reporter.
A sponsor publishes scope (which contracts, which commit, sometimes known issues out of scope) and a prize pool split across severity tiers. Wardens submit findings during the contest window; after it closes, an independent judge reviews everything, resolves duplicates, and finalizes severity. High and medium severity findings get real payouts; QA and gas findings get smaller, separate pools.
Read the scope doc first, always
Known issues and out-of-scope contracts are explicitly listed — submitting on something the sponsor already flagged wastes a submission slot for nothing.
Scan every in-scope contract on day one
Get a function inventory and pattern-hit list across the whole scope before you pick where to specialize. Contests reward breadth of coverage early, depth later.
Flag anything that deviates from standard library code
Custom accounting, custom access control, anything that isn't a straight OpenZeppelin import is where contest-winning findings actually live — a scan surfaces those files faster than manually skimming a 4,000-line diff.
Pick your lane and go manual
Once you know which 2-3 contracts have the unusual logic, that's where you spend the rest of the contest. The scan's job ends there.
Most wardens don't lose because they missed a bug entirely — they lose because someone else reported the same bug first, or reported it with a clearer write-up. Time spent re-deriving a function inventory that a scanner gives you instantly is time not spent getting your report in early and well-written.
This matters most in the opening hours, when the whole scope is unfamiliar and every warden is doing roughly the same manual mapping work in parallel.
Larger Code4rena contests span a dozen or more contracts with real interdependencies. Scanning file by file as they're pushed to the repo (or pasted individually) still beats reading the whole diff cold — you get a working map of what each contract actually does before you start tracing calls between them by hand.