Security Budget by TVL Tier: What to Spend on Audits, Monitoring, and Bounties
Web3 security budget is not a fixed line item. It scales with TVL. A tiered framework from <$1M to $100M+ with allocation across pre-launch audit, monitoring, and bug bounty.
TL;DR
- Web3 lost $3.4B to exploits in 2025 (Chainalysis). The dominant cause is teams spending the wrong amount on security at the wrong stage.
- Security budget should scale with TVL. A reasonable framework, by TVL tier:
- Under $1M: $20-50K total. ~30% on monitoring, ~50% on a single thoughtful audit, ~20% on a small bounty.
- $1M to $10M: $50-150K. Monitoring stays material; first round of multi-firm audits begins.
- $10M to $100M: $150-500K. Continuous audits, formal verification on critical paths, larger bounty.
- $100M+: $500K-$2M+. Multi-firm competitive audits, $1M+ bounty, dedicated security engineer in-house.
- Real benchmarks: Aave allocated $1.5M for 345 days of V4 review. Uniswap V4 allocated $15.5M to its bug bounty (largest in DeFi history) plus $2.35M for competitive audits across 9 firms.
- The most common mistakes: spending the entire security budget on one audit pre-launch, then nothing post-launch. Or under-spending early when bugs are cheapest to find.
Why this matters
Most Web3 founders think of security as a single line item: "the audit". They get a quote from one firm, pay $50K-$200K, and consider security spend done.
This is the budgeting failure that produces the audit paradox: 91.96% of hacked smart contracts had been audited (covered in the Audit Paradox article). One audit is necessary. It is nowhere near sufficient.
Security budget is not "the audit". It is a portfolio of investments across audit, monitoring, incident response, key management, and bug bounty. The right portfolio shifts as TVL grows. Founders who think in tiers spend more efficiently and ship more securely.
If you're a founder budgeting for the next 12 months, this article is the framework to copy.
The four TVL tiers
These are guidelines, not rules. Adjust for risk profile (a stablecoin needs more security per dollar of TVL than a yield aggregator; a custodian of long-duration locked assets needs more than a per-block AMM).
Tier 1: Under $1M TVL ($20-50K security spend)
You are pre-product-market-fit. Most exploits at this stage are total-loss; the protocol doesn't survive a $500K hack.
Allocation:
- Monitoring + pause: $5-15K. Highest-ROI investment. Set up alerts on TVL drops, large unusual transfers, oracle deviations. Implement a pause function. Covered in the monitoring-beats-first-audit article.
- One thoughtful audit: $15-30K. A small firm or independent auditor reviewing your codebase before mainnet. Don't pay for a brand; pay for engagement quality. Read the audit report sample before hiring.
- Small bounty: $5K. Set up an Immunefi listing with a small payout. Even a $5K bounty filters drive-by exploit reporters. Real bug researchers will engage if your code is interesting.
What you skip at this tier:
- Multi-firm audit. Diminishing returns when the protocol is small and code is fresh.
- Formal verification. Expensive, slow, valuable only on stable critical paths.
- Dedicated security engineer. You can't afford it.
Tier 2: $1M to $10M TVL ($50-150K security spend)
You have product-market fit. The protocol is real. An exploit at this TVL is painful but survivable.
Allocation:
- Monitoring + pause: $20-40K. Upgrade to professional monitoring (Forta, Hexagate, Tenderly Alerts). Onboard an incident response retainer with a firm.
- Two-firm audit: $40-80K. Two different audit firms, one comprehensive, one focused on a specific subsystem. The diversity catches what one firm misses.
- Bounty: $10-30K. Increase the Immunefi payout to attract serious researchers. The bounty cap should be at least 5% of TVL.
What you skip:
- Continuous audits. Save for higher tier.
- $1M+ bounties. Out of reach.
Tier 3: $10M to $100M TVL ($150-500K security spend)
You are an established protocol. Exploits at this scale make the news. The cost of bad PR alone justifies higher spend.
Allocation:
- Continuous audit relationship: $60-180K. Hire a firm on retainer. They review every meaningful PR, not just full releases. Critical for protocols that ship code regularly.
- Formal verification on critical paths: $30-100K. Hire Certora, Runtime Verification, or equivalent. Apply formal proofs to the highest-value invariants (solvency, liquidation correctness, oracle integrity). Not full coverage; targeted.
- Monitoring + IR + war-game: $40-100K. Quarterly war-game exercises with the IR firm. Pre-rehearsed playbooks beat ad-hoc response.
- Bounty: $30-100K cap, scaling. Immunefi listing with payouts up to 5-10% of TVL.
- Dedicated security engineer (part-time): optional, $50-150K annualized. If you ship code weekly, in-house security review on every PR is more cost-effective than continuous external audit alone.
Tier 4: $100M+ TVL ($500K-$2M+ security spend)
You are blue-chip DeFi. Exploits here move markets, set policy, and define the news cycle. The protocol's continued existence depends on multilayered defense.
Allocation:
- Multi-firm competitive audits: $200-800K per major release. Multiple firms reviewing the same code in parallel, plus a competitive audit (Code4rena, Sherlock, Cantina) for adversarial coverage. Uniswap V4's $2.35M across 9 firms is the canonical example.
- Continuous formal verification: $200-500K. Critical paths under formal proof, with proof artifacts maintained as the code evolves.
- In-house security team: $300K-$1M+ per year. At least one senior security engineer; ideally two.
- Mega bounty: $500K-$15M+. Uniswap V4's $15.5M is the upper bound. The bounty cap should be at least 10% of TVL or $1M, whichever is larger.
- Comprehensive monitoring + IR: dedicated tooling, 24/7 coverage, pre-rehearsed war-rooms.
How allocation shifts as TVL grows
The shape of the spend changes meaningfully across tiers:
| Allocation | Tier 1 (<$1M) | Tier 2 ($1-10M) | Tier 3 ($10-100M) | Tier 4 ($100M+) |
|---|---|---|---|---|
| Pre-launch audit | 50% | 50% | 30% | 20% |
| Continuous audit / FV | 0% | 5% | 25% | 30% |
| Monitoring + IR | 30% | 25% | 25% | 15% |
| Bug bounty | 10% | 15% | 15% | 25% |
| In-house security | 0% | 0% | 5% | 10% |
| Other (war-games, training) | 10% | 5% | 0% | 0% |
The pattern: at small TVL, spend on the foundational audit. At large TVL, spend dominates by bounty (which scales with what attackers could steal) and formal verification (which prevents whole bug classes).
Real benchmarks
Aave V4 review
For the V4 release, Aave allocated approximately $1.5M for 345 days of formal review across multiple firms. This is roughly tier-3 spend on a tier-4 protocol; Aave's parent V3 has multi-billion TVL. The aggressive review reflects that V4 is a new architecture, not a small update.
The lesson: the appropriate spend isn't just TVL-determined. Architectural changes warrant higher review per dollar of TVL than incremental updates.
Uniswap V4 launch
Uniswap V4's full launch security stack:
- $2.35M competitive audits across 9 audit firms (multi-firm coverage of the same code, with explicit firm-vs-firm contest dynamics).
- $15.5M bug bounty on Immunefi (largest in DeFi history at launch).
- Formal verification on critical paths (Certora).
- Long pre-launch review window with internal security team.
Total: roughly $20M+ on security for a single major release. Uniswap V3 had $30B+ TVL; V4 was forecast to absorb most of that. At those numbers, $20M security spend is approximately 0.07% of TVL, which is conservative.
Mid-cap benchmarks
Protocols in the $50-500M range typically spend $250K-$1M annually. The variation is mostly driven by code velocity (protocols shipping weekly need continuous audit; protocols shipping quarterly can use point-in-time audits more cost-effectively).
Common mistakes
Mistake 1: spending the entire budget on one audit
Founder gets $200K from VC, spends $180K on a comprehensive audit pre-launch, has $20K left for everything else. Six months later, they've shipped three new features, none of which are audited, and their monitoring is a hand-rolled Discord bot.
The audit caught what existed at the time. The new code didn't exist at the time. Result: bugs ship in unaudited code, and the protocol joins the 91.96% of hacked-and-audited statistics.
The fix: never spend more than 50% of annual security budget on the pre-launch audit. Reserve the rest for monitoring, IR, continuous review, and bug bounty.
Mistake 2: under-spending in tier 1
Founder thinks "we don't have $20K, we'll skip the audit". They ship un-audited code. They get a small exploit (a few hundred thousand dollars). They spend $50K on incident response, lose 80% of users to the news, and the protocol dies.
The $20-50K tier 1 spend isn't optional. It's the cost of operating a financial protocol. If you can't afford it, don't ship.
Mistake 3: skipping monitoring
Founder spends on the audit, ships, then doesn't notice when something starts leaking. Ronin Bridge lost $624M; the exploit went undetected for six days. Covered in the monitoring-beats-first-audit article.
Monitoring is the cheapest insurance against the "we shipped audited code with a subtle bug" scenario. It's the highest-ROI dollar in the security budget at every tier.
Mistake 4: bounty-without-active-management
Founder lists on Immunefi, sets a $50K cap, then never responds to reports. Researchers escalate elsewhere or quietly disengage. The bounty becomes a vanity number that doesn't actually catch bugs.
A bounty needs a triage owner who responds within 24-48 hours, validates findings within a week, and pays out fairly. Without that operations layer, the bounty doesn't work.
Related questions
What if my TVL is volatile? Use a 30-day moving average. Plan for the average, but design the protocol so monitoring scales with current TVL (alert thresholds in percentage of TVL, not dollar terms).
Should the security budget come from TVL or treasury? Both are valid. Pure-treasury budgeting separates security from short-term TVL fluctuations. TVL-linked budgeting forces honest scaling. Most large protocols use treasury but allocate based on TVL bands.
What's the right ratio between bounty and audit? Mathematically: bounty should equal at least 50% of the largest plausible exploit's value. If exploit could drain $10M, bounty should reach $5M. Practically: most protocols underspend on bounties relative to this benchmark.
Should small protocols use Code4rena or Sherlock instead of one firm? Often yes. Code4rena and Sherlock contests can be more cost-effective for tier 2 and tier 3 protocols than a single-firm audit. The trade-off: less continuity, harder to get follow-up reviews.
How does this change for non-DeFi protocols? Lower factor for protocols holding less liquid value (NFT marketplaces, DAO infrastructure). Higher factor for cross-chain bridges (which historically suffer the worst exploit ratios per TVL).
Where to see this in Academy
eMBA Module 3 (Security from Day One) Lesson 2 walks through the budget framework with the same TVL bands as this article, plus interactive exercises for sizing your own protocol's spend. The module also covers the tiered approach to audit firm selection (when to use Tier 1 firms like Trail of Bits / OpenZeppelin / Spearbit vs Tier 2 firms vs independent auditors).
The numbers are not academic. The lesson opens with the 2025 $3.4B Chainalysis figure and works backward: how much would each protocol have needed to spend, in advance, to prevent its specific exploit? The answer is almost always "more than they did, and on different items than they did".
Pick the framework that matches your TVL band, then read the Audit Paradox article to understand why no single line in this budget is enough by itself.
Tagged