Open-source contribution and hackathons are real signal here
Web3 does not have a standardized credentialing pipeline the way, say, finance or law does, and that absence turns out to work in favor of people without a traditional background, provided they build the right kind of visible proof. Contributing to real, actively used open-source protocols, fixing a genuine bug, improving documentation that developers actually rely on, or building a small tool that plugs into an existing protocol's ecosystem, is directly verifiable: anyone can look at the commit, understand what problem it solved, and judge the quality of the work themselves. This matters more here than in most industries because so much of the work is genuinely hard to evaluate from a resume alone, and a real, used contribution says more than a credential ever could.
Hackathons and bug bounties deserve particular credit here because they function as real portfolio signal in a way that's unusually direct compared to most industries. A hackathon project, even an unpolished one, forces you to build something functional against a real deadline, often on infrastructure a hiring team already knows and respects, and a genuine bug bounty payout, finding and responsibly reporting an actual vulnerability in a live, real protocol, is about as strong and undeniable a security credential as exists. Neither requires anyone's permission or a formal application process to attempt, which is precisely what makes them accessible to someone without a conventional background.
