Sherlock Shield

Exploit payout coverage for qualified audited code

Welcome to Sherlock Shield.

Sherlock Shield is available for qualified codebases that complete an audit with Sherlock and meet the requirements for coverage. Shield is not included by default with every audit.

Here’s how it works:

  1. Complete an audit with Sherlock

  2. Complete the fix review

  3. Sherlock evaluates the audited codebase for Shield eligibility

  4. Confirm scope, coverage amount, and final terms

  5. If approved, Sherlock Shield provides exploit payout coverage for the covered code

Sherlock Shield is part of Sherlock’s broader lifecycle security model, extending protection beyond the audit itself for qualified code that meets coverage requirements.

Coverage Amount Criteria

The amount of coverage Sherlock gives is based on the vulnerabilities found in the Sherlock audit:

Each Medium severity vulnerability is worth 1 point, and each High severity vulnerability is worth 5 points. Additionally, there are multipliers for the type of audit done:

Audit type
Points Multiplier

Recommended

0.75

Minimum

1.0

Best Efforts

2.0

Private

1.5

Collaborative

1.5

Like golf, you want your score to be as low as possible so you can access the maximum amount of coverage:

Points
Coverage Amount

0

$500,000

Less than 3

$250,000

Less than 6

$200,000

Less than 9

$150,000

Less than 12

$100,000

Less than 15

$50,000

Less than 18

$25,000

Less than 21

$10,000

Less than 30

$5,000

30 or more

$1,000

Note: Sherlock does not guarantee payment or the availability of funds. Payouts are determined by the on-chain claims process of the Sherlock protocol on Ethereum mainnet. Please review the Sherlock Disclaimers to better understand the coverage offering.

Last updated