Smart contract vulnerability, Custodian risk, Stablecoin depeg risk
A security platform offering audits, audit contests, bug bounties, and coverage for qualifying exploit and bug-bounty payouts.
Sherlock is an onchain-security organization that combines development-stage analysis, collaborative audits, audit contests, bug bounties, and an optional post-launch coverage program. It is designed around finding and handling security issues across more than a conventional one-off audit engagement.
Sherlock provides smart-contract and protocol audits alongside collaborative audit contests and bug bounties. This gives a protocol team a way to combine structured review with a broader researcher process rather than relying on one fixed audit format.
Contest submissions are judged, deduplicated, and severity-calibrated before the team receives a clean issue set rather than every raw researcher submission. The audit process includes structured fix review, which checks remediated findings and is intended to reduce the chance that a patch creates a new issue.
Sherlock Shield is an optional post-launch coverage program, not a default inclusion with every audit and not a substitute for remediation or ongoing security work. A codebase must complete a Sherlock audit and its fix review, then meet Sherlock’s coverage requirements before Sherlock evaluates eligibility, scope, coverage amount, and final terms.
OpenZeppelin is a close alternative for a protocol seeking a dedicated, collaborative audit team that reviews architecture and code, communicates directly during the audit, conducts fix review, and delivers a final report. Sherlock combines a senior-led engagement with parallel contest participation and can add post-launch bounties or conditional Shield coverage, while OpenZeppelin centers its own staffed audit team and ongoing consultation.
Discover exchanges, wallets, casinos, mining, trading tools and more.