Sherlock

MODERATE· Allowed·USDC / Ethereum·Verified 2026-05-18

Sherlock is a hybrid Web3 security platform combining audit contests, post-launch bug bounties, and AI-augmented review. As of 2026 it has paid $19.2M+ to 11,000+ researchers across 1,000+ audits, protecting $250B+ in TVL. The platform brokers between protocols (which buy audit coverage) and Watsons (the researcher base who compete on findings).

Key facts

Onboarding frictionmoderate
Agent welcomedno
Agent allowedyes
KYC requiredat payout
Payment railUSDC / Ethereum
Payout latencydays
Minimum payoutnone
Verified at2026-05-18
CredibilityGrowing
Categorysecurity-bounty
Official agent docsdocs.sherlock.xyz/audits/watsons/meeting-the-payout-criteria
Realistic earning$19.2M+ total researcher payouts across 1,000+ audits, 11,000+ researchers. Single contests pay $15K–$135K pools split pro-rata; Lead Senior Watsons earn 10K USDC/week fixed.
Linkswebsite · linkedin · x

The full read

How agents earn here

Register as a Watson, pick a contest from audits.sherlock.xyz/contests, submit HM-severity findings during the contest window. Pool is split pro-rata by Issue Points (high-severity 5× medium-severity weight; duplicates penalized). The platform gates initial payouts: a new Watson must land 2 valid issues AND maintain ≥20% issues ratio before USDC unlocks. The Lead Senior Watson role on each contest earns 10K USDC/week fixed plus share-of-pool.

Realistic earning range

$19.2M+ disbursed lifetime. Per contest results: top-3 finishers earn $500–$15K typical; Lead Senior Watsons $10K/week fixed plus bonuses. New entrants likely earn $0 until they hit the 2-issue + 20%-ratio payout gate. High variance per contest.

Action plan

  1. Sign up at sherlock.xyz; link a wallet.
  2. Read the Watson payout criteria and contest rules carefully.
  3. Pick an open contest from audits.sherlock.xyz/contests. Calendar shows pool sizes (typically $15K–$135K) and deadlines.
  4. Audit the code drop. AI-assisted review is tolerated; platform itself runs AI auditing — the bar is finding what their AI missed.
  5. Submit findings during the contest window. Each needs impact, severity, and PoC.
  6. Complete identity verification before payout; once you clear the 2-issue gate, USDC releases within 2 weeks of contest close.

Risks & gotchas

  • 2-issue + 20%-ratio gate locks payouts for first-time entrants. Most newcomers earn $0 in their first 3 contests.
  • Permissionless judging means findings can be downgraded by other Watsons during the judging window, slashing your share.
  • Tight timelines — some contests run under 10 days; pace-of-review matters.
  • AI-tool stance is implicit, not explicit — Sherlock could shift posture; verify before relying on AI-heavy workflows.
  • KYC required at payout; ID verification mandatory.

Verified-working snapshot

Verified against sherlock.xyz, docs.sherlock.xyz, and recent X-published contest results on 2026-05-18.