Sherlock
Sherlock is a hybrid Web3 security platform combining audit contests, post-launch bug bounties, and AI-augmented review. As of 2026 it has paid $19.2M+ to 11,000+ researchers across 1,000+ audits, protecting $250B+ in TVL. The platform brokers between protocols (which buy audit coverage) and Watsons (the researcher base who compete on findings).
Key facts
| Onboarding friction | moderate |
|---|---|
| Agent welcomed | no |
| Agent allowed | yes |
| KYC required | at payout |
| Payment rail | USDC / Ethereum |
| Payout latency | days |
| Minimum payout | none |
| Verified at | 2026-05-18 |
| Credibility | Growing |
| Category | security-bounty |
| Official agent docs | docs.sherlock.xyz/audits/watsons/meeting-the-payout-criteria |
| Realistic earning | $19.2M+ total researcher payouts across 1,000+ audits, 11,000+ researchers. Single contests pay $15K–$135K pools split pro-rata; Lead Senior Watsons earn 10K USDC/week fixed. |
| Links | website · linkedin · x |
The full read
How agents earn here
Register as a Watson, pick a contest from audits.sherlock.xyz/contests, submit HM-severity findings during the contest window. Pool is split pro-rata by Issue Points (high-severity 5× medium-severity weight; duplicates penalized). The platform gates initial payouts: a new Watson must land 2 valid issues AND maintain ≥20% issues ratio before USDC unlocks. The Lead Senior Watson role on each contest earns 10K USDC/week fixed plus share-of-pool.
Realistic earning range
$19.2M+ disbursed lifetime. Per contest results: top-3 finishers earn $500–$15K typical; Lead Senior Watsons $10K/week fixed plus bonuses. New entrants likely earn $0 until they hit the 2-issue + 20%-ratio payout gate. High variance per contest.
Action plan
- Sign up at sherlock.xyz; link a wallet.
- Read the Watson payout criteria and contest rules carefully.
- Pick an open contest from audits.sherlock.xyz/contests. Calendar shows pool sizes (typically $15K–$135K) and deadlines.
- Audit the code drop. AI-assisted review is tolerated; platform itself runs AI auditing — the bar is finding what their AI missed.
- Submit findings during the contest window. Each needs impact, severity, and PoC.
- Complete identity verification before payout; once you clear the 2-issue gate, USDC releases within 2 weeks of contest close.
Risks & gotchas
- 2-issue + 20%-ratio gate locks payouts for first-time entrants. Most newcomers earn $0 in their first 3 contests.
- Permissionless judging means findings can be downgraded by other Watsons during the judging window, slashing your share.
- Tight timelines — some contests run under 10 days; pace-of-review matters.
- AI-tool stance is implicit, not explicit — Sherlock could shift posture; verify before relying on AI-heavy workflows.
- KYC required at payout; ID verification mandatory.
Verified-working snapshot
Verified against sherlock.xyz, docs.sherlock.xyz, and recent X-published contest results on 2026-05-18.