For a normal DeFi user: Sherlock Shield does not cover you. It pays the protocol team for exploits in Sherlock-audited code, is capped at $500k, has no public terms, and Sherlock states funds are not guaranteed. If you want cover you can personally claim on, see the buyable analyses.
Sherlock is primarily an audit and contest platform. Its cover product, Sherlock Shield, pays out only for exploits in code Sherlock itself audited, is capped at $500,000, and is sold to protocol teams, not end users. This profile examines how much protection that promise really contains. Facts, not advice.
Who this is for: Protocol teams combining an audit with a coverage commitment (payout goes to the TEAM)
A narrow but transparently framed product. The dispute process with UMA escalation is a distinctive design and the Euler payout is a documented track record. On the other side, coverage is capped at $500k, terms are private per engagement, and Sherlock states that neither payment nor availability of funds is guaranteed. The Raccoon Score rates Shield on the builder rubric, for its actual buyer, the protocol team; retail users have no claim under this product at all. The low score reflects the private terms, the $500k cap, the non-guaranteed funds and that the payout is not committed to reach the users, and is not a verdict on Sherlock as an auditor, which is top-tier.
How to read this page: where each value comes from
Only on-chain values are verifiable without trusting anyone. Everything off-chain, including binding documents, ultimately relies on trust in the source.
Reading the chain…
The key structural point: Shield is an accessory to the audit business, not a standalone insurance pool. Coverage exists only for code Sherlock audited, the amount depends on how clean the audit was, and the buyer is the protocol team. For a DeFi user this product provides no direct claim at all. For the protocol team itself the calculus is different: Shield comes bundled with the audit and its skin-in-the-game pricing, but is capped at $500k with no payout guarantee. Teams that want materially larger protocol-layer protection for their users can compare Nexus Mutual Native Protocol Cover, where a team buys up to $25M of cover that pays its users (per Nexus documentation).
No public, binding cover wording exists; the following is compiled from provider documentation. Final terms are set per engagement and are not public, which is itself a finding.
Pick what you actually want protection from; the list below highlights your answer. Runs in your browser only, nothing is sent.
Even "covered" is not a payment guarantee: every claim is decided by the mutual's members (claims assessors). A risk not listed here is most likely not part of the wording at all. No advice.
Pick your risks above and only those appear here, with the verdict: covered or not.
Disputes run through a three-tier system: first a Sherlock Bounty Judge (core team member), then the Sherlock Protocol Claims Committee (7 members, enforced as a 4-of-7 multisig, one week to decide), and finally the UMA Optimistic Oracle, where tens of thousands of UMA tokenholders vote. The top tier is genuinely independent of Sherlock, but reaching it costs roughly $15k. The first two tiers are Sherlock-internal or Sherlock-appointed.
A structured assessment across seven categories, 0 to 100 points in total. The score is an opinion based on the sources below, not a probability of payout and not a guarantee.
Note: this product is bought by a protocol team, not by end users. We therefore score it with our team rubric, which asks the questions a team asks. The most important one: if disaster strikes, does the money actually reach the users? Compare this score only with other team products, not with the retail list.
The payout ladder is public and recomputable, a rare plus (see conditions and worked example below). But what triggers a payout is private per engagement: no public binding wording, no event catalogue. A team can negotiate its own terms, which is control, but nobody outside can verify what was agreed.
Sherlock itself states availability of funds is not guaranteed, and the current backing is off-chain and unverifiable: the V2 staking pool readable live above holds only a fraction of former reserves. The $500k cap keeps the promise small; the Euler payout proves capacity existed historically.
The UMA escalation is the most independent top instance in the market and the Euler case proves the pipeline can move millions. Deductions: the first two tiers are Sherlock-internal, escalation costs roughly $15k, and there is no public claims database.
The builder question: does the payout reach the protocol users? At Shield the payout goes to the team with no obligation to pass it on, and Sherlock states users should not assume reimbursement. Honest of Sherlock, but for a team whose goal is making users whole, Shield does not commit to that outcome. Reading aid: if you are buying purely a treasury backstop bundled with your audit, not user protection, treat this category (and transparency to users) as not applicable rather than as a defect; the other five categories carry your comparison.
The auditor insures its own audit: aligned incentives before launch, a conflict of interest at claim time. Sherlock holds full discretion over platform participation and appoints the committee; the 4-of-7 multisig is a real but limited check.
Credit where due: unlike a discretionary mutual, there is a real bilateral written contract between Sherlock and the protocol team, genuinely more enforceable for that counterparty. Capped because the terms are private, explicitly not insurance, and disclaim guaranteed payment.
The audit side is radically transparent, the cover side is the opposite: the users of a covered protocol cannot verify terms, capital or claims. Only the score ladder is public. The gap shows this is a choice, and it weighs on the rating.
No complete public product terms: coverage is governed by private, per-engagement agreements. Under the Raccoon methodology this alone triggers an automatic warning.
No public information about the capital backing payouts, and Sherlock itself disclaims guaranteed availability of funds: the second automatic warning.
The 2023 Euler payout consumed roughly 90% of reserves per press reporting; the current balance of the staking pool is readable live above. The old capital model effectively died with its first big claim.
The first two claim instances (Bounty Judge, claims committee) are Sherlock-internal or Sherlock-appointed; independence only begins at UMA, behind a roughly $15k escalation fee.
End users are never entitled to anything: payouts go to protocol teams, and Sherlock explicitly warns that users should not assume reimbursement.
The auditor insures its own audit: if a covered exploit occurs, Sherlock pays for its own miss. That aligns incentives before launch but creates a conflict of interest in claims assessment.
Points this analysis could not verify. Anyone buying significant cover should clarify these first.
Analysis as of 2026-07-16. Live figures update every 5 minutes from the contracts. Not affiliated with Sherlock. Informational only, no legal, investment or insurance advice.