COVERRACCOON
← All providers
Cover analysis · Sherlock

The audit shop
that backs its work.

In plain words

For a normal DeFi user: Sherlock Shield does not cover you. It pays the protocol team for exploits in Sherlock-audited code, is capped at $500k, has no public terms, and Sherlock states funds are not guaranteed. If you want cover you can personally claim on, see the buyable analyses.

Sherlock is primarily an audit and contest platform. Its cover product, Sherlock Shield, pays out only for exploits in code Sherlock itself audited, is capped at $500,000, and is sold to protocol teams, not end users. This profile examines how much protection that promise really contains. Facts, not advice.

39/100 Low fit

Who this is for: Protocol teams combining an audit with a coverage commitment (payout goes to the TEAM)

A narrow but transparently framed product. The dispute process with UMA escalation is a distinctive design and the Euler payout is a documented track record. On the other side, coverage is capped at $500k, terms are private per engagement, and Sherlock states that neither payment nor availability of funds is guaranteed. The Raccoon Score rates Shield on the builder rubric, for its actual buyer, the protocol team; retail users have no claim under this product at all. The low score reflects the private terms, the $500k cap, the non-guaranteed funds and that the payout is not committed to reach the users, and is not a verdict on Sherlock as an auditor, which is top-tier.

Data confidence: low · Assessment as of 2026-07-16 · Methodology: Raccoon Score

How to read this page: where each value comes from

On-chain Read from contracts, verifiable by anyone at any time.
Contract doc From a binding written document, off-chain but checkable.
Provider claim Stated by the provider, off-chain: a matter of trust.
Third party From a third-party source, off-chain: a matter of trust.
Our assessment Our judgement under the Raccoon methodology.

Only on-chain values are verifiable without trusting anyone. Everything off-chain, including binding documents, ultimately relies on trust in the source.

Live on-chain On-chain

Reading the chain…

Profile

Provider Sherlock (audit firm plus coverage protocol on Ethereum) Provider claim
Product analysed Sherlock Shield: exploit payout coverage for Sherlock-audited code Our assessment
Who is covered Protocol teams only. Sherlock states explicitly: users should not assume they will be reimbursed Provider claim
Legal nature Not insurance (own disclaimer). Coverage governed solely by private, per-engagement written terms Provider claim
Maximum coverage $500,000 per codebase, tiered down to $1,000 based on audit findings score Provider claim
Payout guarantee None. Sherlock: "does not guarantee payment or the availability of funds" Provider claim
Claims settlement Payouts run through the on-chain claims process of the Sherlock protocol on Ethereum mainnet Provider claim

The key structural point: Shield is an accessory to the audit business, not a standalone insurance pool. Coverage exists only for code Sherlock audited, the amount depends on how clean the audit was, and the buyer is the protocol team. For a DeFi user this product provides no direct claim at all. For the protocol team itself the calculus is different: Shield comes bundled with the audit and its skin-in-the-game pricing, but is capped at $500k with no payout guarantee. Teams that want materially larger protocol-layer protection for their users can compare Nexus Mutual Native Protocol Cover, where a team buys up to $25M of cover that pays its users (per Nexus documentation).

What is covered Provider claim

No public, binding cover wording exists; the following is compiled from provider documentation. Final terms are set per engagement and are not public, which is itself a finding.

1 covered 2 conditional 4 excluded
Does it fit you?

Pick what you actually want protection from; the list below highlights your answer. Runs in your browser only, nothing is sent.

Even "covered" is not a payment guarantee: every claim is decided by the mutual's members (claims assessors). A risk not listed here is most likely not part of the wording at all. No advice.

Pick your risks above and only those appear here, with the verdict: covered or not.

Conditions attached Provider claim

Eligibility Completed Sherlock audit plus approved fix review; Shield is neither automatic nor free
Coverage amount (full public ladder) Score-based and checkable. Points: Medium finding = 1, High = 5, times an audit-type multiplier (Recommended 0.75, Minimum 1.0, Private and Collaborative 1.5, Best Efforts 2.0). Cover by points: 0 = $500k, under 3 = $250k, under 6 = $200k, under 9 = $150k, under 12 = $100k, under 15 = $50k, under 18 = $25k, under 21 = $10k, under 30 = $5k, 30 or more = $1k. Fewer and less severe findings mean more cover.
Coverage window Team selects a time-bound protection window; coverage applies only within it
Dispute costs Escalation to the claims committee costs $1k, to the UMA Optimistic Oracle roughly $15k
Negotiation Supervised negotiation allowed, capped at 14 days, only in Sherlock-moderated channels
Worked example (checkable) Gamma Staking contest, May 2024: 0 High and 2 Medium valid findings per the public judging repo. Points: 2 x 1 = 2, below 3 even after any audit-type multiplier, so up to $250,000 Shield coverage. Because contest results are public, this part of the promise is verifiable by anyone; whether Gamma actually bought Shield is not public.

Who decides on claims Provider claim

Disputes run through a three-tier system: first a Sherlock Bounty Judge (core team member), then the Sherlock Protocol Claims Committee (7 members, enforced as a 4-of-7 multisig, one week to decide), and finally the UMA Optimistic Oracle, where tens of thousands of UMA tokenholders vote. The top tier is genuinely independent of Sherlock, but reaching it costs roughly $15k. The first two tiers are Sherlock-internal or Sherlock-appointed.

Raccoon Score Our assessment

A structured assessment across seven categories, 0 to 100 points in total. The score is an opinion based on the sources below, not a probability of payout and not a guarantee.

Note: this product is bought by a protocol team, not by end users. We therefore score it with our team rubric, which asks the questions a team asks. The most important one: if disaster strikes, does the money actually reach the users? Compare this score only with other team products, not with the retail list.

Coverage clarity & scope control 8/20

The payout ladder is public and recomputable, a rare plus (see conditions and worked example below). But what triggers a payout is private per engagement: no public binding wording, no event catalogue. A team can negotiate its own terms, which is control, but nobody outside can verify what was agreed.

Capital & payout capacity 6/20

Sherlock itself states availability of funds is not guaranteed, and the current backing is off-chain and unverifiable: the V2 staking pool readable live above holds only a fraction of former reserves. The $500k cap keeps the promise small; the Euler payout proves capacity existed historically.

Claims process & incident fit 9/15

The UMA escalation is the most independent top instance in the market and the Euler case proves the pipeline can move millions. Deductions: the first two tiers are Sherlock-internal, escalation costs roughly $15k, and there is no public claims database.

User outcome 3/15

The builder question: does the payout reach the protocol users? At Shield the payout goes to the team with no obligation to pass it on, and Sherlock states users should not assume reimbursement. Honest of Sherlock, but for a team whose goal is making users whole, Shield does not commit to that outcome. Reading aid: if you are buying purely a treasury backstop bundled with your audit, not user protection, treat this category (and transparency to users) as not applicable rather than as a defect; the other five categories carry your comparison.

Governance & conflicts 4/10

The auditor insures its own audit: aligned incentives before launch, a conflict of interest at claim time. Sherlock holds full discretion over platform participation and appoints the committee; the 4-of-7 multisig is a real but limited check.

Legal enforceability 6/10

Credit where due: unlike a discretionary mutual, there is a real bilateral written contract between Sherlock and the protocol team, genuinely more enforceable for that counterparty. Capped because the terms are private, explicitly not insurance, and disclaim guaranteed payment.

Transparency to users 3/10

The audit side is radically transparent, the cover side is the opposite: the users of a covered protocol cannot verify terms, capital or claims. Only the score ladder is public. The gap shows this is a choice, and it weighs on the rating.

Total 39/100 · Low fit

Red flags Our assessment

01

No complete public product terms: coverage is governed by private, per-engagement agreements. Under the Raccoon methodology this alone triggers an automatic warning.

02

No public information about the capital backing payouts, and Sherlock itself disclaims guaranteed availability of funds: the second automatic warning.

03

The 2023 Euler payout consumed roughly 90% of reserves per press reporting; the current balance of the staking pool is readable live above. The old capital model effectively died with its first big claim.

04

The first two claim instances (Bounty Judge, claims committee) are Sherlock-internal or Sherlock-appointed; independence only begins at UMA, behind a roughly $15k escalation fee.

05

End users are never entitled to anything: payouts go to protocol teams, and Sherlock explicitly warns that users should not assume reimbursement.

06

The auditor insures its own audit: if a covered exploit occurs, Sherlock pays for its own miss. That aligns incentives before launch but creates a conflict of interest in claims assessment.

Open questions Our assessment

Points this analysis could not verify. Anyone buying significant cover should clarify these first.

  • Is the Sherlock V2 staking pool (live above) still the payout basis for Shield, or does Sherlock pay from other, non-public sources?
  • How many Shield engagements are active, and what is the aggregate coverage outstanding?
  • What do the per-engagement terms look like: covered events, exclusions, evidence requirements, deadlines?
  • Has any claim other than Euler ever been paid, and were claims ever denied?
  • Who audits the current Sherlock protocol contracts, and what admin rights and upgrade paths exist?

Sources

Analysis as of 2026-07-16. Live figures update every 5 minutes from the contracts. Not affiliated with Sherlock. Informational only, no legal, investment or insurance advice.

COVERRACCOON

Independent analysis of DeFi cover. We read the terms nobody else opens.