A structured assessment across seven categories, 0 to 100 points in total. The score is an opinion based on the sources below, not a probability of payout and not a guarantee.
The payout ladder is public and recomputable, a rare plus (see conditions and worked example below). But what triggers a payout is private per engagement: no public binding wording, no event catalogue. A team can negotiate its own terms, which is control, but nobody outside can verify what was agreed.
Sherlock itself states availability of funds is not guaranteed, and the current backing is off-chain and unverifiable: the V2 staking pool readable live above holds only a fraction of former reserves. The $500k cap keeps the promise small; the Euler payout proves capacity existed historically.
The UMA escalation is the most independent top instance in the market and the Euler case proves the pipeline can move millions. Deductions: the first two tiers are Sherlock-internal, escalation costs roughly $15k, and there is no public claims database.
The builder question: does the payout reach the protocol users? At Shield the payout goes to the team with no obligation to pass it on, and Sherlock states users should not assume reimbursement. Honest of Sherlock, but for a team whose goal is making users whole, Shield does not commit to that outcome. Reading aid: if you are buying purely a treasury backstop bundled with your audit, not user protection, treat this category (and transparency to users) as not applicable rather than as a defect; the other five categories carry your comparison.
The auditor insures its own audit: aligned incentives before launch, a conflict of interest at claim time. Sherlock holds full discretion over platform participation and appoints the committee; the 4-of-7 multisig is a real but limited check.
Credit where due: unlike a discretionary mutual, there is a real bilateral written contract between Sherlock and the protocol team, genuinely more enforceable for that counterparty. Capped because the terms are private, explicitly not insurance, and disclaim guaranteed payment.
The audit side is radically transparent, the cover side is the opposite: the users of a covered protocol cannot verify terms, capital or claims. Only the score ladder is public. The gap shows this is a choice, and it weighs on the rating.
No complete public product terms: coverage is governed by private, per-engagement agreements. Under the Raccoon methodology this alone triggers an automatic warning.
No public information about the capital backing payouts, and Sherlock itself disclaims guaranteed availability of funds: the second automatic warning.
The 2023 Euler payout consumed roughly 90% of reserves per press reporting; the current balance of the staking pool is readable live above. The old capital model effectively died with its first big claim.
The first two claim instances (Bounty Judge, claims committee) are Sherlock-internal or Sherlock-appointed; independence only begins at UMA, behind a roughly $15k escalation fee.
End users are never entitled to anything: payouts go to protocol teams, and Sherlock explicitly warns that users should not assume reimbursement.
The auditor insures its own audit: if a covered exploit occurs, Sherlock pays for its own miss. That aligns incentives before launch but creates a conflict of interest in claims assessment.
Points this analysis could not verify. Anyone buying significant cover should clarify these first.
Analysis as of 2026-07-16. Not affiliated with Sherlock. Informational only, no legal, investment or insurance advice.