Sherlock closed its bug bounty program on Immunefi, ending submissions with a final max bounty of $500K.
Tech & Launches ·
Sherlock has concluded its bug bounty program on Immunefi, halting new vulnerability submissions. The program's final maximum bounty stood at $500K. According to the program history, this represents the end of an active security incentive initiative that previously invited researchers to report flaws through the Immunefi platform.
The closure means Sherlock is no longer fielding fresh bug reports through this formal channel. This type of program wind-down typically follows a project's decision to redirect resources or alter its security strategy, though the specific rationale behind Sherlock's decision has not been detailed in available reports.
It remains unclear whether Sherlock intends to launch alternative vulnerability disclosure mechanisms, maintain a private security reporting path, or shift its approach to auditing and threat detection altogether. The timeline and any transition details for researchers who may have been engaged with the program are not yet documented.