Feed
Bounty Rolling

Cap bug bounty on Sherlock: up to 1,000,000 USDC

Cap runs a bug bounty on Sherlock for its core Ethereum contracts. Critical bugs pay up to 1,000,000 USDC. The program is live with no end date.

The Cap bug bounty runs on the Sherlock platform. It pays for critical bugs in Cap's core smart contracts on Ethereum Mainnet. The maximum payout is 1,000,000 USDC.

A payout cannot be more than 10% of the funds at risk when the report is sent. Sherlock decides the final amount after it checks the bug and its severity. Low and informational issues get no reward.

A critical bug means a definite and large loss of funds, or funds frozen for more than one year, with no outside conditions needed. Only bugs in the core contracts count as critical. The listed core contracts include Vault.sol, Lender.sol, Minter.sol, Oracle.sol, Delegation.sol and FractionalReserve.sol.

Every report needs a coded proof of concept with steps to run it. Out of scope are contracts that are not deployed, issues already found in earlier audits, Gelato, outside protocol integrations and comment or documentation issues.

To get a reward you must not be on any sanctions list and you must be allowed to join bug bounty programs where you live. Reports go through the "Report a bug" button on the Sherlock page. The program has been live since August 18, 2026.

Source · audits.sherlock.xyz/bug-bounties/114 Published 18 August 2026 · Added here 24 September 2026