Bounty Rolling

Midas bug bounty on Sherlock: up to 500,000 USDC

Midas pays up to 500,000 USDC on Sherlock for bugs in its Ethereum and Solana contracts and web app. Live since August 21, 2026, with no end date.

The Midas bug bounty runs on the Sherlock platform. Midas is a platform for onchain investment products. The bounty covers its Ethereum contracts, its Solana contracts, its contract configuration and the web app at midas.app. The top payout shown on the page is 500,000 USDC.

For the Ethereum contracts, a critical bug pays from 25,000 USD to 500,000 USD and a high bug pays from 5,000 USD to 25,000 USD. For the Solana contracts, a critical bug pays from 10,000 USD to 200,000 USD. Bugs in contract configuration and in the web app pay up to 50,000 USD. A critical reward is 10% of the funds directly affected, up to the cap, and a bug must put at least 10,000 USD at direct risk to count as critical.

To earn a reward you must be the first to report a new bug that is not public. You must give a clear proof of concept and steps to reproduce it. People who worked on the affected code cannot take part, and neither can residents of sanctioned countries.

Out of scope are issues already found in earlier audits, centralization risks, admin errors, theoretical bugs without a proof of concept, phishing and reports from automated scans. Do not share a bug with anyone before Midas has fixed it and agreed to disclosure.

Reports go through the Sherlock page. The program has been live since August 21, 2026 and has no end date. Total payouts are capped at 1,000,000 USD, paid in order of when reports arrive.

Source · audits.sherlock.xyz/bug-bounties/122 Published 21 August 2026 · Added here 8 October 2026

Quick answers

How much does it pay?

500,000 USDC maximum payout. It is paid as prizes to the winning entries.

When is the deadline?

There is no fixed deadline. Applications are reviewed as they arrive.

Who can apply?

Researchers of legal age who report a new, non public bug first, who are not employees or contractors of the affected code, and who do not live in sanctioned countries. Applicants from anywhere in the world can enter, unless the eligibility rules say otherwise.

Is it online or in person?

Online. You can take part from anywhere the rules allow.

How do I apply?

Through the official page at audits.sherlock.xyz. The link is at the top of this page.

Do I need to pass KYC?

The program owner may ask for identity checks before it pays a reward.

Is there a deposit to submit a report?

The Sherlock page lists a deposit of 250 USDC for each report, at every severity level.