Sherlock Unveils Audit Engine as AI Security Race Accelerates
Key Takeaways
- •Sherlock has publicly unveiled Audit Engine, an orchestration platform for AI-native security review that was already being developed and deployed with major protocol teams ahead of launch.
- •The platform brings frontier LLMs, purpose-built AI auditors, and AI-enabled security researchers into a single review, with all three working against the same scoped code and underlying context.
- •Sherlock coordinates submissions through judging, validation, and deduplication, delivering one consolidated audit result to the customer from a field of independent security approaches.
- •Attribution features let teams see which approaches delivered strong coverage and precision, providing a like-for-like comparison of AI systems and human researchers on identical code.
- •The launch coincides with rapid advances in AI security capabilities — Anthropic reported frontier models finding high-severity vulnerabilities at scale — while Chainalysis estimated more than $3.4 billion in cryptocurrency was stolen in 2025.

New York City, United States, August 18th, 2026 — The security platform coordinates frontier models, specialized AI auditors and AI-enabled researchers inside a single review.
Web3 security company Sherlock has officially unveiled Sherlock Audit Engine, a new security auditing platform the company has been quietly developing and deploying with major protocol teams ahead of its public launch.
At its core, Audit Engine is an orchestration platform for AI-native security review. The platform brings three layers of security intelligence into the same engagement: frontier LLMs, purpose-built AI auditors and AI-enabled security researchers. All three work against the same scoped code and underlying context. The design mirrors a pattern already familiar in Web3 security, where audit competitions and bug bounties put many independent reviewers on the same codebase on the premise that different approaches catch different bug classes.
Sherlock coordinates the review and processes the resulting submissions through judging, validation and deduplication. That consolidation step carries much of the practical weight: when many independent reviewers examine the same code, overlapping reports and low-signal findings are common, and judging, validation and deduplication are what turn raw submissions into a result a protocol can act on. The customer ultimately receives one consolidated audit result drawn from a field of independent security approaches.
AI Is Finding More Bugs
The launch arrives as the security capabilities of frontier AI models are advancing quickly. In February, Anthropic reported that frontier models had reached the point of finding high-severity vulnerabilities at scale, including vulnerabilities that survived years of conventional testing.
For crypto protocols, where vulnerable software can directly control significant economic value, improvements in offensive capability carry unusually direct consequences. Chainalysis estimated that more than $3.4 billion in cryptocurrency was stolen during 2025.
Sherlock is approaching that environment by giving protocols access to multiple forms of security intelligence simultaneously.
Audit Engine also attributes performance across the review stack. Teams can see which approaches delivered strong coverage, which maintained high precision, and where individual systems contributed security signal that others missed. That creates an empirical view of what actually worked on a protocol's code, which can help shape future security spending, tooling and review composition. Because every layer works against the same scoped code and context, the attribution data also functions as a like-for-like comparison of AI systems and human researchers on identical code, rather than a set of competing claims.
Sherlock describes Audit Engine as "the orchestration layer for AI-native security review."
About Sherlock
Sherlock is a Web3 security company focused on protecting onchain systems throughout their lifecycle. The company describes its model as complete lifecycle security, spanning development security, private staffed auditing, high-intensity security review, and post-launch live bug bounties.
Sherlock says it completed more than 200 high-profile security engagements during the first half of 2026, a pace the company says has made it one of Web3's fastest-growing security companies this year.
Media contact: Alec Novella, Head of Marketing, Sherlock — alec@sherlock.xyz
Source: Chainwire