Case Study

Sky Ecosystem x Sherlock: The Next Generation of Defensive Security

779
Findings Submitted
18
Frontier LLMs + AI Auditors
Sky Ecosystem x Sherlock: The Next Generation of Defensive Security
Case Study

Sky Ecosystem x Sherlock: The Next Generation of Defensive Security

779
Findings Submitted
18
Frontier LLMs + AI Auditors
Table of Content

How Sky Ecosystem used Sherlock Audit Engine to apply AI-native security across one of DeFi's most heavily reviewed ecosystems.

A security culture built over years

Sky Protocol carries forward one of the longest-running security legacies in DeFi. The protocol evolved from MakerDAO and today sits behind USDS, the third-largest stablecoin in the world, and sUSDS, the world’s largest yield-generating stablecoin, alongside a broader ecosystem of governance, liquidity, and capital-allocation infrastructure.

That scale changes the security equation. Mature systems accumulate integrations, history, and economic importance. They also attract more capable adversaries.

The teams building Sky Protocol have responded with sustained scrutiny. The protocol’s public security index lists 77 unique audit and review reports across the ecosystem. Few codebases in DeFi have been examined this many times over such an extended period.

  • 77 unique public audit and security review reports listed across the ecosystem.
  • 20 public reviews in 2026 alone before the Audit Engine engagement concluded.
  • Years of repeated external review created an unusually high bar for any new security approach to add meaningful signal.

Security leadership is a constantly moving target. Sky Ecosystem is treating it that way.

Preparing for an AI-shaped threat landscape

AI is changing the economics of security analysis. Systems can now explore larger codebases, test more hypotheses in parallel, and repeat specialized analysis at a speed that keeps improving.

For a protocol containing high-value financial infrastructure, the implication is straightforward: defensive capability has to evolve alongside offensive capability.

Sky Ecosystem wanted to explore that frontier early, without publishing a blueprint of its internal security strategy. The goal was to apply the strongest emerging approaches to a real, mature production ecosystem, learn from how those systems behaved, and continue raising the cost of finding something the security program had missed.

That led Sky Ecosystem to become one of the earliest major users of Sherlock Audit Engine, applying a new AI-native review model across the full ecosystem.

Audit Engine: Many Systems, One Security View

Audit Engine is designed around a simple premise. Different AI systems see different things.

A frontier model, a specialized AI auditor, and another purpose-built system can reason about the same code through different architectures, prompting strategies, tools, and internal workflows. That diversity matters when the goal is finding edge cases.

For Sky Ecosystem, Sherlock brought a heterogeneous field of specialized AI auditors and frontier models against the same scope. The engagement tested three ideas at once:

  1. Expand coverage. Different systems could push into different parts of the vulnerability space and surface issues others missed.
  2. Reinforce signal. When independent systems converged on the same underlying issue, the aggregate view provided stronger evidence that the finding deserved attention.
  3. Move faster. Parallel AI review compressed a large amount of discovery work into days, with meaningful results from individual systems arriving within hours.

The results supported the ensemble approach. The strongest systems showed materially different coverage profiles. Some contributed findings unique to their own runs. Others independently rediscovered the same issues, creating corroboration across the field.

That complementarity is the important part. A standalone AI auditor gives a team one methodology, one set of strengths, and one set of blind spots. Combining many approaches produces a broader map of the codebase and a clearer picture of where independent systems agree.

How Audit Engine Turns Parallel Output Into Actionable Security

Running many AI systems can create enormous output. Raw volume has limited value when engineering teams still have to determine which reports are valid, which describe the same root cause, which severity is appropriate, and what deserves remediation first.

Audit Engine is built to consolidate that activity. Across the engagement, submissions moved through triage, duplicate detection, judging, validation, and synthesis. Overlapping reports were grouped around common root causes. Low-signal output was filtered. Independent findings were preserved. The final result gave the teams building Sky Protocol one structured view across a field of different AI approaches.

Unique findings expanded coverage. Shared findings strengthened confidence.  Overall, 779 submissions were consolidated and finalized into 119 final findings.

The discovery phase itself moved quickly. The bulk of discovery activity was generated in roughly the first five days, while the remaining engagement time focused on judging, consolidation, and finalization.

That separation matters. AI can dramatically accelerate discovery, while disciplined judging turns speed into something a security team can actually use.

A signal of how Sky Protocol operates

The strongest takeaway from the engagement is the security posture across Sky Ecosystem.

The teams contributing to Sky Protocol arrived at AI-native security with a codebase that had already faced years of scrutiny. Its ecosystem had already gone through dozens of public reviews, and the team still chose to apply a new generation of security technology across a broad, mature scope.

That decision reflects a security culture built around continuous pressure testing. Previous audits establish confidence. New approaches test the assumptions behind that confidence. As the capabilities available to attackers change, Sky Ecosystem continues evaluating the capabilities available to defenders.

For users, builders, and ecosystem participants, that is a powerful signal. Sky Frontier Foundation is actively investing in the next generation of defensive security while keeping the details of its security playbook where they belong.

For Sherlock, the engagement showed what Audit Engine can become as AI security matures: a way to coordinate many independent systems, measure how their coverage differs, strengthen signal through convergence, preserve unique discoveries, and deliver one coherent result.

Sky Protocol has spent years building one of DeFi's deepest security programs.

As AI changes the frontier, Sky Protocol is already there.

Sky Ecosystem is a decentralized financial ecosystem built around USDS, one of the world’s largest stablecoins, alongside savings, lending, governance, liquidity, and capital-allocation infrastructure.
Categories
  • DeFi
  • Stablecoins
  • Onchain Financial Infrastructure
  • Services & Solutions
  • Issue & Access USDS
  • Earn Yield with sUSDS
  • Supply & Borrow Onchain
  • Stake & Govern with SKY
  • Learn More