A Living Swarm of Security Intelligence
PolySwarm's detection network combines 35+ specialized security engines (commercial antivirus, sandboxes, machine learning models, and independent researchers) to deliver consensus-driven malware verdicts you can trust.
The Ecosystem at a Glance
Specialists
Security experts who build and maintain detection engines, competing to identify threats first and most accurately.
Engines
35+ active engines from commercial vendors, research labs, and specialized threat hunters, all competing in parallel. New partners join regularly.
Marketplace
Engines are financially rewarded for accurate detections and penalized for wrong verdicts. This means every engine has a direct incentive to be right.
Researchers
Join the network as a contributor: build engines, earn NCT, and help protect the world from malware.
Why Crowdsourced Detection Wins
No single engine catches everything. The swarm combines diverse approaches to eliminate blind spots.
Diverse Coverage
Multiple detection approaches
No single engine catches everything. Our swarm combines commercial AV, sandboxes, ML models, YARA rules, and regional specialists to eliminate blind spots.
- Commercial AV engines
- Sandbox analysis
- ML models
- YARA rules
- Regional specialists
Faster Zero-Day Detection
Catch threats early
Specialized engines often detect emerging threats hours or days before commercial vendors update signatures. The swarm catches what others miss.
- Early threat detection
- Specialized engine coverage
- Hours ahead of major vendors
Economic Accountability
Skin in the game
Engines stake tokens on their verdicts. Wrong answers cost money. This creates powerful incentives for accuracy that traditional scanning lacks.
- Token staking on verdicts
- Financial incentives for accuracy
- Continuous improvement loop
Weighted Consensus
Reliable scoring
PolyScore weighs each engine's verdict by historical accuracy, giving you a single number that's more reliable than any individual engine.
- Historical accuracy weighting
- Single authoritative score
- More reliable than individual engines
From Submission to Verdict
Artifact Submission
Files or URLs are submitted via API, web UI, or integration. A bounty is automatically attached to incentivize engine participation.
Parallel Analysis
Multiple engines analyze the artifact simultaneously. Each engine that participates stakes NCT tokens on its verdict: malicious, benign, or abstain.
Consensus Scoring
PolyScore aggregates all verdicts, weighting each by historical accuracy. You receive real-time results with full engine-level transparency.
Ground Truth & Rewards
After ~2 weeks, the network settles on ground truth. Accurate engines earn rewards; incorrect engines lose their stake. This continuous feedback loop drives improvement.
Ready to Join the Swarm
Whether you're a security team looking for better intelligence, or a researcher ready to contribute detection capabilities, there's a place for you in the PolySwarm ecosystem.

