Black Hat USA 2026 · PolySwarm is co-hosting the poker night · Claim a Seat →

THE POLYSWARM NETWORK

A Living Swarm of Security Intelligence

PolySwarm's detection network combines 35+ specialized security engines (commercial antivirus, sandboxes, machine learning models, and independent researchers) to deliver consensus-driven malware verdicts you can trust.

The Ecosystem at a Glance

Specialists

Security experts who build and maintain detection engines, competing to identify threats first and most accurately.

Engines

35+ active engines from commercial vendors, research labs, and specialized threat hunters, all competing in parallel. New partners join regularly.

Marketplace

Engines are financially rewarded for accurate detections and penalized for wrong verdicts. This means every engine has a direct incentive to be right.

Researchers

Join the network as a contributor: build engines, earn NCT, and help protect the world from malware.

Why Crowdsourced Detection Wins

No single engine catches everything. The swarm combines diverse approaches to eliminate blind spots.

Diverse Coverage

Multiple detection approaches

No single engine catches everything. Our swarm combines commercial AV, sandboxes, ML models, YARA rules, and regional specialists to eliminate blind spots.

  • Commercial AV engines
  • Sandbox analysis
  • ML models
  • YARA rules
  • Regional specialists

Faster Zero-Day Detection

Catch threats early

Specialized engines often detect emerging threats hours or days before commercial vendors update signatures. The swarm catches what others miss.

  • Early threat detection
  • Specialized engine coverage
  • Hours ahead of major vendors

Economic Accountability

Skin in the game

Engines stake tokens on their verdicts. Wrong answers cost money. This creates powerful incentives for accuracy that traditional scanning lacks.

  • Token staking on verdicts
  • Financial incentives for accuracy
  • Continuous improvement loop

Weighted Consensus

Reliable scoring

PolyScore weighs each engine's verdict by historical accuracy, giving you a single number that's more reliable than any individual engine.

  • Historical accuracy weighting
  • Single authoritative score
  • More reliable than individual engines

From Submission to Verdict

1

Artifact Submission

Files or URLs are submitted via API, web UI, or integration. A bounty is automatically attached to incentivize engine participation.

2

Parallel Analysis

Multiple engines analyze the artifact simultaneously. Each engine that participates stakes NCT tokens on its verdict: malicious, benign, or abstain.

3

Consensus Scoring

PolyScore aggregates all verdicts, weighting each by historical accuracy. You receive real-time results with full engine-level transparency.

4

Ground Truth & Rewards

After ~2 weeks, the network settles on ground truth. Accurate engines earn rewards; incorrect engines lose their stake. This continuous feedback loop drives improvement.

35+
Active Engines & Growing
30%
Malware First Seen in PolySwarm
<60s
Time to Verdict
1M+
Daily Scans

Ready to Join the Swarm

Whether you're a security team looking for better intelligence, or a researcher ready to contribute detection capabilities, there's a place for you in the PolySwarm ecosystem.