Title
Sherlock’s template builds the title from three parts: the actor, the impact, the affected party.
Actor will impact affected party
Summary
One sentence that chains root cause, impact, affected party and path. When that sentence cannot be written, the finding is not ready.
Root cause, with the file will cause impact for affected party as actor will the path in a few words.
Root Cause
Link the exact lines on the contest commit. Judges group duplicates by root cause, so name the mistake and not its symptom. A design decision that causes no loss is informational.
In path/File.sol lines start-end at the contest commit commit (permalink), the mistake: the missing check, the wrong order, the unsafe cast.
{The smallest excerpt that shows it}
Internal pre-conditions
Numbered. Each one names who sets which variable to which value. Admin functions are assumed to be used correctly and internal roles are trusted unless the README says otherwise, so a pre-condition that needs an admin to act against users ends the report.
- Role needs to call
functionto setvariableto be at least, at most or exactlyvalue - Contract state that has to hold, with the number
Write "None" when the path works from any state.
External pre-conditions
Changes outside the protocol: an oracle price, gas, another protocol’s state. High needs a loss without extensive external conditions, so every line here moves the finding toward Medium.
- External condition with numbers, for example a 12% price move inside one block
Write "None" when the path needs nothing outside the protocol.
Attack Path
Numbered calls, one actor per step, concrete values. A report is only grouped with a valid issue when it shows a valid path. On a chain with a private mempool, a path that depends on front-running drops one level, and Medium becomes invalid.
- Actor calls
functionwith arguments. State after the call. - Actor calls
functionwith arguments. State after the call. - Final state, with the number.
Impact
Name the affected party and the loss as a number. High: more than 1% and more than $10 of principal, yield or fees, without extensive external conditions. Medium: more than 0.01% and more than $10, or broken core functionality. Likelihood is not weighed. For a denial of service, state the lock duration: the bar is more than a week, or a time-sensitive function.
Affected party lose amount, which is percentage of their principal, yield or fees. The attacker gains amount, or nothing when this is griefing.
Severity claimed: High or Medium, because the threshold the number clears.
PoC
Sherlock recommends a coded PoC for complex paths, non-trivial input constraints, precision loss, reentrancy, and gas or revert attacks. A report that cannot be understood without a PoC is invalid without one. Paste the test, the command and the output.
Command: forge test --match-test test_name -vvv on the contest commit.
{The test}
{Pasted output, with the final assertion and the measured loss}
Mitigation
The fix. Judges separate issues whose fixes differ, so a precise fix also marks where your root cause ends.
The change, in the file and function it belongs to.
- {vulnerable line}
+ {fixed line}
Limits and non-claims
State the constraints yourself. The criteria ask Watsons to specify every condition needed to trigger the issue, and additional constraints lower the severity.
- Not claimed: what this report does not say, for example no loss beyond the funds held at this address
- Mocked or assumed: each mock and assumption, or "nothing: every step runs the deployed code"
- Stops working when: the condition that breaks the path
Known issues checked
Invalid on Sherlock: issues labelled wont fix in an earlier contest, and acknowledged findings in the audits the README links. Name the nearest one and state the difference in root cause.
- Contest README, known issues and acceptable risks: the nearest item, why this differs
- Earlier contests,
wont fixissues: issue link, or "none on this code" - Audits linked in the README, acknowledged findings: report and finding id, why the root cause differs
Markdown sourcesherlock.md
> Sherlock report template from https://bountyoperator.com/templates/sherlock. Platform rules checked 2 Oct 2026.
> Replace every {placeholder}. Delete this note before you submit.
# {Actor} will {impact} {affected party}
### Summary
{Root cause, with the file} will cause {impact} for {affected party} as {actor} will {the path in a few words}.
### Root Cause
In `{path/File.sol}` lines {start}-{end} at the contest commit `{commit}` ({permalink}), {the mistake: the missing check, the wrong order, the unsafe cast}.
```solidity
{The smallest excerpt that shows it}
```
### Internal pre-conditions
1. {Role} needs to call `{function}` to set `{variable}` to be {at least, at most or exactly} `{value}`
2. {Contract state that has to hold, with the number}
{Write "None" when the path works from any state.}
### External pre-conditions
1. {External condition with numbers, for example a 12% price move inside one block}
{Write "None" when the path needs nothing outside the protocol.}
### Attack Path
1. {Actor} calls `{function}` with {arguments}. {State after the call.}
2. {Actor} calls `{function}` with {arguments}. {State after the call.}
3. {Final state, with the number.}
### Impact
{Affected party} lose {amount}, which is {percentage} of their {principal, yield or fees}. The attacker gains {amount, or nothing when this is griefing}.
Severity claimed: {High or Medium}, because {the threshold the number clears}.
### PoC
Command: `{forge test --match-test test_name -vvv}` on the contest commit.
```solidity
{The test}
```
```text
{Pasted output, with the final assertion and the measured loss}
```
### Mitigation
{The change, in the file and function it belongs to.}
```diff
- {vulnerable line}
+ {fixed line}
```
### Limits and non-claims
- Not claimed: {what this report does not say, for example no loss beyond the funds held at this address}
- Mocked or assumed: {each mock and assumption, or "nothing: every step runs the deployed code"}
- Stops working when: {the condition that breaks the path}
### Known issues checked
- Contest README, known issues and acceptable risks: {the nearest item, why this differs}
- Earlier contests, `wont fix` issues: {issue link, or "none on this code"}
- Audits linked in the README, acknowledged findings: {report and finding id, why the root cause differs}