Sherlock audit contest report template

Sherlock’s own headings, in its order, with the loss thresholds a judge reads the Impact section against. Two sections are added at the end for the objections that close reports: limits and known issues.

Download .md

Rules checked 2 Oct 2026 · 9 sources

The template

The headings from Summary to Mitigation are the ones in Sherlock’s published report template. Keep them as they are. One issue per submission, even when two issues share a line.

Platformasked for in Sherlock’s published guidance. Addedanswers the two objections that close reports late: overclaiming and known issues.

sherlock.md11 sections
01Platform

Title

Sherlock’s template builds the title from three parts: the actor, the impact, the affected party.

Actor will impact affected party

02Platform

Summary

One sentence that chains root cause, impact, affected party and path. When that sentence cannot be written, the finding is not ready.

Root cause, with the file will cause impact for affected party as actor will the path in a few words.

03Platform

Root Cause

Link the exact lines on the contest commit. Judges group duplicates by root cause, so name the mistake and not its symptom. A design decision that causes no loss is informational.

In path/File.sol lines start-end at the contest commit commit (permalink), the mistake: the missing check, the wrong order, the unsafe cast.

{The smallest excerpt that shows it}
04Platform

Internal pre-conditions

Numbered. Each one names who sets which variable to which value. Admin functions are assumed to be used correctly and internal roles are trusted unless the README says otherwise, so a pre-condition that needs an admin to act against users ends the report.

  1. Role needs to call function to set variable to be at least, at most or exactly value
  2. Contract state that has to hold, with the number

Write "None" when the path works from any state.

05Platform

External pre-conditions

Changes outside the protocol: an oracle price, gas, another protocol’s state. High needs a loss without extensive external conditions, so every line here moves the finding toward Medium.

  1. External condition with numbers, for example a 12% price move inside one block

Write "None" when the path needs nothing outside the protocol.

06Platform

Attack Path

Numbered calls, one actor per step, concrete values. A report is only grouped with a valid issue when it shows a valid path. On a chain with a private mempool, a path that depends on front-running drops one level, and Medium becomes invalid.

  1. Actor calls function with arguments. State after the call.
  2. Actor calls function with arguments. State after the call.
  3. Final state, with the number.
07Platform

Impact

Name the affected party and the loss as a number. High: more than 1% and more than $10 of principal, yield or fees, without extensive external conditions. Medium: more than 0.01% and more than $10, or broken core functionality. Likelihood is not weighed. For a denial of service, state the lock duration: the bar is more than a week, or a time-sensitive function.

Affected party lose amount, which is percentage of their principal, yield or fees. The attacker gains amount, or nothing when this is griefing.

Severity claimed: High or Medium, because the threshold the number clears.

08Platform

PoC

Sherlock recommends a coded PoC for complex paths, non-trivial input constraints, precision loss, reentrancy, and gas or revert attacks. A report that cannot be understood without a PoC is invalid without one. Paste the test, the command and the output.

Command: forge test --match-test test_name -vvv on the contest commit.

{The test}
{Pasted output, with the final assertion and the measured loss}
09Platform

Mitigation

The fix. Judges separate issues whose fixes differ, so a precise fix also marks where your root cause ends.

The change, in the file and function it belongs to.

- {vulnerable line}
+ {fixed line}
10Added

Limits and non-claims

State the constraints yourself. The criteria ask Watsons to specify every condition needed to trigger the issue, and additional constraints lower the severity.

  • Not claimed: what this report does not say, for example no loss beyond the funds held at this address
  • Mocked or assumed: each mock and assumption, or "nothing: every step runs the deployed code"
  • Stops working when: the condition that breaks the path
11Added

Known issues checked

Invalid on Sherlock: issues labelled wont fix in an earlier contest, and acknowledged findings in the audits the README links. Name the nearest one and state the difference in root cause.

  • Contest README, known issues and acceptable risks: the nearest item, why this differs
  • Earlier contests, wont fix issues: issue link, or "none on this code"
  • Audits linked in the README, acknowledged findings: report and finding id, why the root cause differs
Markdown sourcesherlock.md
sherlock.md
> Sherlock report template from https://bountyoperator.com/templates/sherlock. Platform rules checked 2 Oct 2026.
> Replace every {placeholder}. Delete this note before you submit.

# {Actor} will {impact} {affected party}

### Summary

{Root cause, with the file} will cause {impact} for {affected party} as {actor} will {the path in a few words}.

### Root Cause

In `{path/File.sol}` lines {start}-{end} at the contest commit `{commit}` ({permalink}), {the mistake: the missing check, the wrong order, the unsafe cast}.

```solidity
{The smallest excerpt that shows it}
```

### Internal pre-conditions

1. {Role} needs to call `{function}` to set `{variable}` to be {at least, at most or exactly} `{value}`
2. {Contract state that has to hold, with the number}

{Write "None" when the path works from any state.}

### External pre-conditions

1. {External condition with numbers, for example a 12% price move inside one block}

{Write "None" when the path needs nothing outside the protocol.}

### Attack Path

1. {Actor} calls `{function}` with {arguments}. {State after the call.}
2. {Actor} calls `{function}` with {arguments}. {State after the call.}
3. {Final state, with the number.}

### Impact

{Affected party} lose {amount}, which is {percentage} of their {principal, yield or fees}. The attacker gains {amount, or nothing when this is griefing}.

Severity claimed: {High or Medium}, because {the threshold the number clears}.

### PoC

Command: `{forge test --match-test test_name -vvv}` on the contest commit.

```solidity
{The test}
```

```text
{Pasted output, with the final assertion and the measured loss}
```

### Mitigation

{The change, in the file and function it belongs to.}

```diff
- {vulnerable line}
+ {fixed line}
```

### Limits and non-claims

- Not claimed: {what this report does not say, for example no loss beyond the funds held at this address}
- Mocked or assumed: {each mock and assumption, or "nothing: every step runs the deployed code"}
- Stops working when: {the condition that breaks the path}

### Known issues checked

- Contest README, known issues and acceptable risks: {the nearest item, why this differs}
- Earlier contests, `wont fix` issues: {issue link, or "none on this code"}
- Audits linked in the README, acknowledged findings: {report and finding id, why the root cause differs}

What gets this closed on Sherlock

Each reason comes from a page Sherlock publishes. The programme or contest page adds its own rules on top, and those win.

  1. Loss below the written thresholds

    Only High and Medium score in a contest. High is a direct loss above 1% and $10 without extensive external conditions. Medium is a loss above 0.01% and $10 that needs conditions, or broken core functionality. Likelihood is not considered.

    Source Criteria for Issue Validity, How to Score Issue Points in a Contest

  2. Denial of service that does not last

    A DoS counts when funds are locked for more than a week or a time-sensitive function is affected. One of the two is Medium, both is High. A repeatable attack is judged on a single occurrence.

    Source Criteria for Issue Validity

  3. Trusted roles and design decisions

    Admin functions are assumed to be used correctly. Internal roles are trusted unless the README names them untrusted. A design decision that causes no loss is informational. The README outranks code comments, and past judging decisions carry no weight:

    Historical decisions are not considered sources of truth.

    Criteria for Issue Validity, Sherlock

    Source Criteria for Issue Validity

  4. Known issues

    Issues labelled wont fix in a previous contest and acknowledged findings in the audits linked from the README are invalid. On bounties, publicly known bugs and bugs from a previous audit are never eligible for a payout.

    Source Criteria for Issue Validity, Bug bounty Platform Rules

  5. The listed invalid categories

    Gas optimisations, wrong event values, zero-address checks, user and admin input validation, blacklisting, initializer front-running, non-standard tokens the README does not name, stale-price recommendations, re-orgs, sequencer downtime, future integrations, and wrong values in view functions that nothing else consumes.

    Source Criteria for Issue Validity

  6. No PoC where one is needed

    A PoC is recommended for complex paths, non-trivial input constraints, precision loss, reentrancy and gas or revert attacks. A report that cannot be understood without one is invalid without one.

    Source Criteria for Issue Validity

  7. Duplicates

    A report is grouped with a valid issue only when it identifies the root cause, shows at least Medium impact and gives a valid path. Duplicates share the points: each of n submissions is weighted by 0.9 to the power n − 1, divided by n. On bounties the earlier timestamp wins and the duplicate is not rewarded.

    Source Criteria for Issue Validity, How to Score Issue Points in a Contest, Criteria for Bug Bounty reports validity

  8. Penalties and fees

    Contest payouts are withheld until the account has two valid issues and at least 20% of everything it has submitted is valid. An escalation costs Signal Score that is not refunded, and the window is 24 hours. On bounties, escalating a decision to the claims committee costs $1,000.

    Source Meeting the Payout Criteria, Discussion, Judging, Dispute Resolution

Challenge the filled draft

Paste the report once every placeholder is replaced. The workbench opens with Challenge a draft report selected and argues against each claim: the impact row, the proof, the severity, the known issues. You decide what to rewrite.

The draft stays in this browser. It is sent only when you run a review in the workbench.

Sources

Primary sources only, read on 2 Oct 2026. Rules change. Read the programme page on the day you submit.