Which bug classes get accepted
Twelve bug classes, ranked by how often contest judges accepted them. 461 of 1,032 judged findings were accepted; the spread between classes is wide.
Your content never leaves the browser.
- 1,032
- 461
- 10
- 12
| Copy | ||||
|---|---|---|---|---|
Reentrancyreentrancy |
78% | 51 | 40 | |
Overflowoverflow |
58% | 45 | 26 | |
Trusted actortrusted-actor |
51% | 311 | 159 | |
Fee miscalculationfee-miscalculation |
50% | 109 | 55 | |
Stalenessstaleness |
49% | 174 | 86 | |
MEV and slippagemev-slippage |
49% | 89 | 44 | |
Access controlaccess-control |
47% | 74 | 35 | |
Flash loanflash-loanSmall sample |
46% | 13 | 6 | |
DoS and griefingdos-griefing |
41% | 156 | 64 | |
Roundingrounding |
40% | 63 | 25 | |
Oracle manipulationoracle-manipulation |
36% | 131 | 47 | |
LiquidationliquidationSmall sample |
29% | 14 | 4 |
Source: Sherlock audit-contest judging repositories on public GitHub, compiled in vulnerability-acceptance-rates.json (methodology), licence CC0, snapshot of 21 July 2026. Only contests whose accepted and invalid counts reconcile with Sherlock’s published results are included. Tags are assigned by keyword and a finding can carry more than one, so the rows overlap.
How to read a row
n is the number of judged findings that carry the tag. Accepted is how many of those the judges accepted. Rate is the second divided by the first.
A row with n under 20 is marked as a small sample. Liquidation (14) and flash loan (13) are the two; one more accepted finding moves either rate by more than seven points.
Every header sorts. Each row has its own link, and the copy button gives the row as one line of Markdown with its source.
Sorting and copying run in this tab. After the page has loaded it makes one request: a counter that says the tool was used, with nothing of yours in it.
What stands out
- Reentrancy was accepted 78% (40 of 51), the highest rate in the table. Overflow follows at 58% (26 of 45).
- Trusted actor is the largest tag, 311 findings, and splits down the middle: 51% (159 of 311).
- Oracle manipulation was accepted 36% (47 of 131), rounding 40% (25 of 63), DoS and griefing 41% (64 of 156).
For a class in the lower half, settle three things before you write: who performs each step, whether every precondition is reachable from live state by public calls, and what loss is left after every recovery action.
Find out which side of the rate your finding is on
The triager simulation reads your draft as the programme triager, ranks the three likeliest rejection reasons, quotes the sentence that triggers each and names the evidence that flips it.