Which bug classes get accepted

Twelve bug classes, ranked by how often contest judges accepted them. 461 of 1,032 judged findings were accepted; the spread between classes is wide.

Your content never leaves the browser.

Acceptance rate by bug class
Copy
Reentrancyreentrancy 78% 51 40
Overflowoverflow 58% 45 26
Trusted actortrusted-actor 51% 311 159
Fee miscalculationfee-miscalculation 50% 109 55
Stalenessstaleness 49% 174 86
MEV and slippagemev-slippage 49% 89 44
Access controlaccess-control 47% 74 35
Flash loanflash-loanSmall sample 46% 13 6
DoS and griefingdos-griefing 41% 156 64
Roundingrounding 40% 63 25
Oracle manipulationoracle-manipulation 36% 131 47
LiquidationliquidationSmall sample 29% 14 4

Source: Sherlock audit-contest judging repositories on public GitHub, compiled in vulnerability-acceptance-rates.json (methodology), licence CC0, snapshot of 21 July 2026. Only contests whose accepted and invalid counts reconcile with Sherlock’s published results are included. Tags are assigned by keyword and a finding can carry more than one, so the rows overlap.

How to read a row

n is the number of judged findings that carry the tag. Accepted is how many of those the judges accepted. Rate is the second divided by the first.

A row with n under 20 is marked as a small sample. Liquidation (14) and flash loan (13) are the two; one more accepted finding moves either rate by more than seven points.

Every header sorts. Each row has its own link, and the copy button gives the row as one line of Markdown with its source.

Sorting and copying run in this tab. After the page has loaded it makes one request: a counter that says the tool was used, with nothing of yours in it.

What stands out

  • HighReentrancy was accepted 78% (40 of 51), the highest rate in the table. Overflow follows at 58% (26 of 45).
  • SizeTrusted actor is the largest tag, 311 findings, and splits down the middle: 51% (159 of 311).
  • LowOracle manipulation was accepted 36% (47 of 131), rounding 40% (25 of 63), DoS and griefing 41% (64 of 156).

For a class in the lower half, settle three things before you write: who performs each step, whether every precondition is reachable from live state by public calls, and what loss is left after every recovery action.

Find out which side of the rate your finding is on

The triager simulation reads your draft as the programme triager, ranks the three likeliest rejection reasons, quotes the sentence that triggers each and names the evidence that flips it.

More free tools