Dev.to
7/24/2026

I'm Entering My First Sherlock Audit Contest: The Setup, the Plan, the Fear
Short summary
An experienced crypto developer documents their preparation for their first Sherlock smart contract audit contest, sharing methodology and honest fears. The approach combines reading past contest reports to learn severity patterns, using local LLMs (Ollama with qwen2.5-coder) as attack-path idea generators, and requiring Foundry proof-of-concept tests for every submission. The goal isn't to win but to submit two fully defensible findings.
- •Read past contest reports to learn what counts as valid severity
- •Use LLMs for attack path enumeration, not as oracles—validate with Foundry PoCs
- •Goal for first contest: submit 2 defensible issues, not win
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



