Scanner Benchmark

QUICK ANSWER

We ran our scanner on 23 small Solidity contracts that each contain one known bug, most modeled on real exploits like The DAO (2016) and Parity (2017). It flagged 23 of 23. On 18 patched or correctly written contracts it raised no high or critical finding, and on 16 audited OpenZeppelin contracts it reported nothing at all.

23/23
known bugs detected
0/18
safe contracts with a high/critical alarm
0/16
OpenZeppelin contracts flagged
13
bug classes covered

Vulnerable contracts

ContractBug classModeled onResult
dao reentrancyReentrancyThe DAO (2016)criticalReentrancy: credit updated after external call in withdraw()
bank reentrancyReentrancySWC-107criticalReentrancy: balances updated after external call in withdrawAll()
poly access controlAccess controlPoly Network (2021)criticalMissing access control: anyone can change keeper via putCurEpochConPubKeyBytes()
unprotected ownerAccess controlEthernaut: FalloutcriticalMissing access control: anyone can change owner via setOwner()
unprotected mintAccess controlSWC-105criticalMissing access control: unrestricted mint in mint()
cream spot oracleSpot price oracleCream Finance (2021)highManipulable spot price oracle in getPrice()
tx origin wallettx.origin authorizationSWC-115hightx.origin used for authorization in transferTo()
unchecked sendUnchecked send / callSWC-104highUnchecked return value of .send() in sendToWinner()
overflow legacyInteger overflow (pre-0.8)SWC-101 / BeautyChain (2018)highInteger overflow/underflow: Solidity ^0.6.0 without SafeMath
delegatecall proxyDelegatecallSWC-112 / ParitycriticalDelegatecall to caller-supplied address in forward()
timestamp gameTimestamp-based outcomeSWC-116highPredictable randomness from block.timestamp (timestamp-dependent outcome) in receive()
weak randomnessPredictable randomnessSWC-120 / Ethernaut: Coin FliphighPredictable randomness from block.timestamp (timestamp-dependent outcome) in pickWinner()
unprotected selfdestructUnprotected selfdestructSWC-106 / Parity (2017)criticalUnprotected selfdestruct in kill()
unbounded loop dosDenial of serviceSWC-128highDenial of service: unbounded loop with payments in distribute()
king dosDenial of serviceEthernaut: KinghighDenial of service: refund to king can block receive()
signature replaySignature replaySWC-121highSignature replay: claim() accepts the same signature repeatedly
unprotected initializerUnprotected initializerWormhole / Nomad-style upgrade bugscriticalUnprotected initializer: initialize() can be called by anyone, any time
reentrancy cross functionReentrancySWC-107 (cross-function)criticalReentrancy: stakes updated after external call in unstake()
oracle balance priceSpot price oracleHarvest / bZx-style balance oracleshighManipulable spot price oracle in sharePrice()
tx origin ownershiptx.origin authorizationEthernaut: Telephonehightx.origin used for authorization in changeOwner()
reentrancy delete after callReentrancySWC-107 variantcriticalReentrancy: deposits updated after external call in refund()
unprotected oracle setterAccess controlUnprotected price feed settercriticalMissing access control: anyone can change priceFeed via setPriceFeed()
unchecked payable sendUnchecked send / callSWC-104 varianthighUnchecked return value of .send() in split()

Safe contracts (false-alarm check)

Patched twins of the bugs above plus common correct patterns that crude scanners misfire on: OpenZeppelin initializers, nonce-protected signatures, pull payments, SafeMath on Solidity 0.7, Chainlink price feeds, two-step ownership and proxies.

ContractPatternResult
dao reentrancy fixedReentrancyNo high/critical alarm
owner fixedAccess controlNo high/critical alarm
wallet msg sendertx.origin authorizationNo high/critical alarm
checked callUnchecked send / callNo high/critical alarm
simple tokenInteger overflow (pre-0.8)No high/critical alarm
init guarded flagUnprotected initializerNo high/critical alarm
init oz modifierUnprotected initializerNo high/critical alarm
signature with nonceSignature replayNo high/critical alarm
king pull paymentDenial of serviceNo high/critical alarm
batch airdrop calldataDenial of serviceNo high/critical alarm
safemath legacyInteger overflow (pre-0.8)No high/critical alarm
chainlink oracleSpot price oracleNo high/critical alarm
guarded selfdestructUnprotected selfdestructNo high/critical alarm
timelock deadlineTimestamp-based outcomeNo high/critical alarm
paid nft mintAccess controlNo high/critical alarm
two step ownershipAccess controlNo high/critical alarm
guarded reentrancyReentrancyNo high/critical alarm
minimal proxyDelegatecallNo high/critical alarm

How we measure it

A contract only counts as detected if the scanner reports a critical or high finding in the same bug class as the planted bug. An unrelated warning doesn't count.

A safe contract fails if it gets any high or critical finding, in any class. That's stricter than counting only same-class mistakes, because noise is noise.

These are small, single-bug contracts, so this measures whether each detector works, not how the scanner handles a 3,000-line protocol. Treat any scanner as a first pass before a manual audit.

Last run 2026-10-04. Engine: Pattern engine (same for free and Pro; Pro adds Claude AI analysis on top).

Think you can break it?

This is our benchmark. If you find a vulnerable contract it misses, or a safe one it flags, send it in. Confirmed finds get fixed and credited.

Scan a contract free

FAQ

How accurate is the SmartContractAuditor.ai scanner?

On our public benchmark it detected 23 of 23 known-vulnerable contracts and raised no high or critical finding on 18 safe contracts. It also reported nothing on 16 audited OpenZeppelin v4 and v5 contracts.

What counts as a detection?

The scanner has to report a critical or high finding in the same bug class as the planted bug. A serious finding about something unrelated doesn't count, so noise can't inflate the score.

Does this replace a manual smart contract audit?

No. These are small contracts with one bug each, and real code is harder. Use the scanner as a first pass to catch the well-known bug classes before you pay for a manual audit, not instead of one.

Is the free scanner different from Pro?

No. Free and Pro run the same 13 pattern detectors, so these results apply to both. Pro adds an AI review on top, plus PDF reports and full scan history.

Written by Duron Epps, Founder ยท Last updated October 2026