OWASP Smart Contract Top 10: 2026 — Reentrancy Falls to #8, Proxy Bugs Enter, and Your New Audit Priorities
TL;DR The OWASP Smart Contract Top 10: 2026 is live. Based on 2025 incident data and practitioner surveys, it reshuffles the risk landscape. Reentrancy dropped from #2 to #8. Proxy & Upgradeabi...

Source: DEV Community
TL;DR The OWASP Smart Contract Top 10: 2026 is live. Based on 2025 incident data and practitioner surveys, it reshuffles the risk landscape. Reentrancy dropped from #2 to #8. Proxy & Upgradeability Vulnerabilities entered at #10 — a brand new category. And Business Logic Vulnerabilities climbed to #2, reflecting where the real money is being lost. If you're still auditing like it's 2023, this ranking is your wake-up call. What Changed (and Why It Matters) The 2026 Ranking # Category Trend SC01 Access Control Vulnerabilities → Stable at #1 SC02 Business Logic Vulnerabilities ↑ New to Top 3 SC03 Price Oracle Manipulation → Stable SC04 Flash Loan–Facilitated Attacks → Stable SC05 Lack of Input Validation ↑ Climbed SC06 Unchecked External Calls → Stable SC07 Arithmetic Errors ↓ Dropped SC08 Reentrancy Attacks ↓↓ Fell from #2 SC09 Integer Overflow and Underflow ↓ Dropped SC10 Proxy & Upgradeability Vulns 🆕 New entry Three shifts stand out. Let's unpack each. 1. Reentrancy: From #2