Library · Crypto, word by word · Scams and security

What is a reentrancy attack?

A reentrancy attack is a smart contract exploit in which a malicious contract calls back into a victim contract before the victim has finished its first run. If the victim pays out before updating its records, the attacker can withdraw the same balance again and again.

What it means for you

You cannot spot this bug from your wallet; it lives in the code of the app holding your deposit. Before depositing, you can check whether the contract's source is verified on a block explorer and whether published audits looked for reentrancy. Funds drained this way are usually gone, because the chain records each withdrawal as valid.

How it works

When contract A sends ether to, or calls, contract B, control passes to B, as the Solidity documentation explains. If B is malicious, its code can call A's withdraw function again while A is still mid-execution. If A sends funds first and lowers the stored balance afterwards, each nested call sees the old balance and pays again. The standard defence is the checks-effects-interactions pattern: check conditions, update state, and only then make external calls. A mutex, or reentrancy lock, that stops a function being entered twice is another defence ethereum.org describes.

An example

Say a vault holds 100 ETH and you deposit 1 ETH from a malicious contract. The vault's withdraw function sends your 1 ETH, then sets your balance to zero. Your contract's receive code calls withdraw again before that zeroing happens, and each call still sees a balance of 1 ETH. Repeated over and over inside one transaction, the loop empties the vault.

Sources: Solidity documentation: Security considerations (re-entrancy), ethereum.org: Smart contract security · checked 4 October 2026

Related words

Smart contractSmart contract auditSolidityVerified contractFlash loan

Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.