High Severity
Gas & Control Flow

Denial of Service in Smart Contracts

A contract doesn't need to be drained to be broken. DoS vulnerabilities make functions permanently uncallable — locking user funds, freezing governance, or halting an entire protocol — without a single token leaving.

Three ways DoS kills contracts

Unbounded loops

A loop over an array that anyone can grow will eventually exceed the block gas limit. Once the array is long enough, the function can never complete — it always runs out of gas.

Push payment trap

When a contract sends ETH to a list of recipients in a single transaction, any one failed transfer (e.g., to a contract without a receive() function) blocks all remaining payouts.

External call reverts blocking state

If a contract calls an external address and that call reverts, the whole transaction rolls back. An attacker who controls that address can permanently prevent state changes from happening.

Real-world incidents

ProtocolYearPatternImpact
GovernMental2016Unbounded loop in jackpot payout1,100 ETH locked (recovered via mining)
King of the Ether2016Push payment to contract without receive()Refund permanently stuck
Auction contracts (generic)OngoingrefundAll() loop over bidder arrayFunds locked when array grows large
DAO-style voting contractsOngoingVote tallying over unbounded voter listexecuteProposal() becomes uncallable

Scan for DoS vulnerabilities

Our scanner checks your contract for unbounded loops, push payment patterns, and external calls that could lock user funds or halt protocol operations.