Reentrancy attacks are among the most dangerous smart contract vulnerabilities. Learn how they work, see real examples, and discover how to prevent them.
A reentrancy attack occurs when a smart contract calls an external contract before updating its own state. The external contract can then call back into the original contract, exploiting the fact that the state hasn't been updated yet.
Paste Code
Any Solidity contract
AI Analysis
Deep vulnerability scan
Vulnerability Report
Clear findings & severity
Fix & Re-scan
Iterate until clean
A reentrancy attack occurs when a malicious external contract repeatedly calls back into the victim contract before the first execution completes — exploiting state that hasn't been updated yet. The DAO hack in 2016 used this exact pattern to drain $60M in ETH.
The attacker deploys a contract with a fallback function that re-calls the victim's withdraw function. When the victim sends ETH, the fallback triggers before the victim updates its balance mapping — so the attacker can keep withdrawing until the victim's funds are exhausted.
Three defenses work: (1) Follow the checks-effects-interactions pattern — update all state variables before any external call. (2) Use a reentrancy guard (mutex) like OpenZeppelin's ReentrancyGuard. (3) Use Solidity's transfer() or send() instead of call{value:}() for simple ETH sends, as they limit gas forwarding.
Yes — repeatedly. The DAO (2016, $60M), Cream Finance (2021, $130M), and Fei Protocol (2022, $80M) all lost funds to reentrancy variants. Cross-function reentrancy and cross-contract reentrancy remain active threats even in 2024.
Yes. Reentrancy is one of the most well-understood vulnerability classes and a top priority in any professional smart contract audit. SmartContractAuditor.ai's AI scanner detects both single-function and cross-function reentrancy patterns automatically — flagging the exact vulnerable lines and recommended fixes.