Critical Vulnerability

Reentrancy Attacks
Complete Guide

Reentrancy attacks are among the most dangerous smart contract vulnerabilities. Learn how they work, see real examples, and discover how to prevent them.

Critical1
High
Medium
Low
Info
What is a Reentrancy Attack?

A reentrancy attack occurs when a smart contract calls an external contract before updating its own state. The external contract can then call back into the original contract, exploiting the fact that the state hasn't been updated yet.

How Reentrancy Works

  1. 1
    User calls a function that sends Ether to an external contract
  2. 2
    External contract's fallback function is triggered
  3. 3
    Fallback function calls back into the original contract
  4. 4
    Original contract's state hasn't been updated, allowing exploitation
The DAO Hack: Real-World Impact

Attack Details

  • • Date: June 17, 2016
  • • Amount stolen: 3.6 million ETH (~$60M)
  • • Vulnerability: Reentrancy in withdraw function
  • • Impact: Ethereum hard fork to recover funds

Lessons Learned

  • • Always update state before external calls
  • • Use reentrancy guards
  • • Implement proper testing
  • • Code audits are essential

How It Works

01

Paste Code

Any Solidity contract

02

AI Analysis

Deep vulnerability scan

03

Vulnerability Report

Clear findings & severity

04

Fix & Re-scan

Iterate until clean

Frequently Asked Questions

What is a reentrancy attack in Solidity?+

A reentrancy attack occurs when a malicious external contract repeatedly calls back into the victim contract before the first execution completes — exploiting state that hasn't been updated yet. The DAO hack in 2016 used this exact pattern to drain $60M in ETH.

How does a reentrancy attack work step by step?+

The attacker deploys a contract with a fallback function that re-calls the victim's withdraw function. When the victim sends ETH, the fallback triggers before the victim updates its balance mapping — so the attacker can keep withdrawing until the victim's funds are exhausted.

How can I prevent reentrancy attacks in my smart contract?+

Three defenses work: (1) Follow the checks-effects-interactions pattern — update all state variables before any external call. (2) Use a reentrancy guard (mutex) like OpenZeppelin's ReentrancyGuard. (3) Use Solidity's transfer() or send() instead of call{value:}() for simple ETH sends, as they limit gas forwarding.

Has reentrancy been exploited in real DeFi protocols?+

Yes — repeatedly. The DAO (2016, $60M), Cream Finance (2021, $130M), and Fei Protocol (2022, $80M) all lost funds to reentrancy variants. Cross-function reentrancy and cross-contract reentrancy remain active threats even in 2024.

Does a smart contract audit detect reentrancy vulnerabilities?+

Yes. Reentrancy is one of the most well-understood vulnerability classes and a top priority in any professional smart contract audit. SmartContractAuditor.ai's AI scanner detects both single-function and cross-function reentrancy patterns automatically — flagging the exact vulnerable lines and recommended fixes.

Scan Your Contract for Reentrancy Vulnerabilities

Our AI-powered scanner can instantly detect reentrancy vulnerabilities and provide detailed remediation guidance.

Free vulnerability scan • Instant results • Expert recommendations