Unchecked call return values occur when contracts ignore whether external calls succeed or fail. Learn how to properly handle external call failures and implement robust error handling.
Unchecked call return values are a vulnerability where smart contracts make external calls but fail to check whether those calls succeeded or failed. This can lead to unexpected behavior when the contract continues execution assuming the call was successful.
Target contract runs out of gas during execution, causing the call to fail.
Target contract explicitly reverts due to failed conditions or require statements.
Calling a contract address that has no code or has been destroyed.
Attempting to send more Ether than available in the contract balance.
When a low-level call (call(), send(), or delegatecall()) fails in Solidity, it returns false instead of reverting. If the return value is not checked, the calling contract continues execution as if the call succeeded — even though it failed silently. This allows attackers to bypass checks or cause the contract to operate on false assumptions.
A contract might call an external contract to perform a critical action (transfer tokens, update state), assume it succeeded, and update its own state accordingly. If the external call failed silently and the return value wasn't checked, the contract's state is now inconsistent — attackers can exploit the gap between what the contract thinks happened and what actually happened.
Use high-level function calls when possible (they revert automatically on failure). For low-level calls, always check the return value: `(bool success, ) = target.call{value: amount}(''); require(success, 'Call failed');`. For token transfers, use OpenZeppelin's SafeERC20 library which wraps `transfer()` and `transferFrom()` to revert on failure.
Yes. The King of Ether throne game (2016) famously lost ETH because refunds to previous kings failed silently. Multiple token contracts have lost funds because `transfer()` return values weren't checked — some ERC-20 tokens return false on failure rather than reverting, which standard transfer calls silently ignore.
Yes — unchecked return values are a standard audit finding. SmartContractAuditor.ai scans for all low-level call(), send(), and delegatecall() invocations, checks whether their return values are validated, and flags any that could lead to silent failure. It also checks token transfer calls for SafeERC20 compliance.