External Call Vulnerability

Unchecked Call
Return Values

Unchecked call return values occur when contracts ignore whether external calls succeed or fail. Learn how to properly handle external call failures and implement robust error handling.

What are Unchecked Call Return Values?

Unchecked call return values are a vulnerability where smart contracts make external calls but fail to check whether those calls succeeded or failed. This can lead to unexpected behavior when the contract continues execution assuming the call was successful.

Types of External Calls in Solidity

Low-Level Calls

  • • call() - Returns success boolean
  • • delegatecall() - Returns success boolean
  • • staticcall() - Returns success boolean
  • • send() - Returns success boolean

High-Level Calls

  • • transfer() - Throws on failure
  • • Interface calls - May throw or return
  • • Library calls - May throw or return
  • • Try-catch - Explicit error handling
Why External Calls Can Fail

Out of Gas

Target contract runs out of gas during execution, causing the call to fail.

Revert/Require Failures

Target contract explicitly reverts due to failed conditions or require statements.

Non-Existent Contracts

Calling a contract address that has no code or has been destroyed.

Insufficient Funds

Attempting to send more Ether than available in the contract balance.

Impact of Ignoring Call Failures

State Inconsistency

  • • Contract state updated despite call failure
  • • Incorrect balance tracking
  • • Invalid state transitions
  • • Data corruption

Security Implications

  • • Loss of funds
  • • Failed payments assumed successful
  • • Exploitable edge cases
  • • Business logic violations

Frequently Asked Questions

What are unchecked call return values in Solidity?+

When a low-level call (call(), send(), or delegatecall()) fails in Solidity, it returns false instead of reverting. If the return value is not checked, the calling contract continues execution as if the call succeeded — even though it failed silently. This allows attackers to bypass checks or cause the contract to operate on false assumptions.

Why do unchecked return values create security vulnerabilities?+

A contract might call an external contract to perform a critical action (transfer tokens, update state), assume it succeeded, and update its own state accordingly. If the external call failed silently and the return value wasn't checked, the contract's state is now inconsistent — attackers can exploit the gap between what the contract thinks happened and what actually happened.

What is the safe way to handle external calls in Solidity?+

Use high-level function calls when possible (they revert automatically on failure). For low-level calls, always check the return value: `(bool success, ) = target.call{value: amount}(''); require(success, 'Call failed');`. For token transfers, use OpenZeppelin's SafeERC20 library which wraps `transfer()` and `transferFrom()` to revert on failure.

Has unchecked call return value been exploited in real contracts?+

Yes. The King of Ether throne game (2016) famously lost ETH because refunds to previous kings failed silently. Multiple token contracts have lost funds because `transfer()` return values weren't checked — some ERC-20 tokens return false on failure rather than reverting, which standard transfer calls silently ignore.

Does a smart contract audit detect unchecked return values?+

Yes — unchecked return values are a standard audit finding. SmartContractAuditor.ai scans for all low-level call(), send(), and delegatecall() invocations, checks whether their return values are validated, and flags any that could lead to silent failure. It also checks token transfer calls for SafeERC20 compliance.

Audit Your External Call Handling

Our AI-powered scanner identifies unchecked external calls and provides recommendations for proper error handling and return value checking.

Free call safety scan • Instant results • Error handling recommendations