Reentrancy Attack

Last Updated Sep 24, 2026

In One Sentence

A reentrancy attack abuses a callback into a contract before an earlier operation has safely completed its state changes.

Definition

A reentrancy attack exploits unexpected repeated entry into contract logic during an unfinished operation. Smart contracts can call other contracts, and the called code may in turn call back before the original invocation returns. If the original contract relies on state that has not yet been brought into a consistent condition, the callback can violate its intended accounting or authorization rules.

How It Works

A conceptual example is a withdrawal process that makes an external interaction before recording the corresponding balance change. A callback could observe the old balance and trigger behavior the developer intended to allow only once. Reentrancy can cross functions or contracts, and some forms exploit inconsistent reads rather than directly repeating a withdrawal. Not every callback is malicious; the vulnerability is the unsafe assumption about what can happen during external control.

Key Considerations

Developers commonly combine careful ordering of checks and state updates, reentrancy guards, limited external interactions, and designs that maintain valid invariants across calls. No single pattern substitutes for understanding every relevant execution path. Reviews and tests should include cross-function interactions, callbacks from token standards, and dependencies on other contracts. Users cannot determine safety solely from a familiar interface or a prior audit badge. An incident may require pausing affected functionality and reviewing the exact deployed code; remediation must address the underlying state assumptions rather than merely blocking one observed caller.