# Reentrancy Content type: Glossary Term Summary: A smart-contract vulnerability where an external call re-enters a contract before the original execution safely completes state updates. Key concepts: Highlights critical security design flaws, Forces developers to adopt defensive coding, Major financial security risk, Prevents simple, intuitive state management, Requires complex mitigation patterns like mutexes Related resources: - Phishing (Glossary Term): https://theblockchainlibrary.com/glossary/phishing - Private Key (Glossary Term): https://theblockchainlibrary.com/glossary/private-key - Smart Contract Audit (Glossary Term): https://theblockchainlibrary.com/glossary/smart-contract-audit - Sybil Attack (Glossary Term): https://theblockchainlibrary.com/glossary/sybil-attack - 51% Attack (Glossary Term): https://theblockchainlibrary.com/glossary/51-attack - Address Poisoning (Glossary Term): https://theblockchainlibrary.com/glossary/address-poisoning
advanced

Reentrancy

A smart-contract vulnerability where an external call re-enters a contract before the original execution safely completes state updates.

Explain Like I'm 12

A smart-contract vulnerability where an external call re-enters a contract before the original execution safely completes state updates.

Why It Matters

Security concepts help users and developers recognize common blockchain attack surfaces and defenses.

How It Works

The victim contract performs an external call (like sending ETH). The malicious contract's fallback function is triggered, which calls back into the victim contract's withdrawal function. Since the state variable (balance) has not been updated yet, the logic allows another withdrawal, repeating this cycle.

Real-World Example

The 2016 DAO attack remains the most infamous example of a reentrancy exploit, which led to the Ethereum hard fork.

Advantages

  • Highlights critical security design flaws
  • Forces developers to adopt defensive coding

Limitations

  • Major financial security risk
  • Prevents simple, intuitive state management
  • Requires complex mitigation patterns like mutexes

Common Misconceptions

  • Many think only malicious contracts cause this, but it is actually the vulnerable contract's poor design.
  • Developers often assume 'checks-effects-interactions' pattern is easy, but it requires extreme discipline.

Knowledge Explorer

Explore This Concept in the Knowledge Graph

See how Reentrancy connects to other concepts, books, research, and developer resources.

Explore Connections

Related Terms

Phishing

Phishing is a social engineering attack where malicious actors impersonate legitimate platforms, services, or individuals to deceive users into disclosing sensitive information, such as private keys, seed phrases, or login credentials. In the crypto sector, phishing is highly sophisticated; attackers often create fake websites, send fraudulent emails, or use social media bots to trick users into signing malicious transactions that drain their wallets.

Private Key

A private key is a secret, mathematically generated string of characters that grants the owner complete control over an associated cryptocurrency address. It acts as a digital signature tool, allowing users to authorize transactions and prove ownership of funds. In a decentralized network, the private key is the ultimate proof of authority; whoever possesses the private key effectively owns the assets associated with the corresponding address. It is never meant to be shared with anyone.

Smart Contract Audit

A structured review of smart-contract code and system design intended to identify vulnerabilities, logic errors, and security risks.

Sybil Attack

A Sybil attack is a security threat in decentralized networks where an attacker creates a large number of pseudonymous identities to gain a disproportionate influence over the system. By controlling the majority of nodes or participating addresses, the attacker can disrupt network consensus, censor transactions, or manipulate voting processes in governance mechanisms, thereby subverting the decentralization and integrity of the blockchain.

51% Attack

An attack where one entity or coalition controls enough consensus power to reorganize blocks, censor transactions, or attempt double spending.

Address Poisoning

A scam where attackers create lookalike address activity so victims may accidentally send funds to the wrong address.