Skip to content

Lesson 3 · 3 min · Advanced

Spot the bug: reentrancy

On this page

Spot the bug — reentrancy

The most famous class. A reentrancy bug lets an attacker re-enter the contract before state updates from the first call settle, draining funds. The 2016 DAO hack (~$50M, 3.6M ETH) was a reentrancy, and it split Ethereum into Ethereum and Ethereum Classic.

Re-entering before the balance updates

attacker’s contractVault contract1 · withdraw()balance: 1 ETH2 · send 1 ETH3 · receive() calls withdraw() againbalance still 1 ETHsend 1 ETH…again, until drainedbalance = 0too late
The vault sends ETH before it zeroes the balance. The attacker’s contract receives the ETH and calls withdraw() again, and every re-entry still reads the old balance. Zeroing the balance before the call (checks-effects-interactions) closes the loop.

Vulnerable withdraw

Click the line you think is the bug
Vulnerable withdraw
Educational only, not financial or legal advice.