Glossary

Reentrancy

A contract flaw where an external call lets an attacker re-enter before state is updated.

Reentrancy happens when a contract sends funds out before it has updated its own bookkeeping, and the recipient's callback calls back in before that update is done. The contract sees the same state twice and pays out twice.

It is one of the most common patterns in historic DeFi exploits because the code reads correctly. The order of a few lines is the entire bug, and it survives an audit that checks logic rather than call ordering.

Most current contracts defend against it by applying the check-effects-interactions pattern: update your state first, then move funds. When reviewing a new protocol, that ordering is one of the fastest things to verify.

Related terms

← All glossary terms