Reentrancy Attack
Also known as: Recursive Call Exploit, Smart Contract Reentry, Contract Loop Vulnerability
A smart contract vulnerability where an external call reenters the same contract before its previous execution completes.
A reentrancy attack is a vulnerability in smart contracts where an external contract is called and reenters the original contract before the first invocation is completed. This can lead to unexpected state changes and fund extraction. The infamous DAO hack on Ethereum exploited this bug to drain millions. Developers prevent such attacks using design patterns like checks-effects-interactions and Solidity’s `reentrancyGuard`. Reentrancy illustrates the complexity and risk of composable smart contracts and emphasizes the need for formal verification and secure coding standards.
