Teaching the next generation of web3 developers.
150+ hours of Smart Contract Development and Security Courses, completely for Free.
Powered by @cyfrin
Reentrancy is still one of the most common vulnerabilities in production contracts. Understanding it means understanding Solidity's execution model at a fundamental level.
Learn to find and exploit bugs like this in the Security and Auditing course on Updraft, completely free:
https://t.co/G69QNlWvJp
The `refund` function in PuppyRaffle sends ETH before updating state.
That's textbook reentrancy. Here's exactly how an attacker drains the entire contract. 🧵
The fix is simple. Update state BEFORE making the external call:
```
players[playerIndex] = address(0);
emit RaffleRefunded(playerAddress);
payable(msg.sender).sendValue(entranceFee);
```
This is called Checks-Effects-Interactions. If the attacker reenters, the require fails because their slot is already zeroed out. ✅
Reentrancy is one of the first exploits you should learn to recognize and prevent.
We break down this attack and dozens more in the free Smart Contract Security course on Updraft:
https://t.co/Wd3pUlgLb9
Reentrancy has drained hundreds of millions from smart contracts. The original DAO hack. Countless DeFi protocols since.
It all comes down to one mistake: making an external call before updating state. 🧵
Slither catches this automatically. It flagged the refund function in the lesson's codebase for exactly this pattern. Static analysis tools aren't optional. Run them. ⚠️
Want to actually understand the protocols you're depositing into, not just follow UIs blindly?
Learn DeFi from the ground up on Updraft:
https://t.co/SBUVNHuFry
Most people stake ETH and stop there.
But you can stack yield on top of yield by routing through Balancer and Aura Finance.
Here's how rETH holders can earn BAL, AURA, and RPL on top of their staking rewards. 🧵
Step 4: Claim your rewards.
Go to the Claim tab, select all reward tokens, and hit Claim Rewards. That's it.
⚠️ Remember: more layers of DeFi means more smart contract risk. Understand every protocol you're trusting with your funds.
Want to understand what's really happening under the hood in gas-optimized contracts?
Learn formal verification and smart contract security on Updraft, completely free:
https://t.co/3mbvmSgJbx
Most Solidity devs have never manually emitted an event using assembly.
But gas-optimized contracts do it all the time. Here's how log4 actually works at the EVM level. 🧵
The catch: assembly events skip all the safety checks Solidity gives you.
Wrong topic hash? Wrong parameter order? It'll compile fine and emit garbage. In an audit, every log opcode gets manually verified against the original event definition. ⚠️