Top Tweets for #ReEntrancy
Reentrancy is one of those vulnerabilities everyone's heard of, and yet it still shows up regularly in real-world audits.
A simple breakdown of how it actually works, and why it remains dangerous - from Cyberscope's @yuvanksoni.
👏
#web3security #reentrancy #smartcontractsecurity
One wrong line of code. Millions gone.
One of the most infamous smart contract bugs in crypto history.
Reentrancy, explained simply. 🧵
🧃 First, forget blockchain. Think about a vending machine.
You insert money.
You press a button for a snack.
The machine gives you the snack.
Then it updates its system to say the snack is sold out.
Sounds normal.
Now imagine the machine gives you the snack before it updates its system.
And somehow, you press the button again before the machine realizes the snack is already gone.
You get another snack.
And another.
And another.
Even though you only paid once.
That design flaw is exactly how reentrancy works in smart contracts.
🔁 Now Let Us Move to Smart Contracts
Smart contracts often hold user funds. Think staking contracts, DeFi protocols, NFT mint refunds, lending platforms.
A basic withdrawal function usually does two things:
- Send funds to the user
- Update the user’s balance inside the contract
The order of these steps is extremely important.
A vulnerable contract does this:
First, send ETH to the user
Then, update the user’s balance
That tiny ordering mistake can allow an attacker to drain the contract.
🤖 The Important Detail Most Beginners Miss
On blockchains like Ethereum, the “user” receiving ETH is not always a normal wallet. It can be another smart contract.
And smart contracts can run code automatically the moment they receive ETH.
That means when a vulnerable contract sends ETH to a malicious contract, the attacker’s contract can instantly call back into the original contract before the first function finishes executing.
This is the “re entry” in reentrancy.
🧠 Here Is the Attack in Simple Steps
Let us say you deposited 10 ETH into a contract.
You call withdraw(10).
Step 1, the contract sends you 10 ETH
Step 2, it plans to update your balance to 0
But before step 2 happens, your malicious contract runs code and calls withdraw(10) again.
The contract checks your balance.
It still says 10 ETH, because it has not been updated yet.
So it sends another 10 ETH.
This can repeat multiple times in the same transaction, draining funds that were never yours.
🏴 This Is Not Just Theory
The most famous example of a reentrancy attack was the 2016 exploit on The DAO
An attacker repeatedly re-entered the withdrawal function before balances were updated and drained millions of dollars worth of ETH.
The impact was so big that it led to a controversial Ethereum hard fork.
🔒 How Developers Stop Reentrancy
There is a golden rule in smart contract development:
Update your internal state before sending funds out.
So instead of:
Send ETH
Then reduce balance ❌
You do:
Reduce balance
Then send ETH ✅
This pattern is known as Checks, Effects, Interactions.
You check conditions, update internal data, and only then interact with external contracts.
This “update state before external calls” rule is one of the most common issues we still see during professional smart contract audits at @Cyberscope_io, especially in complex DeFi logic.
🛡️ Extra Protection
Many developers also use a reentrancy guard, which acts like a lock.
Once a function starts running, it cannot be entered again until it finishes.
Security libraries from @OpenZeppelin provide built-in protection that makes this much easier and safer.
⚠️ Why This Bug Is So Dangerous
Reentrancy attacks:
- Happen in a single transaction
- Can drain all funds in a contract
- Are easy to miss in complex DeFi logic
- Still appear in modern exploits
One small mistake in function ordering can lead to catastrophic loss.
🧩 One Sentence Summary
Reentrancy is a vulnerability where a contract sends funds before updating its records, allowing an attacker to repeatedly withdraw more than they should by calling back into the contract before it finishes.
Reentrancy has drained protocols before, and it will happen again.
Retweet to help more builders and investors avoid this.
Follow for more breakdowns of real smart contract exploit patterns.

Learning more about reentrancy and learning how to attack smart contract that have reentrancy hole.
It's only for security research on a road to smart contract security researcher.
#smartcontract #solidity
#reentrancy #programmer

TL;DR
💥 Found $1.2M reentrancy vuln
🧑💻 Used a tool that shows new contracts
🛠 I reviewed the code manually
✅ Reported and patched
🌐 Now sharing the tool
Try it: http://223.130.137.20:8080
#web3 #bugbounty #smartcontracts #security #solidity #reentrancy
Just published a full Foundry-based PoC for the Cross-Contract Reentrancy attack described by @InspexCo:
Focused Solidity test file
Clean repo (no JS / Hardhat)
Extra components: MockRouter, BaseToken
Repo: https://t.co/Du3lmG4OM0
#Web3Security #Reentrancy #Foundry #Solidity
5️⃣Stay Safe!
Reentrancy is one of the most critical vulnerabilities in DeFi.
🔐 Learn how to detect, prevent, and secure smart contracts with me.
Follow @SmartSecAI for daily security insights.
#DeFi #SmartContracts #Web3 #BlockchainSecurity #AI #Reentrancy
Last week, I dived deeper into reentrancy attacks.
I wrote a blog about it. Check it out:
https://t.co/UToQDAKfbF
#Web3 #SmartContracts #Security #Reentrancy #Ethereum

A Historical Collection of Reentrancy Attacks
📷
Types of Reentrancy Attacks:
1. Single-Function Reentrancy
2. Cross-Function Reentrancy
3. Cross-Contract Reentrancy
4. Cross-Chain Reentrancy
5. Read-Only Reentrancy
Link: https://t.co/Lhkcp0JJnc
#Blockchain #Reentrancy #Web3
4/🔍At reCEPTION, our analysis engine detects reentrancy risks in real time, ensuring your smart contracts remain bulletproof before they go live.
🛡️Build safer Web3 with reCEPTION.
#SmartContracts #Web3Security #BlockchainAudit #reentrancy #reCEPTION
🔗Secure your contracts today: https://t.co/rkThIiFQOg
#DeFi #CurveFinance #SmartContractSecurity #Vyper #BlockchainSecurity #HackBreakdown #OdinAudit #Web3 #Reentrancy
Compilation of Reentrancy Attacks through the ages by @pcaversaccio
https://t.co/OpQWPSYJDo
#reentrancy #blockchain #securityresearch #cibersecurity
SEPTEMBER HACKFEST: $120M lost in 20+ crypto hacks! BingX, Penpie, Indodax hit for $92M total. Even Euler hacker joined the party. Welcome to DeFi school, paid in $ETH.
#CryptoHacks #DeFi #Blockchain #CryptoNews #Penpie #BingX #Indodax #Web3 #ETH #Reentrancy #Hackers

Started reading about #Reentrancy attack from @PatrickAlphaC 's Smart contract security course from @CyfrinUpdraft. While checking the reentrancy attacks of 2024, found that almost 11 attacks have occurred till now!!!

I was looking at this smart contract where I found a reentracy vulnerability in it and now I did some practice on it now I know on how I spot , find and prevent reentracy attacks on smart contracts #web3security #smartcontract #reentrancy #blockchian #BlockchainSecurity

🔍 The security benefits and challenges of #Clarity uncovered 📃
Discover how the smart contract programming language prevents #reentrancy attacks and integer overflows, as well as its limitations 🔐
📖 Read the second article of our series 👇 https://t.co/IkRv1yB2Za
🔍 Reentrancy is a critical vulnerability in Solidity that can lead to severe exploits. Let's dive in! #Reentrancy #Solidity #Blockchain
That's it for my #Reentrancy thread! I hope this has been enlightening on the importance of secure smart contract development. For more details on securing your smart contracts against reentrancy attacks, check out this great article at https://t.co/PiQyX4oX0J. Stay tuned for more insights on #Blockchain and #SmartContractSecurity! Follow me for more 🧵🔚
VỤ KYBERSWAP BỊ TẤN CÔNG
(Cập nhật và góc nhìn kỹ thuật)
☑️TÓM TẮT VỤ TẤN CÔNG
Vào ngày 23 tháng 11 năm 2023, #KyberSwap, một sàn giao dịch phi tập trung (#DEX) đa chuỗi, đã bị tấn công dạng #reentrancy vào #Smartcontract của mình.
Cuộc tấn công này đã khiến KyberSwap thiệt hại 47 triệu đô la (Arbitrum: 20M$, Optimism: 15M$; Kyber Mainnet: 7,5M$; Polygon: 2M$; Base: 315.000 đô la)
Total Value Locked giảm 90% từ 84,9 triệu đô la xuống còn 8,28 triệu đô la vào ngày xảy ra vụ tấn công, (Ban đầu, việc khai thác đã dẫn đến thiệt hại trực tiếp 49M$. Sau đó, sau khuyến nghị của KyberNetwork người dùng đã rút thêm 27M$ khỏi Aggregator)
Update thông tin mới nhất ngày hôm qua 03/12, Theo PeckShieldAlert hacker đã chuyển hơn 2.010 ETH từ Arbitrum sang Ethereum, sau đó gửi 1.000 ETH đến Tornado Cash ( hệ thống trộn che dấu hoàn toàn danh tính) theo nhiều giao dịch nhỏ, mỗi lần 100 ETH để tẩu tán từ ví chính. Hành động này cho thấy cuộc thương lượng hacker vs Kyber Network có vẻ đã thất bại.
☑️KỸ THUẬT TẤN CÔNG
Theo một số phân tích ghi nhận, Kẻ tấn công sử dụng kiểu tấn công reentrancy attacks, nhằm khai thác một lỗ hổng trong chức năng mint của phiên bản nâng cấp v2 reinvestment token (KS2-RT) của KyberSwap.
☑️LỔ HỔNG TRONG SMART CONTRACT
Reentrancy attack thực hiện khi một smartcontract gọi lại chính nó trong khi vẫn đang thực thi một giao dịch trước đó. Điều này có thể dẫn đến:
🔹Tạo ra thanh khoản ảo: Kẻ tấn công tạo ra một lượng lớn thanh khoản ảo, vượt quá số lượng thanh khoản thực tế trong pool. Điều này có thể khiến kẻ tấn công mua lại các token với giá thấp hơn giá thị trường.
🔹Kẻ tấn công có thể sử dụng để thực hiện rút tiền từ các tài khoản hoặc đánh cắp dữ liệu.
🔹Đây là loại tấn công vào lỗ hổng của smartcontract, với mã: Vulnerable Contract KS2-RT: Smart Contract Tracker.
☑️BIỆN PHÁP PHÒNG TRÁNH
Có một số giải pháp tổng thể như sau:
🔹Sử dụng các giao thức smartcontract an toàn: Một số giao thức smartcontract được thiết kế để bảo vệ chống lại các cuộc tấn công reentrancy. Ví dụ: giao thức SafeMath của OpenZeppelin cung cấp các hàm để giúp ngăn chặn các lỗi logic.
🔹Tuân thủ các nguyên tắc bảo mật trong phát triển phần mềm: Các coder, security engineer... cần tuân thủ các nguyên tắc bảo mật trong quá trình phát triển, thiết lập smartcontract hoặc nâmg cấp phiên bản hệ thống. Điều này bao gồm việc tránh các lỗi phổ biến như reentrancy.
🔹Thường xuyên thực hiện audit: Các nền tảng DeFi nên thường xuyên thực hiện audit bởi các công ty kiểm toán uy tín để phát hiện và sửa chữa các lỗ hổng bảo mật. Đặc biệt là khi nâng cấp bổ sung tính năng cho hệ thống
🔹Giám sát real-time: Các nền tảng DeFi cần giám sát liên tục hoạt động của mạng để phát hiện và phản hồi các giao dịch đáng ngờ.
✴️TÓM LẠI
🔹Vụ tấn công vào KyberSwap - một kỳ lân của VN là một vụ tấn công gây thiệt hại nghiêm trọng
🔹Khả năng cao khó đạt đc một thoả thuận với hacker do đã có dấu hiệu tẩu tán tài sản ẩn danh Tornado Cash
🔹Bỏ qua các vấn đề khác, dưới góc nhìn kỹ thuật, các nền tảng Dex không chỉ KyberSwap sẽ luôn còn tiềm ẩn nhiều nguy cơ sau vụ này nếu không có chiến lược bảo mật đủ tốt
Bài viết là góc nhìn cá nhân, Chúc AE ngày mới vui vẻ 🥰

VỤ KYBERSWAP BỊ TẤN CÔNG
(Cập nhật và góc nhìn kỹ thuật)
☑️TÓM TẮT VỤ TẤN CÔNG
Vào ngày 23 tháng 11 năm 2023, #KyberSwap, một sàn giao dịch phi tập trung (#DEX) đa chuỗi, đã bị tấn công dạng #reentrancy vào #Smartcontract của mình.
Cuộc tấn công này đã khiến KyberSwap thiệt hại 47 triệu đô la (Arbitrum: 20M$, Optimism: 15M$; Kyber Mainnet: 7,5M$; Polygon: 2M$; Base: 315.000 đô la)
Total Value Locked giảm 90% từ 84,9 triệu đô la xuống còn 8,28 triệu đô la vào ngày xảy ra vụ tấn công, (Ban đầu, việc khai thác đã dẫn đến thiệt hại trực tiếp 49M$. Sau đó, sau khuyến nghị của KyberNetwork người dùng đã rút thêm 27M$ khỏi Aggregator)
Update thông tin mới nhất ngày hôm qua 03/12, Theo PeckShieldAlert hacker đã chuyển hơn 2.010 ETH từ Arbitrum sang Ethereum, sau đó gửi 1.000 ETH đến Tornado Cash ( hệ thống trộn che dấu hoàn toàn danh tính) theo nhiều giao dịch nhỏ, mỗi lần 100 ETH để tẩu tán từ ví chính. Hành động này cho thấy cuộc thương lượng hacker vs Kyber Network có vẻ đã thất bại.
☑️KỸ THUẬT TẤN CÔNG
Theo một số phân tích ghi nhận, Kẻ tấn công sử dụng kiểu tấn công reentrancy attacks, nhằm khai thác một lỗ hổng trong chức năng mint của phiên bản nâng cấp v2 reinvestment token (KS2-RT) của KyberSwap.
☑️LỔ HỔNG TRONG SMART CONTRACT
Reentrancy attack thực hiện khi một smartcontract gọi lại chính nó trong khi vẫn đang thực thi một giao dịch trước đó. Điều này có thể dẫn đến:
🔹Tạo ra thanh khoản ảo: Kẻ tấn công tạo ra một lượng lớn thanh khoản ảo, vượt quá số lượng thanh khoản thực tế trong pool. Điều này có thể khiến kẻ tấn công mua lại các token với giá thấp hơn giá thị trường.
🔹Kẻ tấn công có thể sử dụng để thực hiện rút tiền từ các tài khoản hoặc đánh cắp dữ liệu.
🔹Đây là loại tấn công vào lỗ hổng của smartcontract, với mã: Vulnerable Contract KS2-RT: Smart Contract Tracker.
☑️BIỆN PHÁP PHÒNG TRÁNH
Có một số giải pháp tổng thể như sau:
🔹Sử dụng các giao thức smartcontract an toàn: Một số giao thức smartcontract được thiết kế để bảo vệ chống lại các cuộc tấn công reentrancy. Ví dụ: giao thức SafeMath của OpenZeppelin cung cấp các hàm để giúp ngăn chặn các lỗi logic.
🔹Tuân thủ các nguyên tắc bảo mật trong phát triển phần mềm: Các coder, security engineer... cần tuân thủ các nguyên tắc bảo mật trong quá trình phát triển, thiết lập smartcontract hoặc nâmg cấp phiên bản hệ thống. Điều này bao gồm việc tránh các lỗi phổ biến như reentrancy.
🔹Thường xuyên thực hiện audit: Các nền tảng DeFi nên thường xuyên thực hiện audit bởi các công ty kiểm toán uy tín để phát hiện và sửa chữa các lỗ hổng bảo mật. Đặc biệt là khi nâng cấp bổ sung tính năng cho hệ thống
🔹Giám sát real-time: Các nền tảng DeFi cần giám sát liên tục hoạt động của mạng để phát hiện và phản hồi các giao dịch đáng ngờ.
✴️TÓM LẠI
🔹Vụ tấn công vào KyberSwap - một kỳ lân của VN là một vụ tấn công gây thiệt hại nghiêm trọng
🔹Khả năng cao khó đạt đc một thoả thuận với hacker do đã có dấu hiệu tẩu tán tài sản ẩn danh Tornado Cash
🔹Bỏ qua các vấn đề khác, dưới góc nhìn kỹ thuật, các nền tảng Dex không chỉ KyberSwap sẽ luôn còn tiềm ẩn nhiều nguy cơ sau vụ này nếu không có chiến lược bảo mật đủ tốt
Bài viết là góc nhìn cá nhân, Chúc AE ngày mới vui vẻ 🥰
Last Seen Hashtags on Sotwe
สวิงกิ้งสระบุรี
Seen from Thailand
คอลเสียว
Seen from Thailand
cheat((()))*************************************************
ควยเพื่อน
Seen from Thailand
寸止
Seen from Japan
omegle
momson() nolimit()* filter:native_video
Seen from United States
hot thai massage
Seen from Netherlands
konyatravesti
Seen from Germany
응원해주는마음
Seen from Brazil
Trends for you
Most Popular Users

Elon Musk 
@elonmusk
241.5M followers

Barack Obama 
@barackobama
119M followers

Cristiano Ronaldo 
@cristiano
113.8M followers

Donald J. Trump 
@realdonaldtrump
111.8M followers

Narendra Modi 
@narendramodi
107.2M followers

Rihanna 
@rihanna
98.6M followers

NASA 
@nasa
92.4M followers

Justin Bieber 
@justinbieber
91.7M followers

KATY PERRY 
@katyperry
89.6M followers

Taylor Swift 
@taylorswift13
83.6M followers

Lady Gaga 
@ladygaga
75M followers

Virat Kohli 
@imvkohli
72.8M followers

Kim Kardashian 
@kimkardashian
70.7M followers

YouTube 
@youtube
68.8M followers

Neymar Jr 
@neymarjr
65.8M followers

Bill Gates 
@billgates
64.9M followers

Selena Gomez 
@selenagomez
62.7M followers

The Ellen Show
@theellenshow
62.3M followers

CNN 
@cnn
61.8M followers

X 
@x
60.7M followers





















