freecoding.school100% FREE · NO SIGNUP
Ledger LandISSUE #86 of 90

security · reentrancy · overflow · access control

BlockyVSDouble-Spend Dan
Blocky saysTop contract vulnerabilities: reentrancy, integer overflow, and broken access control.

The recurring killers: reentrancy (a called contract calls back before your state updates — the DAO hack; fix with checks-effects-interactions or a guard), integer overflow (mostly solved by Solidity 0.8+'s checked math), and access control (missing onlyOwner-style checks letting anyone call privileged functions). Most exploits trace to one of these patterns.

Power-ups you unlock

Double-Spend Dan attacks — common mistakes

Boss battleExplain the checks-effects-interactions order and why it stops reentrancy.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>bad:  send funds → then update balance (reentrant!)
good: checks → effects (update state) → interactions (send)</pre></body></html>
▶ Open the interactive comic issue
‹ Gas Optimization · Packing Storage · Short-CircuitAudits · Slither · Mythril · Manual Review ›