logo

Cross-Function Reentrancy Attacks in Kadena Smart Contracts

ID: 7debad60-0520-5fc6-a86a-84644092bbfd

STIX ID: report--7debad60-0520-5fc6-a86a-84644092bbfd

Feed Name: CertiK Blog

Threat Score
50/100

Date Published: 2023-01-17

Date Updated: 2026-06-11

...
...

This report analyzes a proof-of-concept cross-function reentrancy attack against Kadena's Pact smart contract language: a malicious external module is granted a capability during execution and reenters a different function to inflate an attacker's balance, demonstrating that Turing incompleteness (no unbounded recursion) does not prevent all reentrancy vectors and recommending careful auditing of Pact contracts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.