Helen Lai is an Information Security Engineer at XREX. She has led teams to successfully obtain ISO 27001 certification and has conducted in-depth research on Web3 fraud tactics.
Currently, she serves as an operator at DeFiHackLabs, dedicating her efforts to promoting awareness of Web3 cybersecurity.
In 2024, she was a speaker at major conferences such as COSCUP and Web+, sharing insights on Web3 security topics.
Reentrancy Trap: Debunking the Myth of Smart Contract Immutability
Smart contracts, a highly anticipated blockchain technology, face a critical challenge: reentrancy attacks.
These attacks operate like invisible assassins, waiting for the perfect opportunity to strike. Once successful, they can lead to asset loss and even the collapse of an entire system.
Traditional defense mechanisms often address only the symptoms rather than the root cause, making them insufficient in truly mitigating the risk.
In this talk, we will delve into the origins of reentrancy attacks and uncover a crucial truth:
"The essence of a reentrancy attack lies in the inconsistency of smart contract states."
Our discussion will focus on how to approach smart contract design and architecture to ensure state consistency, effectively preventing reentrancy attacks at their core. You will learn:
Why are reentrancy attacks so dangerous?
What is their underlying mechanism, and how do they impact the smart contract ecosystem?
Why is maintaining immutability key?
How does state consistency ensure the security of transactions?
How to build an immutable smart contract?
This talk will introduce various practical design patterns and best practices to strengthen contract security.
By attending this session, you will gain not only an understanding of reentrancy attack defense strategies but also a deeper insight into smart contract security design principles, contributing to a safer and more reliable blockchain ecosystem.
Key Takeaways:
A deep understanding of the nature of reentrancy attacks
Mastering essential principles for secure smart contract development
Enhanced awareness of smart contract security design
Practical defense strategies for developers
CYBERSEC 2025 uses cookies to provide you with the best user experience possible. By continuing to use this site, you agree to the terms in our Privacy Policy 。