Executive brief
Vyper is a Python-based smart contract programming language for Ethereum. The @nonreentrant decorator is designed to prevent reentrancy attacks, a critical security vulnerability in blockchain contracts. When developers accidentally use an empty string as the lock key (e.g., @nonreentrant("")), the decorator fails silently and provides no reentrancy protection, leaving smart contracts vulnerable to exploitation.
Technical details
The vulnerability is a logic error in Vyper's reentrancy lock implementation where empty-string lock keys are not validated. When @nonreentrant("") or @nonreentrant('') is used, the decorator does not generate any runtime reentrancy checks, contrary to the developer's intent. The attack vector requires network access to call the unprotected function, with no authentication required. An attacker can invoke the vulnerable function multiple times in the same transaction context to perform reentrancy attacks and manipulate contract state or steal funds. The vulnerability was patched in Vyper 0.3.10 (PR #3605), and the workaround is to use a non-empty string for lock keys.
Affected products
- Vyper Vyper >=0.2.9, <0.3.10
Timeline
- 2023-09-18: disclosed
- 2023-09-18: patched: Patched in version 0.3.10