NeoField

The Reentrancy You Didn't See in Restaking: A Code Audit of LRT's Withdrawal Gap

CryptoTiger
Interviews

I found the bug at block 19,402,118. Not in a shadowy fork, but in the public deposit contract of a liquid restaking token that had raised $200 million. The fix was three lines of code. The vulnerability? A missing reentrancy guard in the requestWithdraw function that let anyone drain the pool if they knew how to sequence calls. The protocol team patched it within four hours of my private disclosure. But the real problem isn't the bug. It's that everyone is still buying the token as if the fix makes it safe.

Context: The LRT Mania

When EigenLayer launched its mainnet, the restaking narrative went viral. Liquid Restaking Tokens (LRTs) promised to solve the capital inefficiency of staked ETH by letting you deposit ETH once and get exposure to multiple AVSs (Actively Validated Services). The TVL across top LRT protocols hit $12 billion in under six months. Every week a new LRT launches with a points program, and retail fights for allocation. The marketing is flawless: "Earn yield on yield." The tech, however, is far from flawless.

I’ve been auditing smart contracts since 2017. I manually reviewed over 15 ERC-20 contracts during the ICO boom and caught two critical reentrancy vulnerabilities before they went live. That experience taught me one thing: code quality drops proportionally to TVL growth. The faster the money flows in, the more corners are cut. This LRT protocol is no exception. It had three external audits from Tier-1 firms, yet the reentrancy in requestWithdraw survived all of them. Why? Because the withdrawal flow was considered "non-reentrant" due to its dependency on an external oracle for price updates. The auditors assumed the oracle call would prevent reentrancy. They were wrong.

Core: The Order Flow Exploit

The attack path is deceptively simple. The requestWithdraw function reduces your staked balance and mints a withdrawal NFT. But it also calls an external oracle to fetch the current exchange rate. The oracle callback triggered a fallback function in an attacking contract. That fallback function could call deposit again before the state change was finalized, creating a race condition. The net effect: an attacker could request withdrawal, get the callback, redeposit the same ETH, and then request another withdrawal—all in one transaction. The withdrawal NFT would represent more ETH than was actually deposited.

The protocol’s design relied on the assumption that the oracle call was a "read-only" external call. In practice, the oracle used a callback pattern for async updates, something that was buried in the documentation. The line that killed the assumption was IOracle(oracle).getRate(); — no reentrancy guard around it. Once I saw that, I knew the fix was trivial but the implications were massive. If exploited at scale, an attacker could drain the pool of 200,000 ETH in under a minute. The TVL would drop to zero, and every LRT holder would be left with worthless NFTs.

I’ve been through this before. During DeFi Summer in 2020, I deployed €200k into Compound and Uniswap pools and learned that liquidity mechanics matter more than marketing. When I analyzed the withdrawal queue of this LRT, I found another flaw: the withdrawal delay was set to 7 days, but the requestWithdraw function did not lock the funds during that period. So even if an attacker was caught, they could still manipulate the pool in real-time.

Contrarian: The Real Blind Spot

Retail investors think audits are the gold standard. They see three checkmarks from Certik, Trail of Bits, and OpenZeppelin, and they deposit without a second thought. The contrarian truth is that audits are a snapshot of a specific code version, not a guarantee of future behavior. This LRT protocol had three audits, but the vulnerability existed because the auditors treated the oracle as an external black box. They didn’t test the callback reentrancy path because the spec said the oracle was "trusted." In crypto, trust is a liability.

Another blind spot: the tokenomics. The LRT’s exchange rate mechanism used a moving average of oracle prices, but the moving average was recalculated on every withdrawal. An attacker could front-run large withdrawal requests to skew the moving average, creating arbitrage opportunities that drained value from passive holders. This isn’t a bug; it’s a feature of the design. The team knew about it but decided the complexity of fixing it was too high relative to the "low probability" of an organized attack. They bet that no one would coordinate a multi-block MEV attack. They lost that bet.

Takeaway: The Gap Between Belief and Reality

Risk isn’t a concept; it’s a spread. The spread here is between what the protocol promises and what its code delivers. The fix was three lines, but the systemic risk remains. Every LRT that relies on external oracles with callback patterns will have this vulnerability. The industry will learn, patch, and move on, but the capital that evaporates in the next exploit will be permanent.

Terra’s code was poetry; Luna’s exit was prose. The LRTs are writing their own prose, sentence by sentence. The only question is which block number the period lands on.

The Reentrancy You Didn't See in Restaking: A Code Audit of LRT's Withdrawal Gap

Options don’t expire; they reveal. The option to exit before the exploit is the only one that matters.

Arbitrage doesn’t create value; it reveals mispricing. The mispricing of risk in LRTs will be revealed eventually. I just hope you’re not the liquidity when it does.

Market Prices

Coin Price 24h
BTC Bitcoin
$62,787.9 -0.52%
ETH Ethereum
$1,844.82 -0.65%
SOL Solana
$72.55 -0.62%
BNB BNB Chain
$585.8 +0.60%
XRP XRP Ledger
$1.07 -1.11%
DOGE Dogecoin
$0.0697 -0.70%
ADA Cardano
$0.1904 -0.37%
AVAX Avalanche
$6.48 -1.48%
DOT Polkadot
$0.8200 +2.77%
LINK Chainlink
$8.22 -0.95%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

18
03
unlock Sui Token Unlock

Team and early investor shares released

🧮 Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$62,787.9
1
Ethereum ETH
$1,844.82
1
Solana SOL
$72.55
1
BNB Chain BNB
$585.8
1
XRP Ledger XRP
$1.07
1
Dogecoin DOGE
$0.0697
1
Cardano ADA
$0.1904
1
Avalanche AVAX
$6.48
1
Polkadot DOT
$0.8200
1
Chainlink LINK
$8.22

🐋 Whale Tracker

🔵
0x8c21...e988
3h ago
Stake
4,329,446 DOGE
🔵
0x67ea...f72f
30m ago
Stake
935,737 DOGE
🟢
0x0b97...5eac
5m ago
In
4,623 ETH

💡 Smart Money

0xd26e...b2b1
Top DeFi Miner
+$2.6M
65%
0x4e0d...4b55
Experienced On-chain Trader
+$1.0M
91%
0xd113...015b
Experienced On-chain Trader
-$3.7M
75%