Vault.sol
withdraw() · marked by reviewer B
function withdraw(uint256 amt) external {require(bal[msg.sender] >= amt);(bool ok,) = msg.sender.call{value: amt}("");require(ok);bal[msg.sender] -= amt;}
re-enters
before the write
A receiver re-enters withdraw before the balance write and empties the vault. PoC in the appendix. Fix: checks-effects-interactions, then nonReentrant.