# Re entrancy attack in ICP

**URL:** <https://forum.dfinity.org/t/re-entrancy-attack-in-icp/48900>\
**Category:** Developers\
**Created:** [May 25, 2025, 1:55pm UTC](https://forum.dfinity.org/t/re-entrancy-attack-in-icp/48900 "2025-05-25T13:55:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![AliSci](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/alisci/32/33799_2.png) [@AliSci](https://forum.dfinity.org/u/AliSci)\
**Post date:** [May 25, 2025, 1:55pm UTC](https://forum.dfinity.org/t/re-entrancy-attack-in-icp/48900/1 "2025-05-25T13:55:00Z")

</div>

Currently I lock the function for the user to prevent re-enterncy attack but is there other ways? Especially i am thinking that our backend canister can’t by called by any other frontend, so it can be overkill.

```rs

#[update]
async fn deposit_ckusdt() -> Result<Wallet, Error> {
    if is_deposeting(caller()){
      return Err("Please tray again later")
     }
    set_is_deposeting(caller())
     // ..... rest of code
    unset_is_deposeting(caller())
}

```

---

<div class="post-metadata">

**Author:** ![Buriburizaemon](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/buriburizaemon/32/19925_2.png) [@Buriburizaemon](https://forum.dfinity.org/u/Buriburizaemon)\
**Post date:** [May 25, 2025, 3:57pm UTC](https://forum.dfinity.org/t/re-entrancy-attack-in-icp/48900/2 "2025-05-25T15:57:48Z")

</div>

for `deposit` of tokens you can’t achieve such thing. As the address is publicly available anyone can deposit the tokens to the address.

> [@AliSci](#):
>
> Especially i am thinking that our backend canister can’t by called by any other frontend

I think there is no way to check if the calls are made from your deployed frontend canister directly. BUT you can use some tokenization way (for e.g. `JWT`).

read this post from @Vivienne: [How does canister state change when processing multiple messages that await inter-canister calls? - #5 by Vivienne](https://forum.dfinity.org/t/how-does-canister-state-change-when-processing-multiple-messages-that-await-inter-canister-calls/17527/5)
