โ† All Blockchain Technology Flashcard Decks

DeFi Security and Audits Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 DeFi Security and Audits flashcards as text
  1. What is the danger of an unprotected 'delegatecall' to an attacker-controlled address?

    Answer: The attacker's code runs in the caller's storage context and can overwrite state

    delegatecall executes external code using the caller's storage, so a malicious target can rewrite the caller's variables, including ownership.

  2. In an upgradeable proxy pattern, what is a common security risk?

    Answer: Storage slot collisions between proxy and implementation

    If the proxy and implementation use overlapping storage layouts, an upgrade can corrupt critical variables like the admin slot.

  3. What is a sandwich attack against a DEX trader?

    Answer: An attacker front-runs and back-runs a victim swap to profit from induced price movement

    The attacker buys before the victim's trade and sells after, exploiting the price impact, a classic MEV technique.

  4. How can a trader reduce exposure to sandwich attacks?

    Answer: Set a tight slippage tolerance and use private transaction relays

    Tight slippage limits the price movement an attacker can exploit, and private relays keep the transaction out of the public mempool.

  5. An audit flags integer arithmetic without SafeMath in a pre-0.8.0 Solidity contract. Why?

    Answer: Unchecked overflow/underflow can corrupt balances

    Before Solidity 0.8.0, arithmetic did not revert on overflow, allowing balances to wrap around and be manipulated.

  6. What risk does an unbounded loop over a user-controlled array introduce?

    Answer: A denial-of-service if the loop exceeds the block gas limit

    If an array can grow large enough that iterating it exceeds gas limits, the function becomes permanently uncallable, a DoS condition.

  7. Why is using 'tx.origin' for authorization a vulnerability?

    Answer: A malicious intermediary contract can phish the original signer's authority

    tx.origin is the original EOA, so a user tricked into calling a malicious contract grants that contract their authority; use msg.sender instead.

DeFi Security and Audits Flashcards โ€” Blockchain Technology Study Cards with Answers