โ† All Blockchain Technology Flashcard Decks

DeFi Security and Audits Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 DeFi Security and Audits flashcards as text
  1. What is the main advantage of formal verification in a smart contract audit?

    Answer: It mathematically proves the code satisfies specified properties

    Formal verification uses mathematical methods to prove that code meets its specification under all inputs, catching flaws testing might miss.

  2. What does a 'fuzzing' tool do during a security review?

    Answer: Feeds random or generated inputs to find unexpected reverts or invariant violations

    Fuzzers bombard functions with varied inputs to surface edge-case failures and broken invariants that manual review can overlook.

  3. Why is a reentrancy guard (mutex) used in withdrawal functions?

    Answer: It prevents a function from being re-entered before its first execution completes

    A reentrancy guard locks the function so a malicious external call cannot recursively re-invoke it and drain funds.

  4. What is a signature replay attack in DeFi?

    Answer: A valid signed message is reused to repeat an authorized action

    Without a nonce or domain separator, an attacker can resubmit a previously valid signature to trigger the same action again.

  5. How does EIP-712 with nonces help prevent signature replay?

    Answer: It binds signatures to a unique nonce and domain so each can be used only once

    Including a per-user nonce and chain/contract domain in the signed data ensures a signature is valid only once and only on the intended contract.

  6. What is a key risk when a DeFi protocol composes with an external unaudited protocol?

    Answer: Composability risk, where a flaw or exploit in the dependency cascades into your protocol

    DeFi's money-lego composability means a vulnerability or failure in an integrated protocol can directly compromise contracts that rely on it.

  7. Why should auditors review how a protocol handles a sudden depeg of a stablecoin collateral?

    Answer: A depeg can leave loans undercollateralized and trigger cascading bad debt

    If a stablecoin used as collateral loses its peg, positions can become undercollateralized faster than liquidations can clear them, creating systemic bad debt.