← All Blockchain Technology Flashcard Decks

Security and Attacks Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security and Attacks flashcards as text
  1. What vulnerability did the 2016 DAO hack on Ethereum exploit?

    Answer: Reentrancy: the withdraw function called an external contract before updating the internal balance

    The DAO attacker repeatedly called the withdraw function before the balance was updated, draining ~3.6 million ETH through recursive external calls.

  2. What is a 'price oracle manipulation' attack in DeFi?

    Answer: Artificially moving an asset's spot price on a DEX used as a price reference to exploit lending protocols

    Attackers manipulate the spot price of a token on a DEX (often via flash loans) that a lending protocol uses as an oracle, enabling under-collateralized borrowing.

  3. Which consensus attack requires controlling more than one-third of stake in a Proof-of-Stake system?

    Answer: Finality delay or safety failure attacks requiring ≥1/3 of stake to prevent or break consensus

    In BFT-based PoS systems like Ethereum's Casper, controlling ≥1/3 of stake lets an attacker prevent finality or, with ≥2/3, revert finalized blocks.

  4. What is 'signature malleability' and which Bitcoin transaction issue did it enable?

    Answer: Altering a signature's encoding without invalidating it, allowing third parties to change transaction IDs before confirmation

    Signature malleability let attackers tweak ECDSA signatures to produce valid but different transaction IDs (txids), complicating transaction tracking and was central to the MtGox issues.

  5. What does 'access control misconfiguration' most commonly allow in smart contract exploits?

    Answer: Unauthorized users calling privileged functions like mint, pause, or upgrade due to missing onlyOwner checks

    Missing or incorrect modifiers (e.g., onlyOwner) allow arbitrary users to call administrative functions, enabling minting, fund draining, or contract upgrades.

  6. How does a 'BGP hijacking' attack threaten Bitcoin mining pools?

    Answer: Rerouting internet traffic to intercept pool communications, allowing attackers to steal hashrate or delay block propagation

    BGP hijacking can redirect mining pool traffic through attacker-controlled routers, enabling hashrate theft, block withholding, or network partitioning.

  7. What is the 'nothing-at-stake' problem in naive Proof-of-Stake implementations?

    Answer: Validators can vote on multiple competing forks simultaneously at no cost, undermining consensus

    Without slashing, validators lose nothing by supporting every fork, making double-spending trivial; modern PoS systems use slashing to penalize equivocation.