Security and Vulnerabilities Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Vulnerabilities flashcards as text
A function transfers Ether to a user before updating their balance. What vulnerability does this introduce?
Answer: Reentrancy
Sending Ether before updating state lets the recipient's fallback re-enter the function and drain funds.
Which pattern is the recommended defense against reentrancy attacks?
Answer: Checks-Effects-Interactions
The Checks-Effects-Interactions pattern updates state before making external calls, preventing re-entry exploitation.
In Solidity 0.8+, what happens by default when an arithmetic operation overflows?
Answer: The transaction reverts
Solidity 0.8 and later include built-in overflow/underflow checks that revert on overflow.
What is the main risk of using tx.origin for authorization?
Answer: A malicious intermediate contract can impersonate the user
tx.origin refers to the original sender, so a phishing contract called by the user passes the check.
A lottery contract picks a winner using block.timestamp and blockhash. Why is this insecure?
Answer: Miners/validators can manipulate these values
On-chain values like timestamp and blockhash can be influenced by block producers, making the randomness predictable or manipulable.
What does the 'pull over push' payment pattern improve?
Answer: Resilience to failed external transfers and DoS
Letting users withdraw (pull) instead of the contract pushing payments avoids a single failing transfer blocking everyone.
Which tool is commonly used for static analysis of Solidity contracts to detect vulnerabilities?
Answer: Slither
Slither is a widely used static analysis framework that flags common Solidity security issues.