Security Principles Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Principles flashcards as text
Relying on block.timestamp for critical randomness is risky because miners can do what?
Answer: Manipulate the timestamp within a small range
Miners can slightly adjust block.timestamp, so it is not a safe source of randomness or precise timing.
Which oracle service provides verifiable on-chain randomness resistant to manipulation?
Answer: Chainlink VRF
Chainlink VRF produces cryptographically verifiable random numbers that cannot be tampered with by miners or operators.
An oracle manipulation attack on a DeFi protocol typically targets what?
Answer: The price feed used for collateral valuation
Attackers distort the price source to mis-value collateral and drain funds, often via flash loans.
Why are time-weighted average price (TWAP) oracles more resistant to flash loan attacks?
Answer: They average prices over time, resisting single-block manipulation
Averaging price over many blocks makes a one-block flash-loan distortion negligible.
A flash loan enables an attacker to do what within a single transaction?
Answer: Borrow large uncollateralized funds that must be repaid before the transaction ends
Flash loans provide large capital with no collateral as long as repayment happens atomically in the same transaction.
What is the main security benefit of using audited libraries like OpenZeppelin?
Answer: They reduce bugs by reusing community-reviewed, battle-tested code
Widely audited libraries lower the risk of introducing common vulnerabilities through well-vetted implementations.
Why should external calls' return values always be checked?
Answer: A low-level call can fail silently without reverting
Low-level calls return a success boolean instead of reverting, so unchecked failures can corrupt logic.