โ† All CBSE Flashcard Decks

DeFi and Token Security Flashcards

6 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 DeFi and Token Security flashcards as text
  1. What is a 'rug pull' in the context of DeFi token security?

    Answer: Developers abandoning a project and draining liquidity, leaving investors with worthless tokens

    Rug pulls occur when malicious developers withdraw all liquidity pool funds after attracting investors, causing the token price to collapse to zero.

  2. Which type of DeFi attack exploits the ordering of transactions within a block for profit?

    Answer: Maximal Extractable Value (MEV) exploitation

    MEV refers to profit extracted by reordering, inserting, or censoring transactions within a block, often at the expense of regular users.

  3. A liquidity pool uses a constant product formula (x * y = k). What attack surface does this create for low-liquidity pools?

    Answer: High price impact susceptibility making oracle manipulation cheaper and more effective

    Low-liquidity constant-product pools can be significantly price-manipulated with relatively small capital, making them ideal oracle attack targets.

  4. What is a token vesting contract security concern that a CBSE professional should audit?

    Answer: Improper access control allowing beneficiaries or admins to bypass vesting schedules and drain tokens early

    Vesting contracts must enforce time-locks and access controls; bugs in these checks allow premature withdrawal that undermines tokenomics.

  5. What does 'approval phishing' target in the DeFi ecosystem?

    Answer: Tricking users into signing unlimited ERC-20 token approvals that drain their wallets

    Approval phishing tricks victims into authorizing malicious contracts to spend all their tokens via a standard ERC-20 approve() call.

  6. Which security practice best mitigates the risk of a compromised DeFi protocol admin key?

    Answer: Using a multi-signature wallet with time-locked governance for all admin operations

    Multi-sig wallets require multiple key holders to approve critical actions, and time-locks give the community time to detect and respond to malicious proposals.