DeFi and Token Security Flashcards
6 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 DeFi and Token Security flashcards as text
What is a 'rug pull' in the context of DeFi token security?
Answer: Developers abandoning a project and draining liquidity, leaving investors with worthless tokens
Rug pulls occur when malicious developers withdraw all liquidity pool funds after attracting investors, causing the token price to collapse to zero.
Which type of DeFi attack exploits the ordering of transactions within a block for profit?
Answer: Maximal Extractable Value (MEV) exploitation
MEV refers to profit extracted by reordering, inserting, or censoring transactions within a block, often at the expense of regular users.
A liquidity pool uses a constant product formula (x * y = k). What attack surface does this create for low-liquidity pools?
Answer: High price impact susceptibility making oracle manipulation cheaper and more effective
Low-liquidity constant-product pools can be significantly price-manipulated with relatively small capital, making them ideal oracle attack targets.
What is a token vesting contract security concern that a CBSE professional should audit?
Answer: Improper access control allowing beneficiaries or admins to bypass vesting schedules and drain tokens early
Vesting contracts must enforce time-locks and access controls; bugs in these checks allow premature withdrawal that undermines tokenomics.
What does 'approval phishing' target in the DeFi ecosystem?
Answer: Tricking users into signing unlimited ERC-20 token approvals that drain their wallets
Approval phishing tricks victims into authorizing malicious contracts to spend all their tokens via a standard ERC-20 approve() call.
Which security practice best mitigates the risk of a compromised DeFi protocol admin key?
Answer: Using a multi-signature wallet with time-locked governance for all admin operations
Multi-sig wallets require multiple key holders to approve critical actions, and time-locks give the community time to detect and respond to malicious proposals.