โ† All CBSE Flashcard Decks

DeFi and Token Security Flashcards

6 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 DeFi and Token Security flashcards as text
  1. What is a flash loan attack in the context of DeFi security?

    Answer: Borrowing a large uncollateralized loan within a single transaction to manipulate prices and exploit protocols

    Flash loans are repaid within one transaction; attackers use the temporary capital to manipulate oracle prices or drain protocol reserves.

  2. Which vulnerability type allows an attacker to repeatedly call a DeFi protocol's withdrawal function before the balance is updated?

    Answer: Reentrancy

    Reentrancy exploits occur when external contract calls are made before state changes, allowing recursive withdrawals that drain funds.

  3. What is price oracle manipulation in DeFi, and why is it dangerous?

    Answer: Using flash loans or low-liquidity pools to distort on-chain price feeds, causing protocols to mis-price assets

    Manipulated oracles cause lending protocols to accept inflated collateral or release excess funds, enabling massive theft in a single transaction.

  4. A token contract includes a hidden mint function accessible only to the deployer. What security risk does this represent?

    Answer: A backdoor allowing unlimited token creation, enabling rug pulls and inflation attacks

    Hidden privileged mint functions are a common rug pull vector, allowing the deployer to devalue existing holders by inflating supply at will.

  5. What is a 'sandwich attack' in DeFi trading?

    Answer: Front-running a victim's transaction and back-running it to profit from the price impact

    In a sandwich attack, the attacker places a buy before and a sell after the victim's trade, profiting from the slippage they create.

  6. Which ERC standard is specifically designed to prevent token approval exploits by introducing permit-based approvals?

    Answer: ERC-2612

    ERC-2612 adds a permit() function that uses off-chain signatures for approvals, eliminating the unlimited approval attack surface.