Smart Contract Vulnerabilities Flashcards
7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Smart Contract Vulnerabilities flashcards as text
What is a 'front-running' attack in the context of decentralized exchanges (DEXs)?
Answer: Submitting a higher-gas transaction to execute before a pending victim transaction and profit from the price change
Front-running (a form of MEV) involves observing a pending transaction in the mempool and submitting a competing transaction with higher gas to be mined first.
A contract's 'selfdestruct' function is callable by any address. Which vulnerability category does this represent?
Answer: Logic error / missing access control
Allowing any address to call selfdestruct is a missing access control vulnerability; a proper guard (e.g., onlyOwner) should restrict this destructive function.
Which attack exploits the fact that an ERC-20 'approve' operation can be front-run to spend both the old and new allowance?
Answer: Allowance race condition (approve/transferFrom race)
If an owner calls approve to change an existing non-zero allowance, a spender can front-run and spend the old allowance, then spend the new allowance too, extracting double the intended amount.
What is a 'griefing attack' in smart contract security?
Answer: Making a contract unusable or forcing it into a bad state without direct financial gain
A griefing attack aims to harm or permanently disrupt a contract's functionality (e.g., blocking withdrawals) rather than extracting funds.
An attacker sends ETH directly to a contract address using 'selfdestruct' before the contract is deployed (via CREATE2). What impact can this have?
Answer: The pre-loaded ETH may break invariants that assume the contract starts with zero balance
Because a CREATE2 address is deterministic, an attacker can seed ETH to that address beforehand; contracts that assume they start with zero balance (e.g., checking address(this).balance == 0) will behave incorrectly.
Which Solidity visibility specifier should be avoided on sensitive functions to prevent unauthorized external access?
Answer: public (without an access modifier check)
Marking a sensitive function public without a role-based guard exposes it to all external callers, enabling unauthorized state changes or fund extraction.
What does 'signature replay' mean in smart contract security?
Answer: Reusing a valid cryptographic signature from a past transaction to authorize a new, unintended one
A replay attack re-submits a legitimately signed message on the same or a different chain/contract where no nonce or chainId prevents its reuse.