โ† All CBSE Flashcard Decks

Smart Contract Vulnerabilities Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Smart Contract Vulnerabilities flashcards as text
  1. What is a 'front-running' attack in the context of decentralized exchanges (DEXs)?

    Answer: Submitting a higher-gas transaction to execute before a pending victim transaction and profit from the price change

    Front-running (a form of MEV) involves observing a pending transaction in the mempool and submitting a competing transaction with higher gas to be mined first.

  2. A contract's 'selfdestruct' function is callable by any address. Which vulnerability category does this represent?

    Answer: Logic error / missing access control

    Allowing any address to call selfdestruct is a missing access control vulnerability; a proper guard (e.g., onlyOwner) should restrict this destructive function.

  3. Which attack exploits the fact that an ERC-20 'approve' operation can be front-run to spend both the old and new allowance?

    Answer: Allowance race condition (approve/transferFrom race)

    If an owner calls approve to change an existing non-zero allowance, a spender can front-run and spend the old allowance, then spend the new allowance too, extracting double the intended amount.

  4. What is a 'griefing attack' in smart contract security?

    Answer: Making a contract unusable or forcing it into a bad state without direct financial gain

    A griefing attack aims to harm or permanently disrupt a contract's functionality (e.g., blocking withdrawals) rather than extracting funds.

  5. An attacker sends ETH directly to a contract address using 'selfdestruct' before the contract is deployed (via CREATE2). What impact can this have?

    Answer: The pre-loaded ETH may break invariants that assume the contract starts with zero balance

    Because a CREATE2 address is deterministic, an attacker can seed ETH to that address beforehand; contracts that assume they start with zero balance (e.g., checking address(this).balance == 0) will behave incorrectly.

  6. Which Solidity visibility specifier should be avoided on sensitive functions to prevent unauthorized external access?

    Answer: public (without an access modifier check)

    Marking a sensitive function public without a role-based guard exposes it to all external callers, enabling unauthorized state changes or fund extraction.

  7. What does 'signature replay' mean in smart contract security?

    Answer: Reusing a valid cryptographic signature from a past transaction to authorize a new, unintended one

    A replay attack re-submits a legitimately signed message on the same or a different chain/contract where no nonce or chainId prevents its reuse.