Smart Contract Vulnerabilities Flashcards
7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Smart Contract Vulnerabilities flashcards as text
What is a 'flash loan attack' and which property of flash loans makes it possible?
Answer: An attack using borrowed funds that must be repaid within the same transaction, enabling massive capital with zero collateral
Flash loans provide uncollateralized capital for the duration of a single transaction; attackers use the borrowed capital to manipulate prices or exploit protocol logic, repaying the loan in the same transaction.
How can an attacker manipulate a Uniswap V2 spot price to exploit a smart contract that uses it as an on-chain oracle?
Answer: By executing a large trade in the same block to skew the spot price before the victim contract reads it
Spot prices on automated market makers can be manipulated within a single transaction (especially with flash loans), making them unreliable as oracles; time-weighted average prices (TWAP) are more resistant.
Which vulnerability exists when a proxy contract's 'implementation' storage slot overlaps with a variable in the implementation contract?
Answer: Storage collision between proxy and implementation
If the proxy stores the implementation address in slot 0 and the implementation also writes to slot 0, the implementation address can be overwritten by normal operations.
What is the 'uninitialized storage pointer' vulnerability in older Solidity code?
Answer: A local struct or array that defaults to pointing at storage slot 0, potentially overwriting critical variables
In older Solidity versions, uninitialized local storage variables default to slot 0 in storage, so writing to them overwrites whatever critical data resides at slot 0 (often the contract owner).
A lending contract checks 'require(msg.sender == tx.origin)' to block contract callers. What attack does this guard against, and what is its limitation?
Answer: It blocks flash loan contracts but breaks composability and can still be bypassed by EOA-initiated exploits
Requiring msg.sender == tx.origin ensures only externally owned accounts call the function, blocking most flash loan attack contracts, but it breaks composability with legitimate multisigs and smart wallets.
What is 'gas griefing' in the context of a contract that forwards external calls with a fixed gas stipend?
Answer: A callee deliberately consuming all forwarded gas to cause the caller's logic to fail
If a contract forwards a fixed gas amount to an untrusted external call, a malicious callee can consume all that gas, causing the parent call to receive a failure return without reverting everything.
Which audit technique is most effective for discovering integer overflow vulnerabilities in Solidity contracts older than version 0.8.0?
Answer: Dynamic fuzz testing with maximum uint256 boundary values
Fuzz testing with extreme boundary values (e.g., type(uint256).max) automatically surfaces wrap-around behavior that manual review or linting may miss.