Security, Risk, and Vulnerabilities Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security, Risk, and Vulnerabilities flashcards as text
What is the security implication of 'bytecode verification' in smart contract auditing?
Answer: Ensuring the deployed bytecode matches the audited source code to prevent bait-and-switch deployments
Bytecode verification confirms that the on-chain deployed contract matches the source code that was audited, preventing a developer from deploying different malicious code after the audit.
Which type of risk is introduced when a blockchain protocol relies heavily on off-chain data providers (oracles) for critical operations?
Answer: Oracle risk — data manipulation or failure creates incorrect on-chain outcomes
Oracle risk arises because smart contracts trust external data feeds; if these feeds are manipulated, stale, or unavailable, dependent protocols can be exploited or halt.
In cryptocurrency security, what is a 'dusting attack' primarily designed to accomplish?
Answer: De-anonymizing wallet owners by sending tiny amounts and analyzing the resulting transaction graph
Dusting attacks send small 'dust' amounts to many addresses, then track how those funds move to cluster addresses and link pseudonymous wallets to real identities.
What vulnerability exists when a smart contract emits sensitive data as event logs that are intended to be private?
Answer: Event logs are publicly visible on-chain, so any 'private' data in logs is exposed to anyone
Ethereum event logs are stored on-chain and permanently visible to anyone, so using them to store sensitive data (like private keys or personal information) is a critical security flaw.
Which threat model concern applies specifically to hardware wallet supply chain attacks?
Answer: Physical tampering of device hardware or firmware before delivery to introduce backdoors
Supply chain attacks involve compromising hardware wallets during manufacturing, shipping, or resale to pre-install malicious firmware that can leak private keys.
What is 'front-running' in the context of DeFi, and why is it a risk to users?
Answer: Validators or bots monitoring the mempool to insert transactions ahead of users and profit from predictable price impacts
Front-running in DeFi involves bots detecting pending transactions in the mempool and submitting similar transactions with higher gas fees to execute first, extracting value at the user's expense.
Which control best mitigates the risk of compromised API keys being used to drain a cryptocurrency exchange's hot wallet?
Answer: Implementing IP allowlisting and withdrawal address whitelisting on API keys
IP allowlisting restricts API key usage to known IP addresses, and withdrawal address whitelisting limits where funds can be sent even if a key is stolen.