← All CCA Flashcard Decks

Security, Risk, and Vulnerabilities Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security, Risk, and Vulnerabilities flashcards as text
  1. What is 'MEV (Maximal Extractable Value)' and why is it considered a security and fairness concern?

    Answer: Profit extracted by block producers by reordering, inserting, or censoring transactions within blocks they produce

    MEV allows block producers to reorder or insert transactions for profit at users' expense, creating unfair outcomes, enabling front-running, and potentially destabilizing consensus incentives.

  2. A cryptocurrency auditor identifies that a protocol uses 'unchecked' arithmetic in Solidity 0.8+. What specific risk does this introduce?

    Answer: It bypasses Solidity 0.8's built-in overflow/underflow protection, reintroducing integer overflow vulnerabilities

    Solidity 0.8+ automatically reverts on overflow/underflow, but the 'unchecked' block disables this protection, allowing silent integer wrapping that can be exploited.

  3. Which risk mitigation technique involves distributing cryptographic key material across multiple parties so no single party holds a complete key?

    Answer: Multi-Party Computation (MPC) or Secret Sharing

    MPC and secret sharing schemes (like Shamir's Secret Sharing) split key material so that a threshold of parties must cooperate to sign, eliminating any single point of key compromise.

  4. What makes 'selfish mining' a threat to blockchain security even when an attacker controls less than 51% of hash power?

    Answer: It enables an attacker with ~33% hash power to withhold blocks strategically and waste honest miners' work, gaining disproportionate revenue share

    Selfish mining allows attackers with as little as ~33% hash power to selectively publish blocks to create orphans for honest miners, gaining more than their fair share of rewards.

  5. During a DeFi protocol audit, which finding would be classified as a 'critical' severity vulnerability?

    Answer: Reentrancy vulnerability allowing an attacker to drain all protocol funds in a single transaction

    A reentrancy vulnerability enabling total fund drainage is critical because it directly threatens all user assets and can be exploited immediately upon deployment.

  6. What is the security risk associated with 'delegate call' (delegatecall) in Ethereum smart contracts when used incorrectly?

    Answer: It executes external code in the context of the calling contract's storage, potentially allowing unauthorized storage manipulation

    Delegatecall runs the called contract's code using the caller's storage context, so a malicious or poorly designed implementation contract can corrupt or hijack the proxy's state.

  7. Which risk is specifically associated with 'wrapped' token protocols (e.g., WBTC) from a cryptocurrency audit perspective?

    Answer: Custodial risk — the underlying asset is held by a centralized custodian who could be hacked, fail, or freeze redemptions

    Wrapped tokens depend on a custodian holding the underlying asset; if that custodian is compromised, insolvent, or faces regulatory action, the wrapped token loses its backing and value.