โ† All CCA Flashcard Decks

Smart Contract Auditing Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Smart Contract Auditing flashcards as text
  1. Which smart contract vulnerability allows an attacker to repeatedly call a function and drain funds before the initial execution updates the contract state?

    Answer: Reentrancy

    Reentrancy occurs when an external call is made before state updates, allowing attackers to re-enter the function and repeatedly withdraw funds.

  2. What is the primary purpose of a 'checks-effects-interactions' pattern in Solidity smart contracts?

    Answer: To prevent reentrancy attacks by updating state before external calls

    The checks-effects-interactions pattern mitigates reentrancy by performing checks, then updating state (effects), and only then making external calls (interactions).

  3. During a smart contract audit, you identify that a mapping is never deleted after funds are transferred. What risk does this pose?

    Answer: Unbounded storage growth leading to excessive gas costs

    Unmaintained mappings cause unbounded state growth that increases storage costs and can make contract operations prohibitively expensive over time.

  4. Which tool is specifically designed for formal verification of Ethereum smart contracts?

    Answer: Certora Prover

    Certora Prover uses formal verification to mathematically prove that a smart contract satisfies specified properties under all conditions.

  5. A smart contract uses `tx.origin` for authentication. What attack does this enable?

    Answer: Phishing via malicious intermediary contract

    `tx.origin` returns the original transaction sender, so a malicious contract can trick the original user into calling it, then use `tx.origin` to impersonate them.

  6. What is 'gas griefing' in the context of smart contract security?

    Answer: An attack where a caller sends just enough gas to cause a sub-call to fail

    Gas griefing occurs when an attacker provides insufficient gas so that a sub-call fails, potentially causing the parent transaction to behave unexpectedly.

  7. Which of the following best describes a 'proxy upgrade' vulnerability in smart contracts?

    Answer: Storage slot collisions between proxy and implementation contracts

    Storage slot collisions happen when the proxy and implementation contracts use the same storage slots for different variables, causing data corruption.