Smart Contract Auditing Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Smart Contract Auditing flashcards as text
What is a 'sandwich attack' in the context of decentralized exchanges?
Answer: Placing two transactions around a victim's trade to profit from the resulting price impact
A sandwich attack involves front-running a victim's swap to move the price, then back-running it to sell at the inflated price, profiting from the victim's price impact.
During an audit, a contract is found to use `selfdestruct`. What key concern should an auditor flag?
Answer: The opcode is deprecated and may behave differently post-EIP-6049, and can destroy ETH sent to the contract
EIP-6049 deprecated `selfdestruct`, and post-EIP-6780 it no longer destroys code except in the same transaction as creation; auditors must flag behavioral changes and unintended ETH loss.
What is the difference between a 'static analysis' tool and a 'symbolic execution' tool in smart contract security?
Answer: Static analysis reviews source code for patterns; symbolic execution explores all possible execution paths using abstract values
Static analysis scans code for known vulnerability patterns without executing it, while symbolic execution explores code paths with symbolic inputs to find violations of properties.
A CCA auditor reviews a multi-signature wallet contract. Which scenario represents a critical risk?
Answer: A function that allows any single signer to change the list of authorized signers
Allowing a single signer to modify the authorized signer list defeats the purpose of multi-signature security and gives one party unilateral control.
What is 'shadowing' in Solidity, and why is it flagged during audits?
Answer: A state variable or local variable with the same name as an inherited variable, causing the inherited variable to be silently overridden
Variable shadowing occurs when a derived contract declares a variable with the same name as a base contract variable, potentially causing unintended behavior by masking the parent's state.
Which audit step is most effective for verifying that access control is correctly implemented across all sensitive functions?
Answer: Mapping all public and external functions against their required roles and verifying modifier coverage
A systematic access control matrix that maps every sensitive function to its required roles and verifies that appropriate modifiers are applied ensures no privileged function is left unprotected.
What is the purpose of a 'bug bounty program' in the context of a post-audit smart contract deployment?
Answer: To incentivize white-hat hackers to responsibly disclose vulnerabilities not found during the formal audit
Bug bounty programs offer financial rewards to security researchers who discover and responsibly disclose vulnerabilities, providing an additional security layer after formal audits.