← All CCE Flashcard Decks

DeFi and Decentralized Applications Flashcards

6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 DeFi and Decentralized Applications flashcards as text
  1. In a constant product AMM (x*y=k), a liquidity provider deposits equal value of ETH and USDC. After a large ETH price surge, they withdraw their liquidity. Compared to simply holding the original assets, which outcome best describes their position?

    Answer: They hold less ETH and more USDC than if they had held, and may have less total USD value due to impermanent loss

    In a constant product AMM, as ETH price rises, arbitrageurs buy ETH from the pool, leaving the LP with less ETH and more USDC than their original deposit. This rebalancing — selling the appreciating asset — causes impermanent loss. The LP ends up with less total USD value compared to simply holding, unless trading fees sufficiently compensate. The loss is 'impermanent' only if prices revert.

  2. A DeFi protocol uses a 'flash loan' to execute an arbitrage across two DEXes in a single transaction. The attacker borrows 10M USDC, manipulates a low-liquidity price oracle on DEX A, exploits a lending protocol that reads that oracle, then repays the loan — all atomically. What core design flaw in the lending protocol enabled this attack?

    Answer: Using an on-chain AMM spot price as the sole price oracle without a time-weighted average

    The critical flaw is relying on an AMM's instantaneous spot price as a price oracle. Spot prices can be manipulated within a single block with sufficient capital (e.g., via flash loans). Time-Weighted Average Prices (TWAPs) over multiple blocks are far harder to manipulate because an attacker would need to sustain the price deviation across many blocks, incurring massive arbitrage losses. Protocols like Uniswap v3 provide on-chain TWAP oracles specifically for this reason.

  3. A DAO votes to upgrade its smart contract using the transparent proxy pattern. A governance attacker acquires just enough tokens to pass a proposal that upgrades the implementation to a malicious contract. Which defense mechanism specifically addresses this vector by introducing a mandatory delay between proposal approval and execution?

    Answer: A timelock controller contract

    A timelock controller inserts a mandatory waiting period (e.g., 48–72 hours) between when a governance proposal passes and when it can be executed on-chain. This window allows community members, security researchers, and token holders to detect malicious upgrades and take defensive actions — such as selling tokens, forking the protocol, or mounting a counter-proposal. Compound, Aave, and most major DeFi protocols use timelocks precisely for this reason. Multi-sig helps but doesn't give the community time to react; quorum adjustments and quadratic voting don't solve the time-to-react problem.

  4. In Compound's cToken model, a user supplies 1,000 DAI when the exchange rate is 0.020 DAI per cDAI, receiving 50,000 cDAI. Several months later, the exchange rate rises to 0.025. If the user redeems all 50,000 cDAI, how much DAI do they receive, and what drove the rate change?

    Answer: 1,250 DAI; accrued interest from borrowers increased the protocol's DAI reserves

    The user receives 50,000 × 0.025 = 1,250 DAI. The cToken exchange rate is not fixed — it monotonically increases over time as borrowers pay interest into the protocol. That interest accrues to the total pool, raising the DAI-per-cDAI ratio. Suppliers gain yield passively simply by holding cTokens; they do not need to claim rewards separately. The protocol does not mint DAI, and secondary market cDAI prices are distinct from the redemption exchange rate.

  5. Curve Finance's StableSwap invariant is specifically optimized for pegged assets. Compared to a standard Uniswap x*y=k pool with the same liquidity, Curve's design achieves lower slippage near the peg primarily because it:

    Answer: Concentrates liquidity in a narrow price band around the peg by blending a constant-sum and constant-product invariant

    Curve's StableSwap formula is a hybrid: it behaves like a constant-sum (x+y=k) market maker near the peg — providing near-zero slippage — but reverts toward a constant-product curve when balances become highly imbalanced, preventing pool depletion. This amplification parameter (A) controls how tightly liquidity is concentrated. The result is dramatically lower slippage for same-peg swaps (e.g., USDC↔DAI) compared to a standard AMM, which spreads liquidity uniformly across all prices. Curve is fully on-chain and does not use order books.

  6. A protocol implements 'veToken' mechanics (e.g., veCRV in Curve). A user locks 10,000 CRV for the maximum duration of 4 years and receives voting power. A second user locks 10,000 CRV for 1 year. Which statement accurately describes a key consequence of this design for the second user relative to the first?

    Answer: The second user receives proportionally less voting power and smaller LP yield boosts, decaying further as their lock period shortens

    In the veToken model, voting power (and associated benefits like LP yield boosts) is proportional to both the amount locked and the time remaining on the lock. Locking 10,000 CRV for 1 year yields roughly 1/4 the veCRV of locking for 4 years, meaning less governance weight and lower boosted rewards on Curve liquidity pools (up to 2.5× boost for max veCRV). Crucially, veCRV balance decays linearly toward zero as the lock expiration approaches, so the second user's power continuously diminishes unless they extend their lock. Tokens are returned at expiry — not burned. There is no explicit fee penalty for shorter locks.