← All CCE Flashcard Decks

DeFi and Decentralized Applications Flashcards

6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 DeFi and Decentralized Applications flashcards as text
  1. In a Uniswap v3 concentrated liquidity position, a liquidity provider sets a price range of [1800, 2200] USDC per ETH. If ETH's market price moves to 2400 USDC, what happens to the LP's position?

    Answer: The position becomes 100% USDC and earns no fees until price returns to range

    When ETH's price rises above the upper bound of a concentrated liquidity range in Uniswap v3, all of the LP's ETH has been sold for USDC as price traversed through the range. The position is now 100% USDC (the quote token) and earns zero fees because the active price is outside the specified range. The LP experiences full impermanent loss relative to simply holding ETH.

  2. A flash loan attack on a DeFi lending protocol exploits price oracle manipulation. The attacker borrows 10,000 ETH, uses it to skew the on-chain AMM price of an obscure token, takes out an over-collateralized loan against the inflated collateral, then repays the flash loan — all in one transaction. Which defense mechanism is MOST effective against this specific attack vector?

    Answer: Using a time-weighted average price (TWAP) oracle with a 30-minute window

    A TWAP oracle with a sufficiently long window (e.g., 30 minutes) is the most targeted defense because it makes single-block price manipulation economically impractical. The attacker would need to sustain the manipulated price across many blocks, which requires enormous capital and exposes them to arbitrage losses. Reducing LTV still allows manipulation at scale, fees don't prevent the attack mechanics, and multisig approval breaks the atomicity assumption of flash loans but doesn't stop them.

  3. In a cross-chain DeFi bridge using the Lock-and-Mint model, a user locks 100 USDC on Ethereum and receives 100 wrapped USDC (wUSDC) on Avalanche. A critical vulnerability is discovered that allows the bridge's Ethereum vault to be drained. What is the immediate consequence for wUSDC holders on Avalanche?

    Answer: wUSDC becomes unbacked and effectively worthless, even though the Avalanche smart contract is unaffected

    In a Lock-and-Mint bridge, the wrapped asset's value is entirely dependent on the backing locked in the source chain vault. If the Ethereum vault is drained, the wUSDC on Avalanche becomes unbacked — there is nothing left to redeem it against. The Avalanche smart contract itself may be perfectly intact and functional, but the wrapped tokens are now worthless because the 1:1 backing no longer exists. This is the fundamental systemic risk of custodial bridges.

  4. A DeFi protocol uses a bonding curve defined as P = S² / 1,000,000, where P is the token price in ETH and S is the total token supply. If the current supply is 1,000 tokens, approximately how much ETH is raised by minting the next 1 token (ignoring gas)?

    Answer: 0.001001 ETH

    The price at supply S=1000 is P = 1000² / 1,000,000 = 1,000,000 / 1,000,000 = 1.0 ETH. The price at S=1001 is P = 1001² / 1,000,000 = 1,002,001 / 1,000,000 ≈ 1.002001 ETH. The cost of minting the next token is the integral from 1000 to 1001 of S²/1,000,000 dS, which approximates to the average price ≈ (1.0 + 1.002001)/2 ≈ 1.001 ETH. This demonstrates how bonding curves create continuous price discovery with each marginal purchase.

  5. In Ethereum's EIP-1559 fee model, a DeFi protocol's MEV (Maximal Extractable Value) bot is trying to front-run a large DEX trade. Under EIP-1559, what is the MOST effective lever the MEV bot can use to guarantee transaction ordering priority over the victim's transaction?

    Answer: Setting a high priority fee (tip) to incentivize validators to include the transaction first

    Under EIP-1559, the base fee is burned and is the same for all transactions in a block. Validators (post-Merge) are economically incentivized by the priority fee (tip) — this is what goes directly to the block proposer. To guarantee ordering priority within the same block, an MEV bot maximizes the priority fee (tip), making it more attractive for the validator to include and order the MEV bot's transaction ahead of others. maxFeePerGas is a cap, not a direct incentive. Duplicate nonces would cause only one to be included.

  6. A yield aggregator uses a 'strategy' that deposits user funds into a lending protocol. The lending protocol's utilization rate reaches 99%, making it nearly impossible for the yield aggregator to withdraw funds on demand. This situation is best described as which type of DeFi risk?

    Answer: Liquidity risk — composability across protocols creates withdrawal bottlenecks

    This scenario illustrates liquidity risk arising from DeFi composability. When a lending protocol's utilization rate is near 100%, available liquidity for withdrawals is essentially zero — borrowers have taken out nearly all deposited assets. The yield aggregator, as a downstream depositor, cannot withdraw even though the smart contracts are functioning as designed. This is a well-known composability risk in 'money lego' DeFi stacks: the aggregated system can become illiquid even when each individual protocol is technically sound.