← All CCE Flashcard Decks

DeFi and Decentralized Applications Flashcards

6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 DeFi and Decentralized Applications flashcards as text
  1. In a Uniswap v3 concentrated liquidity position, if a liquidity provider sets a price range of $1,800–$2,200 for an ETH/USDC pool and ETH's market price moves to $2,500, what happens to the LP's position?

    Answer: The position is fully converted to USDC and earns no trading fees until price returns to the range

    In Uniswap v3, when the market price moves above the upper bound of a concentrated liquidity range, the entire position is converted into the quote token (USDC in this case). The position becomes inactive — it earns zero trading fees — and remains fully in USDC until the price re-enters the $1,800–$2,200 range. There is no auto-rebalancing or liquidation penalty; the LP simply holds a 100% USDC position out of range.

  2. Which of the following accurately describes the core vulnerability exploited in a 'read-only reentrancy' attack against DeFi protocols that integrate with Curve Finance pools?

    Answer: An attacker manipulates the return value of a view function mid-transaction by exploiting Curve's internal state during a reentrant callback, causing an integrated protocol to read a temporarily skewed price or balance

    Read-only reentrancy is a subtle attack where a malicious contract, during a legitimate callback (e.g., receiving ETH from a Curve pool withdrawal), calls a view function on an integrated protocol. Curve's internal state is temporarily inconsistent at this moment — balances may not yet reflect the final state — so a protocol reading Curve's virtual_price or get_virtual_price mid-callback receives a manipulated value. Unlike classic reentrancy, no funds are directly drained from Curve itself; the victim is the integrated protocol that trusts the skewed read. Several real exploits (e.g., against protocols using Curve LP tokens as collateral) used this vector.

  3. A MakerDAO vault owner has 10 ETH collateral (ETH price = $2,000) and has drawn 10,000 DAI against it. The liquidation ratio is 150%. If ETH drops to $1,450 and a keeper liquidates the vault, approximately how much of the collateral is auctioned off (assuming a 13% liquidation penalty applies to the debt)?

    Answer: Enough ETH to cover 113% of the outstanding debt ($11,300 worth) is seized, with any surplus returned to the vault owner

    In MakerDAO's Liquidations 2.0 (Dutch auction), the full vault is technically put up for auction, but keepers only need to cover the debt plus the 13% liquidation penalty (i.e., 10,000 × 1.13 = $11,300 worth of collateral). At $1,450/ETH, that equals roughly 7.79 ETH. Any collateral remaining after the debt and penalty are covered is returned to the vault owner. The protocol does not simply seize everything — surplus collateral belongs to the borrower. Option D's 'fixed 10% discount' describes an older liquidation model (Liquidations 1.2), not the current system.

  4. In the context of Aave's 'isolation mode,' which combination of constraints is correctly applied to an asset listed as an Isolated Asset?

    Answer: It can only be used as collateral alone (not combined with other assets), borrowing is capped at a protocol-defined debt ceiling, and only stablecoins can be borrowed against it

    Aave v3's isolation mode is designed to safely onboard higher-risk long-tail assets. When a user enables an isolated asset as collateral: (1) it cannot be combined with other collateral assets in the same account — it must be used alone; (2) borrowing against it is subject to a hard debt ceiling set by governance (e.g., $5M); and (3) only assets designated as 'borrowable in isolation' — typically stablecoins — can be borrowed. This three-part constraint limits systemic risk from potentially manipulable or illiquid collateral.

  5. A flash loan arbitrageur uses a single Aave V3 flash loan to simultaneously exploit a price discrepancy between a Curve stablecoin pool and a Uniswap v3 pool. The transaction reverts at the final step. Which of the following best explains the economic outcome?

    Answer: All state changes within the transaction are atomically reverted; the arbitrageur loses only the gas fee paid to the validator

    Flash loans exploit Ethereum's atomic transaction model: if any step in the transaction fails (including repaying the loan plus fee), the entire transaction reverts as if it never happened. All EVM state changes — token transfers, pool swaps, loan drawdown — are rolled back. The only real cost to the arbitrageur is the gas fee consumed up to the point of reversion, which is paid to the block validator and is non-refundable. No flash loan fee is charged on a failed transaction, no assets are locked, and no partial trades persist on any DEX.

  6. In a cross-chain DeFi protocol using a 'lock-and-mint' bridge model, an attacker compromises 5 of the 9 validator nodes in the bridge's multisig before the exploit is detected. Assuming the bridge requires a 5-of-9 threshold to authorize minting, what is the most accurate description of the attack's on-chain footprint on the destination chain?

    Answer: The attacker can mint an unlimited amount of wrapped tokens on the destination chain, potentially far exceeding the actual assets locked on the source chain

    In a lock-and-mint bridge, the source chain locks native assets while the destination chain mints synthetic/wrapped representations. The bridge's security depends entirely on the multisig validators honestly attesting to lock events. With exactly 5-of-9 compromised validators (meeting the threshold), an attacker can forge arbitrary mint authorizations on the destination chain without locking any real assets. This means wrapped tokens can be minted far beyond the actual TVL — the canonical example being the $600M Ronin bridge hack (5-of-9 private keys compromised). The destination chain has no native mechanism to detect that underlying locks never occurred; fraud proof systems are characteristic of optimistic rollups, not validator-based bridges.