Wallets and Asset Security Flashcards
6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Wallets and Asset Security flashcards as text
A hardware wallet user creates a BIP-39 seed phrase and stores it in a Shamir's Secret Sharing (SSS) scheme split into 5 shares requiring 3 to reconstruct. An attacker obtains 2 of the 5 shares. Which statement is cryptographically accurate?
Answer: The attacker gains zero mathematical information about the seed phrase from 2 shares in a proper (2,5) threshold scheme — it is information-theoretically secure
Shamir's Secret Sharing is information-theoretically secure: any set of shares below the threshold reveals *zero* information about the secret, regardless of computational power. The scheme is based on polynomial interpolation — fewer points than the polynomial's degree leaves infinite valid secrets consistent with those points, making brute force mathematically meaningless.
During a BIP-32 HD wallet key derivation, a developer accidentally exposes a hardened child private key (m/44'/0'/0'/0/5) along with the parent public key at the account level (m/44'/0'/0'). What is the security impact?
Answer: The exposure is isolated — hardened derivation prevents upward or sideward key compromise because the parent public key is not used in hardened child key derivation
Hardened child keys (indices ≥ 0x80000000) are derived using the *parent private key* (not the parent public key) as input to HMAC-SHA512. This breaks the public-key-only derivation chain intentionally. Exposing a hardened child private key alongside the parent *public* key gives the attacker no upward leverage — they cannot derive the parent private key or sibling hardened keys, because the parent public key was never part of the hardened derivation.
A multisig wallet is configured as 2-of-3 using P2SH. The three keyholders are Alice, Bob, and Carol. Alice and Bob both sign a transaction, but Carol's key is later found to be compromised by a nation-state attacker who had access *before* the transaction was broadcast. What is the security outcome?
Answer: The transaction remains valid and funds are safe — the 2-of-3 threshold was met by uncompromised signers, and confirmed transactions are immutable
Once a transaction achieves sufficient confirmations on the blockchain, it is immutable — no key compromise retroactively invalidates it. The 2-of-3 threshold was satisfied by Alice and Bob's legitimate signatures before broadcast. Carol's compromised key is dangerous for *future* transactions (the attacker can now co-sign with any other keyholder), but cannot affect already-confirmed history. The wallet must be migrated to new keys immediately.
A security researcher discovers that a popular mobile wallet derives its encryption key for the local keystore using PBKDF2 with the user's 6-digit PIN and a static, hardcoded salt. Which attack is most efficiently mounted against this design flaw?
Answer: A rainbow table attack pre-computed over all 6-digit PINs with the known static salt, reducing online cracking to a table lookup
A static salt defeats the entire purpose of salting — it prevents per-user uniqueness that makes precomputation infeasible. With a known static salt and a 6-digit PIN space of only 1,000,000 values, an attacker can precompute a complete rainbow table (or simply a full lookup table) of all PBKDF2 outputs offline. When combined with the extracted keystore, this reduces recovery to a millisecond table lookup, completely bypassing PBKDF2's iteration cost.
A user stores ETH in a smart contract wallet that uses social recovery (e.g., similar to Argent's guardian model). Three guardians can collectively rotate the signing key after a 48-hour time-lock. An attacker compromises the user's current signing key. What is the correct security response sequence?
Answer: Initiate a guardian-majority recovery immediately to begin the 48-hour time-lock for key rotation, while simultaneously using the still-valid current key to move assets to a safe address if the attacker has not yet acted
The optimal response is dual-track: initiate guardian recovery immediately (starting the 48-hour clock) AND, if the attacker hasn't yet moved funds, use the current compromised key to self-rescue assets to a safe address. The time-lock exists to protect against *unauthorized* key rotations — guardians cannot instantly rotate the key either, so there is no 'freeze' mechanism at the network layer. Waiting passively (option C) ignores that the attacker also controls the signing key right now and can drain funds during the 48-hour window.
An exchange cold wallet uses an air-gapped signing device. The transaction data is transferred to the signing device via QR codes, signed offline, and the signed transaction is returned via QR code for broadcast. A sophisticated attacker compromises the QR code *rendering software* on the internet-connected machine. Which attack vector remains viable despite the air gap?
Answer: The attacker can modify the displayed unsigned transaction QR code to redirect outputs to an attacker-controlled address, which the offline signer will sign if the operator doesn't independently verify the decoded transaction on the signing device's screen
An air gap is only as secure as the data crossing it. If the QR code rendering software on the internet-connected machine is compromised, the attacker can silently substitute a malicious transaction (e.g., changing the recipient address or amount) in the QR code before the offline signer ever sees it. The offline device will cryptographically sign whatever transaction is encoded in the QR — it cannot distinguish a legitimate from a tampered request. The critical defense is operator verification: the signer must read and confirm the *decoded* transaction details on the signing device's own trusted display before signing.