Smart Contract Security Flashcards
7 cards from real NFT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Smart Contract Security flashcards as text
What vulnerability arises from using delegatecall to an untrusted contract in an upgradeable NFT proxy?
Answer: The called code runs in the proxy's storage context and can overwrite critical state
delegatecall executes external code against the caller's storage, so a malicious implementation can corrupt or hijack proxy state.
In a proxy-based upgradeable contract, what is a storage collision?
Answer: A new implementation's variable layout overlaps the proxy's slots, corrupting data
Mismatched storage layouts between proxy and implementation cause variables to read/write the wrong slots.
Why should an upgradeable NFT contract avoid constructors and use an initializer instead?
Answer: Constructor code runs in the implementation's context, not the proxy, so proxy state would be uninitialized
Because the proxy delegatecalls to the implementation, constructor logic never runs in proxy storage, so an initializer function is required.
What protects an initializer function from being called more than once?
Answer: The initializer modifier that tracks an _initialized flag
OpenZeppelin's initializer modifier sets a flag so the initialization logic can only execute once.
What is a front-running risk when revealing NFT metadata after a mint?
Answer: Observers can read pending reveal transactions and snipe rare tokens before reveal
If rarity can be computed from a pending reveal, attackers can front-run to acquire or avoid specific tokens.
How can a commit-reveal scheme mitigate front-running in NFT trait assignment?
Answer: Participants commit a hashed value first, then reveal later, hiding the data during the vulnerable window
Commit-reveal hides the meaningful value behind a hash until a later reveal, so it can't be acted on in advance.
Why is unchecked external call return value a security concern in NFT contracts?
Answer: A failed transfer may be silently ignored, leaving the contract in an inconsistent state
Low-level calls return a success boolean that, if unchecked, lets failures pass silently and corrupt accounting.