Smart Contract Security Flashcards
7 cards from real NFT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Smart Contract Security flashcards as text
What is an integer overflow risk in a pre-0.8.0 Solidity NFT contract counter?
Answer: A uint wrapping past its max back to zero, potentially resetting token IDs or balances
Before Solidity 0.8.0, arithmetic wrapped silently, so a counter could overflow and corrupt IDs or accounting.
How does Solidity 0.8.0+ handle arithmetic overflow by default?
Answer: It reverts the transaction on overflow/underflow automatically
Solidity 0.8.0 introduced built-in overflow checks that revert on over/underflow without needing SafeMath.
What is the danger of an unbounded loop in an NFT airdrop function?
Answer: It can exceed the block gas limit, making the function impossible to execute
Loops over arbitrarily large arrays can run out of gas and permanently brick the function (denial of service).
Why should NFT royalty logic follow the ERC-2981 standard rather than custom enforcement?
Answer: ERC-2981 provides a standardized, interoperable interface marketplaces can read for royalty info
ERC-2981 standardizes how marketplaces query royalty recipients and amounts, improving interoperability though enforcement remains off-chain.
What is a denial-of-service via a malicious recipient in an auction refund?
Answer: A bidder contract that reverts on receive blocks refunds, freezing the auction
If refunds are pushed and a recipient's fallback reverts, it can block the contract's progress; pull-payment patterns avoid this.
Why is the pull-payment (withdrawal) pattern safer than pushing payments in NFT contracts?
Answer: Each recipient withdraws their own funds, isolating failures and reducing reentrancy/DoS surface
Letting users pull funds isolates a failing transfer to that user and reduces reentrancy and griefing risks.
Why should an NFT contract validate the tokenURI or baseURI source for security?
Answer: A mutable or centralized metadata URI can be changed to point at malicious or rug-pulled content after mint
If metadata is mutable or hosted off-chain centrally, the owner can alter or remove it post-mint, harming holders; immutable/IPFS-pinned URIs mitigate this.