Blockchain Wallet & Exchange Security Flashcards
6 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Blockchain Wallet & Exchange Security flashcards as text
What is the key security difference between a 'hot wallet' and a 'cold wallet' used by cryptocurrency exchanges?
Answer: Hot wallets are internet-connected and thus more vulnerable to remote attacks
Hot wallets maintain an active internet connection for liquidity, making them the primary target for remote hacking attempts.
Why do major exchanges keep the majority of user funds in cold storage rather than hot wallets?
Answer: Offline storage eliminates the remote attack surface for the bulk of assets
Storing most assets offline means that even a full hot wallet compromise exposes only a small fraction of total funds.
What security control do exchanges use to verify user identity and comply with anti-money laundering requirements?
Answer: Know Your Customer (KYC) verification
KYC procedures require users to submit government-issued ID, enabling exchanges to satisfy AML/CFT compliance obligations.
What is a 'rug pull' in the context of DeFi exchange security?
Answer: Developers draining liquidity pools and abandoning a project after raising funds
In a rug pull, malicious project founders withdraw all pooled liquidity, rendering investors' tokens worthless and pocketing the funds.
What is the purpose of enforcing withdrawal address whitelisting on a centralized exchange account?
Answer: It restricts withdrawals to pre-approved addresses, limiting attacker options even after credential theft
Whitelisting means a compromised account can only send funds to pre-verified addresses, neutralizing the attacker's ability to redirect withdrawals.
Which attack involves sending tiny amounts of cryptocurrency to many addresses to break the privacy of wallet owners through later transaction analysis?
Answer: Dusting attack
A dusting attack sends microscopic 'dust' to target wallets so that when users move those funds the attacker can cluster and de-anonymize their transactions.