DeFi Security and Audits Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 DeFi Security and Audits flashcards as text
What is the primary purpose of a timelock on DeFi governance actions?
Answer: It gives users a window to react or exit before privileged changes take effect
A timelock delays execution of approved changes so users can review them and withdraw if they disagree, limiting malicious or rushed upgrades.
A protocol with low token distribution faces what governance risk?
Answer: A whale or flash-loan attacker can pass malicious proposals
Concentrated voting power, or temporarily borrowed tokens via flash loans, can let an attacker push through self-serving proposals.
During an audit, what does 'centralization risk' from an owner-only pause function indicate?
Answer: A single key can halt or alter the protocol, a single point of failure
Privileged admin functions controlled by one key create a single point of failure that can be compromised or abused.
What is the benefit of using a multisig wallet for protocol admin keys?
Answer: It requires multiple parties to approve privileged actions, reducing single-key risk
A multisig spreads authority across several signers so no single compromised key can unilaterally control the protocol.
What is a key purpose of a bug bounty program for a DeFi protocol?
Answer: Incentivizing white-hat researchers to disclose vulnerabilities responsibly
Bug bounties reward ethical hackers for reporting flaws privately, adding a continuous layer of security beyond one-time audits.
Why should an audit verify that ERC-20 'transfer' return values are checked?
Answer: Some tokens return false instead of reverting on failure, causing silent failures
Non-standard tokens may return false rather than revert, so ignoring the return value can leave the protocol thinking a transfer succeeded.
What is the risk of 'fee-on-transfer' tokens in a DeFi pool?
Answer: The amount received differs from the amount sent, breaking accounting assumptions
Tokens that deduct a fee on transfer deliver fewer tokens than expected, corrupting balance accounting if the contract assumes exact amounts.