โ† All Blockchain Technology Flashcard Decks

Security and Attacks Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Attacks flashcards as text
  1. What is the 'long-range attack' threat specific to Proof-of-Stake blockchains?

    Answer: An attacker uses old private keys from past validators to rewrite blockchain history from a distant point

    Long-range attacks use old validator keys (when stake was cheaper) to create an alternative chain from far in the past, which PoS systems mitigate with checkpointing.

  2. What is 'front-running' in the context of blockchain transaction ordering?

    Answer: Observing a pending transaction in the mempool and submitting a competing one with higher gas to be processed first

    Front-running exploits the public mempool by inserting a transaction with higher gas fees ahead of a target transaction to capture arbitrage or MEV profits.

  3. Which Ethereum upgrade mechanism is exploited in an 'upgrade proxy attack'?

    Answer: Attackers compromise the admin key of an upgradeable proxy contract to replace the logic contract with malicious code

    Upgradeable proxy contracts delegate calls to a logic contract; if the admin key is compromised, attackers can swap in a malicious implementation.

  4. What security risk does 'tx.origin' pose compared to 'msg.sender' in Solidity?

    Answer: tx.origin reveals the original EOA, making phishing contracts able to pass authorization checks

    Using tx.origin for authentication allows malicious intermediary contracts to impersonate the original caller, bypassing security checks.

  5. What is 'miner extractable value' (MEV) and why is it a security concern?

    Answer: Profits miners capture by reordering, inserting, or censoring transactions, creating unfair advantages and potential instability

    MEV allows block producers to exploit their ordering power to profit at users' expense, leading to network congestion, unfairness, and potential consensus instability.

  6. What is a 'flash loan attack' and which property makes flash loans uniquely risky?

    Answer: Borrowing large uncollateralized sums within one transaction to manipulate prices and repay, possible because atomicity guarantees repayment

    Flash loans are uncollateralized because they must be repaid in the same transaction; attackers use the temporary capital to manipulate DeFi protocols profitably.

  7. How does 'griefing' differ from theft in smart contract attacks?

    Answer: Griefing aims to cause financial loss or inconvenience to others without direct profit to the attacker

    Griefing attacks cause harm (wasted gas, locked contracts, failed transactions) as the goal itself rather than as a means to steal funds.