โ† All Blockchain Technology Flashcard Decks

Security and Attacks Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Attacks flashcards as text
  1. What is a 'bridge exploit' and why are cross-chain bridges high-value targets?

    Answer: Attacking smart contracts that hold large reserves of locked assets to mint unbacked tokens on the destination chain

    Bridges lock assets on one chain and mint wrapped tokens on another; exploiting the lock contract allows attackers to mint tokens without depositing real assets, as seen in the Ronin and Wormhole hacks.

  2. What is 'wash trading' in the context of NFT marketplaces and why is it harmful?

    Answer: Buying and selling NFTs to oneself or colluders to artificially inflate perceived trading volume and prices

    Wash trading creates false price discovery and misleads buyers about an NFT's value, potentially constituting market manipulation and defrauding investors.

  3. Which cryptographic weakness made early Bitcoin brain wallets (password-derived keys) vulnerable to theft?

    Answer: Low-entropy passwords could be brute-forced offline since the public address alone revealed which hash function to attack

    Brain wallets hash a password to derive a private key; weak passwords are trivially brute-forced against all known Bitcoin addresses using GPU clusters.

  4. What is 'phishing via fake token approval' and how does it compromise DeFi users?

    Answer: Tricking users into signing unlimited token approval transactions that grant malicious contracts full spending authority

    Malicious sites prompt users to approve unlimited token allowances to attacker contracts, which can then drain approved tokens at any time without further user interaction.

  5. What security threat does 'weak nonce reuse' in ECDSA signatures pose to blockchain wallets?

    Answer: Reusing the same nonce in two signatures allows recovery of the private key using simple algebra

    If the same ECDSA nonce k is used twice with different messages, the private key can be algebraically derived from the two public signatures alone.

  6. How does a 'vampire attack' work in the DeFi ecosystem?

    Answer: A new protocol forks a competitor and offers superior incentives to migrate liquidity providers, draining the original protocol

    Vampire attacks offer outsized token rewards to poach liquidity providers from established protocols, rapidly shifting TVL and user base to the new entrant.

  7. What is 'smart contract honeypot' and how does it trap attackers?

    Answer: A contract that appears to have an exploitable vulnerability but contains a hidden mechanism that prevents fund withdrawal

    Honeypot contracts appear exploitable (e.g., seemingly exposed funds) but use hidden code to trap attackers' deposited ETH, turning the tables on would-be exploiters.