โ† All Blockchain Technology Flashcard Decks

Security and Vulnerabilities Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Vulnerabilities flashcards as text
  1. What is a front-running attack in the context of a public mempool?

    Answer: An attacker observes a pending transaction and submits their own with higher gas to execute first

    Because pending transactions are visible, attackers can pay more gas to be ordered ahead and profit from the victim's intended action.

  2. A commit-reveal scheme is primarily used to mitigate which problem?

    Answer: Front-running of submitted values

    Committing a hash first and revealing later hides the value during the vulnerable ordering window.

  3. Why is using a single DEX spot price as a price oracle dangerous?

    Answer: It can be manipulated with flash loans

    An attacker can use a flash loan to skew the pool's spot price within a single transaction and exploit dependent contracts.

  4. What does a flash loan allow an attacker to do?

    Answer: Borrow large amounts with no collateral if repaid in the same transaction

    Flash loans provide uncollateralized capital that must be repaid within the same transaction, enabling large temporary capital for exploits.

  5. Which access-control mistake leaves an initialization function exploitable in upgradeable contracts?

    Answer: Forgetting to protect or disable the initializer so anyone can call it

    An unprotected initializer can be called by an attacker to seize ownership of the proxy.

  6. What is the security concern with delegatecall to an untrusted contract?

    Answer: The callee executes in the caller's storage context and can overwrite its state

    delegatecall runs target code against the caller's storage, so malicious code can corrupt or hijack the calling contract.

  7. A contract uses an unbounded loop over a dynamically growing array. What risk does this create?

    Answer: The function may exceed the block gas limit and become unusable

    As the array grows, iterating over it can require more gas than a block allows, permanently locking the function (a DoS).

Security and Vulnerabilities Flashcards โ€” Blockchain Technology Study Cards with Answers