โ† All Blockchain Technology Flashcard Decks

Security and Vulnerabilities Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Vulnerabilities flashcards as text
  1. In an upgradeable proxy, what is a storage layout collision?

    Answer: Implementation and proxy variables map to the same storage slots, corrupting data

    Mismatched storage layouts between proxy and implementation cause variables to overwrite each other unexpectedly.

  2. What is a function selector clashing vulnerability in proxies?

    Answer: A proxy admin function shares a 4-byte selector with an implementation function

    If a proxy's own function selector matches an implementation function, calls may be misrouted; transparent proxies address this.

  3. Why is relying on contract.balance for accounting logic risky?

    Answer: Ether can be force-sent via selfdestruct, breaking exact-balance assumptions

    selfdestruct can push Ether into a contract without calling any function, invalidating logic that assumes an exact balance.

  4. What is the primary security benefit of using a time-weighted average price (TWAP) oracle?

    Answer: It resists single-block price manipulation

    Averaging prices over time makes flash-loan-driven, single-block manipulation economically impractical.

  5. An attacker calls a public function meant to be internal-only because it lacks an access modifier. What category of bug is this?

    Answer: Broken access control

    Missing or incorrect visibility/permission checks let unauthorized callers execute privileged logic.

  6. What is the recommended approach when a critical bug is found in a deployed immutable contract?

    Answer: Pause via a circuit breaker and migrate funds to a fixed contract

    Since deployed code is immutable, pause mechanisms and migration to a new contract are the safe response paths.

  7. Why should external/integration assumptions be re-validated after a dependency contract is upgraded?

    Answer: A composability change can silently break invariants your contract relies on

    DeFi composability means an upgraded dependency can change behavior your contract assumed, introducing new vulnerabilities.