Security and Vulnerabilities Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Vulnerabilities flashcards as text
In an upgradeable proxy, what is a storage layout collision?
Answer: Implementation and proxy variables map to the same storage slots, corrupting data
Mismatched storage layouts between proxy and implementation cause variables to overwrite each other unexpectedly.
What is a function selector clashing vulnerability in proxies?
Answer: A proxy admin function shares a 4-byte selector with an implementation function
If a proxy's own function selector matches an implementation function, calls may be misrouted; transparent proxies address this.
Why is relying on contract.balance for accounting logic risky?
Answer: Ether can be force-sent via selfdestruct, breaking exact-balance assumptions
selfdestruct can push Ether into a contract without calling any function, invalidating logic that assumes an exact balance.
What is the primary security benefit of using a time-weighted average price (TWAP) oracle?
Answer: It resists single-block price manipulation
Averaging prices over time makes flash-loan-driven, single-block manipulation economically impractical.
An attacker calls a public function meant to be internal-only because it lacks an access modifier. What category of bug is this?
Answer: Broken access control
Missing or incorrect visibility/permission checks let unauthorized callers execute privileged logic.
What is the recommended approach when a critical bug is found in a deployed immutable contract?
Answer: Pause via a circuit breaker and migrate funds to a fixed contract
Since deployed code is immutable, pause mechanisms and migration to a new contract are the safe response paths.
Why should external/integration assumptions be re-validated after a dependency contract is upgraded?
Answer: A composability change can silently break invariants your contract relies on
DeFi composability means an upgraded dependency can change behavior your contract assumed, introducing new vulnerabilities.