Smart Contract Exploit Analysis Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Smart Contract Exploit Analysis flashcards as text
In a reentrancy attack, what must the vulnerable contract do BEFORE updating its internal state?
Answer: Make an external call that transfers value
Reentrancy occurs when an external call is made before state changes, letting the callee re-enter and exploit stale state.
Which coding pattern most directly prevents reentrancy attacks?
Answer: Checks-Effects-Interactions
Checks-Effects-Interactions updates state before external calls, removing the reentrancy window.
The 2016 DAO hack on Ethereum primarily exploited which vulnerability class?
Answer: Reentrancy
The DAO's split function made an external call before zeroing the balance, allowing recursive withdrawals.
A read-only reentrancy attack abuses what specifically?
Answer: A view function returning inconsistent state mid-execution
Read-only reentrancy exploits view functions that report stale or inconsistent values while a callback is in progress.
Which mechanism does OpenZeppelin's ReentrancyGuard use to block reentry?
Answer: A status flag locked during execution (nonReentrant modifier)
ReentrancyGuard sets a lock variable that reverts any nested call into a guarded function.
Cross-function reentrancy is dangerous because the attacker re-enters through:
Answer: A different function sharing the same state variables
Cross-function reentrancy re-enters a separate function that reads or writes the same unupdated state.
Why does using `transfer()` (2300 gas) no longer reliably prevent reentrancy?
Answer: Gas costs can change via hard forks, breaking the fixed stipend assumption
EIP-driven gas repricing (e.g., EIP-1884) can make the 2300 stipend insufficient or its protection assumption unreliable, so guards are preferred.