โ† All Blockchain Technology Flashcard Decks

Smart Contract Exploit Analysis Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Smart Contract Exploit Analysis flashcards as text
  1. In a reentrancy attack, what must the vulnerable contract do BEFORE updating its internal state?

    Answer: Make an external call that transfers value

    Reentrancy occurs when an external call is made before state changes, letting the callee re-enter and exploit stale state.

  2. Which coding pattern most directly prevents reentrancy attacks?

    Answer: Checks-Effects-Interactions

    Checks-Effects-Interactions updates state before external calls, removing the reentrancy window.

  3. The 2016 DAO hack on Ethereum primarily exploited which vulnerability class?

    Answer: Reentrancy

    The DAO's split function made an external call before zeroing the balance, allowing recursive withdrawals.

  4. A read-only reentrancy attack abuses what specifically?

    Answer: A view function returning inconsistent state mid-execution

    Read-only reentrancy exploits view functions that report stale or inconsistent values while a callback is in progress.

  5. Which mechanism does OpenZeppelin's ReentrancyGuard use to block reentry?

    Answer: A status flag locked during execution (nonReentrant modifier)

    ReentrancyGuard sets a lock variable that reverts any nested call into a guarded function.

  6. Cross-function reentrancy is dangerous because the attacker re-enters through:

    Answer: A different function sharing the same state variables

    Cross-function reentrancy re-enters a separate function that reads or writes the same unupdated state.

  7. Why does using `transfer()` (2300 gas) no longer reliably prevent reentrancy?

    Answer: Gas costs can change via hard forks, breaking the fixed stipend assumption

    EIP-driven gas repricing (e.g., EIP-1884) can make the 2300 stipend insufficient or its protection assumption unreliable, so guards are preferred.