Smart Contract Exploit Analysis Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Smart Contract Exploit Analysis flashcards as text
Before Solidity 0.8.0, an unchecked addition that exceeds uint256 max would:
Answer: Wrap around to a small number (overflow)
Pre-0.8.0 arithmetic wrapped silently on overflow, enabling balance manipulation exploits.
How does Solidity 0.8.0+ handle integer overflow and underflow by default?
Answer: Reverts the transaction on over/underflow
Solidity 0.8.0 introduced built-in checked arithmetic that reverts on overflow/underflow.
What is the security risk of wrapping arithmetic in an `unchecked { }` block in Solidity 0.8+?
Answer: It disables overflow/underflow protection inside the block
The `unchecked` block restores wrapping behavior, reintroducing overflow risk if used carelessly.
An underflow in a token balance subtraction (balance -= amount) before checks could let an attacker:
Answer: Obtain a massive balance from a small one
Underflowing a subtraction below zero wraps to near uint256 max, granting an enormous fake balance.
Which library was historically used to add overflow protection before Solidity 0.8?
Answer: SafeMath
OpenZeppelin's SafeMath provided checked add/sub/mul/div that reverted on overflow.
The 2018 BeautyChain (BEC) batchTransfer exploit was caused by:
Answer: A multiplication overflow inflating transfer amounts
An overflow in `amount * receivers.length` produced huge balances minted to attackers.
Casting a uint256 down to uint8 without validation can introduce what bug?
Answer: Silent truncation of the high bits
Narrowing casts drop high-order bits, so a large value can become an unexpectedly small one.