โ† All Blockchain Technology Flashcard Decks

Smart Contract Exploit Analysis Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Smart Contract Exploit Analysis flashcards as text
  1. A function meant only for the owner that lacks an `onlyOwner` check is vulnerable to:

    Answer: Unauthorized access / privilege escalation

    Missing access control lets any caller invoke privileged functions like withdraw or upgrade.

  2. The Parity multisig wallet freeze (2017) occurred because an attacker called which exposed function?

    Answer: An uninitialized initWallet/library kill (selfdestruct) function

    An unprotected initialization function let an attacker take ownership and selfdestruct the shared library, freezing wallets.

  3. Using `tx.origin` for authorization is dangerous because:

    Answer: A malicious intermediary contract can phish the original signer's authority

    `tx.origin` reflects the original EOA, so a victim calling an attacker contract passes the auth check unintentionally.

  4. In an upgradeable proxy, leaving the implementation contract's initializer callable can lead to:

    Answer: An attacker initializing it and self-destructing or hijacking logic

    An uninitialized implementation can be seized by anyone, who may then run delegatecall-based destruction.

  5. A `delegatecall` to an attacker-controlled address is critical because the callee can:

    Answer: Modify the caller's storage and context directly

    `delegatecall` executes external code in the caller's storage context, allowing arbitrary state overwrites.

  6. Which design reduces single-point access-control risk for sensitive admin actions?

    Answer: A multisig or timelock-governed role

    Multisig and timelock controls distribute authority and add delay, limiting damage from a compromised key.

  7. Default function and state-variable visibility issues are mitigated by:

    Answer: Explicitly declaring visibility (public/external/internal/private)

    Explicit visibility prevents accidentally exposing functions or state that should be restricted.