Smart Contract Exploit Analysis Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Smart Contract Exploit Analysis flashcards as text
A flash loan attack typically combines borrowed capital with which secondary weakness?
Answer: A manipulable on-chain price oracle (e.g., spot DEX price)
Flash loans supply huge temporary capital to skew a spot-price oracle and exploit downstream logic in one transaction.
Why is a single-DEX spot price a poor oracle for a lending protocol?
Answer: It can be moved within one transaction via a large swap
Spot prices are instantaneously manipulable, so an attacker can distort collateral valuation atomically.
Which oracle design best resists flash-loan price manipulation?
Answer: A time-weighted average price (TWAP) or decentralized oracle network
TWAPs and robust oracle networks average over time/sources, making single-block manipulation costly.
Front-running (a form of MEV) exploits the fact that:
Answer: Pending transactions are visible in the mempool and ordering can be bought
Searchers observe pending txs and pay higher fees to be ordered first, capturing value such as arbitrage or liquidations.
A sandwich attack against a DEX swap involves the attacker:
Answer: Placing a buy before and a sell after the victim's trade
The attacker front-runs to push the price up, lets the victim buy at the worse price, then back-runs to sell.
A commit-reveal scheme primarily mitigates which exploit?
Answer: Front-running of sensitive parameters
Committing a hashed value first hides intent until reveal, preventing attackers from front-running the data.
Relying on `block.timestamp` for critical randomness or deadlines is risky because:
Answer: Miners/validators can slightly manipulate it within bounds
Block producers have limited influence over the timestamp, so it must not be trusted for randomness or tight financial logic.