Smart Contract Vulnerabilities Flashcards
7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Smart Contract Vulnerabilities flashcards as text
What is the purpose of a 'circuit breaker' (emergency stop) pattern in smart contract design?
Answer: To allow an authorized party to pause certain contract functions when an attack or critical bug is detected
A circuit breaker introduces a boolean pause flag that halts sensitive operations, giving developers time to respond to exploits without requiring an immediate upgrade.
A developer deploys a contract that reads price data from a Chainlink oracle but does not check the 'updatedAt' timestamp. What vulnerability does this create?
Answer: The contract may use stale price data if the oracle has not updated recently, enabling price manipulation exploits
Without validating that the oracle's updatedAt timestamp is recent, the contract may act on stale prices during network outages or oracle failures, enabling attackers to profit from the discrepancy.
Which vulnerability is introduced when an upgradeable contract's 'initialize' function lacks an 'initializer' modifier or equivalent guard?
Answer: Any caller can invoke initialize multiple times, potentially resetting ownership or critical state to attacker-controlled values
Without an initializer guard, the initialize function can be called repeatedly or by an unauthorized party, allowing an attacker to take ownership of the contract.
What is a 'sandwich attack' in DeFi, and which two roles does the attacker simultaneously play?
Answer: Front-runner and back-runner — placing one transaction before and one after the victim's transaction to profit from induced price slippage
The attacker buys before the victim (increasing price), lets the victim's large trade execute at a worse rate, then sells immediately after, profiting from the induced slippage.
A contract emits an 'Approval' event but never actually updates the allowance mapping. Which vulnerability category does this represent?
Answer: Event spoofing / misleading event emission
Emitting events without corresponding state changes deceives off-chain systems (wallets, indexers) into believing an action occurred, which can be exploited to authorize operations that were never truly granted.
Which mitigation directly addresses the risk of a compromised or malicious contract being set as the logic implementation in an upgradeable proxy?
Answer: Using a timelocked upgrade process with a multi-signature governance requirement
A timelock combined with multi-sig governance ensures no single party can instantly swap in malicious logic; stakeholders have a window to detect and cancel a malicious upgrade.
What is a 'logic bomb' in the context of smart contract security?
Answer: Malicious code hidden in the contract that activates under specific conditions (e.g., a date or caller address) to drain funds or disable the contract
A logic bomb is intentionally inserted malicious logic that remains dormant until a trigger condition is met, at which point it executes destructive actions — a supply chain threat in audited contracts.