← All CCA Flashcard Decks

Cryptocurrency Transaction Auditing Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cryptocurrency Transaction Auditing flashcards as text
  1. Which type of Ethereum transaction would have a 'to' field set to null?

    Answer: A contract creation transaction

    Contract creation transactions have a null 'to' field; the contract address is derived from the deployer's address and nonce after mining.

  2. An auditor identifies that a wallet received funds from a sanctioned entity on the OFAC SDN list three hops earlier in the transaction graph. What is the appropriate audit finding classification?

    Answer: Indirect sanctions exposure requiring enhanced due diligence and potential SAR filing

    Indirect sanctions exposure (funds traceable to an SDN within a few hops) triggers enhanced due diligence and potentially a SAR, even without direct counterparty contact.

  3. What is the significance of a Bitcoin transaction with an 'OP_RETURN' output from an audit perspective?

    Answer: It embeds arbitrary data on-chain, which may include evidence of off-chain agreements or protocol-level metadata

    OP_RETURN outputs store up to 80 bytes of arbitrary data on-chain and are used by audit trails, timestamping services, and some token protocols.

  4. When auditing a crypto exchange's proof of reserves, which cryptographic technique allows the exchange to prove it controls specific addresses without revealing customer balances individually?

    Answer: Merkle tree-based proof of liabilities combined with signed address control messages

    Merkle tree PoR allows exchanges to commit to total liabilities, let users verify their inclusion, and sign reserve addresses — proving solvency without exposing individual balances.

  5. A CCA auditor finds that a DeFi protocol's governance token holders voted to redirect protocol treasury funds to a newly created wallet. What governance attack does this pattern resemble?

    Answer: A governance takeover via flash-loan-acquired voting power

    Flash loan governance attacks borrow large token amounts within a single block to acquire temporary voting majority, pass malicious proposals, and repay the loan—all in one transaction.

  6. Which blockchain forensics concept describes the process of assigning risk scores to transactions based on the proportion of funds traceable to illicit sources?

    Answer: Taint analysis (percentage-based contamination tracing)

    Taint analysis propagates a risk percentage through the transaction graph based on what fraction of funds in each transaction originated from flagged sources.

  7. In auditing a crypto lending protocol, which event indicates that a borrower's collateral was liquidated due to undercollateralization?

    Answer: A Liquidation or LiquidationCall event with the collateral asset and debt repaid amount

    Liquidation events emitted by lending protocols record the specific collateral seized, debt repaid, and liquidator address, providing a complete audit trail of the forced closure.