← All CCA Flashcard Decks

Smart Contract Auditing Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Smart Contract Auditing flashcards as text
  1. What vulnerability is introduced when a Solidity contract performs arithmetic without overflow/underflow checks in versions prior to 0.8.0?

    Answer: Integer overflow/underflow

    Prior to Solidity 0.8.0, arithmetic operations would silently wrap around on overflow/underflow, potentially allowing attackers to manipulate balances or counters.

  2. An auditor discovers a contract that relies on `block.timestamp` for a time-locked withdrawal. What is the main risk?

    Answer: Miners can manipulate timestamps by a small margin to affect condition checks

    Miners have limited ability to manipulate `block.timestamp` by roughly 15 seconds, which can be enough to influence time-sensitive conditions.

  3. What is the purpose of a 'fuzz testing' tool like Echidna in smart contract security?

    Answer: To generate random inputs and detect property violations automatically

    Echidna is a fuzzer that generates random transaction sequences to find inputs that violate user-defined properties or invariants in smart contracts.

  4. Which attack type exploits the ordering of transactions in the mempool to profit from a victim's pending transaction?

    Answer: Front-running (MEV)

    Front-running, a form of Miner/Maximal Extractable Value (MEV), allows bots to observe pending transactions and submit competing transactions with higher gas fees to execute first.

  5. A contract uses `delegatecall` to an untrusted address. What is the primary danger?

    Answer: The callee's code executes in the caller's storage context, allowing state manipulation

    With `delegatecall`, the called contract's code runs using the calling contract's storage and context, so a malicious callee can overwrite critical state variables.

  6. What does a 'pull payment' pattern protect against in smart contract design?

    Answer: Reentrancy and failed-send denial of service by separating withdrawal logic from business logic

    Pull payments require recipients to withdraw their funds themselves, preventing a malicious recipient from causing the entire payout function to fail and blocking other recipients.

  7. During an audit, you find that a contract's constructor sets the owner but the contract is designed to be used as an implementation behind a proxy. What is the risk?

    Answer: Constructor code is not stored in bytecode, so the proxy never initializes the owner

    For proxy-based upgradeable contracts, constructors do not run in the proxy's context; an `initialize` function must be used instead to set up state correctly.