← All CCA Flashcard Decks

Smart Contract Auditing Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Smart Contract Auditing flashcards as text
  1. What is a 'flash loan attack' and which property of flash loans enables it?

    Answer: An attack exploiting uncollateralized loans that must be repaid in the same transaction, enabling temporary large capital control

    Flash loans require no collateral and must be repaid within one transaction, giving attackers temporary access to large capital they can use to manipulate prices or exploit protocol logic.

  2. Which audit finding classification is most critical and requires immediate remediation before deployment?

    Answer: Critical

    Critical findings represent vulnerabilities that can lead to total or near-total loss of funds or complete protocol compromise and must be fixed before any deployment.

  3. A contract emits an event for every state change but does not actually update the on-chain state. What type of vulnerability is this?

    Answer: Event spoofing — off-chain listeners are misled about contract state

    Emitting events without corresponding state changes deceives off-chain systems (indexers, frontends) into believing an action occurred when it did not.

  4. What is the significance of EIP-712 in the context of smart contract security audits?

    Answer: It provides a structured, typed data hashing standard for off-chain signatures to prevent replay attacks

    EIP-712 specifies a typed structured data signing standard that includes domain separators, helping prevent cross-chain and cross-contract signature replay attacks.

  5. An auditor finds that a DeFi protocol's price oracle uses spot prices from a single AMM pool. What is the primary attack vector?

    Answer: Price manipulation via flash loans within a single transaction

    Spot prices from AMMs can be temporarily manipulated within a single transaction using flash loans, making them unreliable for on-chain price feeds.

  6. What does the term 'business logic vulnerability' mean in smart contract auditing?

    Answer: A flaw in the contract's intended rules and workflows that can be exploited even when the code executes correctly

    Business logic vulnerabilities arise when the contract's logic can be exploited in ways the developers did not intend, even if the code is technically correct from a language standpoint.

  7. Which Solidity keyword should an auditor flag when found in a public or external function handling critical state?

    Answer: `payable` without access control

    A `payable` function without proper access control allows any caller to send ETH and potentially trigger unintended behavior or drain funds.