Security, Risk, and Vulnerabilities Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security, Risk, and Vulnerabilities flashcards as text
Which attack vector exploits the predictability of a smart contract's pseudo-random number generation (PRNG) to manipulate lottery or gambling outcomes?
Answer: PRNG manipulation attack
PRNG manipulation attacks exploit weak randomness sources like block hashes or timestamps that miners or validators can influence to predict or bias outcomes.
In the context of cryptocurrency exchange security, what is a 'cold wallet' sweep attack?
Answer: Stealing funds by accessing air-gapped systems through physical intrusion or insider threat
A cold wallet sweep attack targets air-gapped or offline storage through insider threats, physical access, or supply chain compromise to extract private keys.
What vulnerability is introduced when a Solidity smart contract uses 'tx.origin' for authentication instead of 'msg.sender'?
Answer: Phishing via contract intermediary
Using tx.origin allows a malicious intermediary contract to trick the original sender into unknowingly authorizing transactions, enabling phishing attacks.
Which risk category does 'validator centralization' fall under in a Proof-of-Stake blockchain?
Answer: Systemic/concentration risk
Validator centralization creates systemic concentration risk because a small group controlling majority stake can collude to censor transactions or perform 51% attacks.
What is the primary security concern with 'infinite approval' patterns in ERC-20 token interactions with DeFi protocols?
Answer: They allow protocols to drain a user's entire token balance if compromised
Infinite approvals grant a protocol unlimited spending rights over a user's tokens, meaning if the protocol contract is exploited, all approved tokens can be stolen.
Which type of attack involves an adversary isolating a blockchain node by monopolizing all of its peer connections?
Answer: Eclipse attack
An eclipse attack monopolizes a victim node's peer connections with attacker-controlled nodes, isolating it from the honest network and enabling double-spend or selfish mining attacks.
During a cryptocurrency audit, an auditor finds that a exchange stores user seed phrases encrypted with a single master key. What is the primary risk identified?
Answer: Single point of failure โ compromise of the master key exposes all user seeds
A single master key is a critical single point of failure; if it is compromised, all encrypted seed phrases become accessible, jeopardizing every user's funds.