Smart Contract Security Flashcards
7 cards from real NFT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Smart Contract Security flashcards as text
In an ERC-721 contract, which function should use _safeMint instead of _mint when the recipient may be a contract?
Answer: When the recipient must be verified to accept ERC-721 tokens via onERC721Received
_safeMint checks that contract recipients implement onERC721Received, preventing tokens from being locked in incompatible contracts.
What is a reentrancy attack in the context of an NFT marketplace contract?
Answer: An attacker repeatedly calls back into the contract before state updates complete, draining funds
Reentrancy occurs when an external call lets an attacker re-enter the function before balances or ownership state are finalized.
Which pattern best prevents reentrancy in a withdraw function?
Answer: Checks-Effects-Interactions: update state before making external calls
Updating internal state before external calls ensures a re-entrant call sees the already-updated state.
Why is using tx.origin for authorization in an NFT contract dangerous?
Answer: A malicious intermediary contract can trick the user into authorizing actions via phishing
tx.origin is the original EOA, so an intermediary contract the user calls can impersonate the user's authority.
What does the OpenZeppelin ReentrancyGuard's nonReentrant modifier do?
Answer: Sets a lock flag preventing the function from being called again until it completes
nonReentrant uses a status flag to block recursive calls into guarded functions until the first call returns.
An NFT minting function uses block.timestamp for randomness in trait assignment. Why is this insecure?
Answer: Miners/validators can influence block.timestamp to manipulate outcomes
On-chain values like block.timestamp are predictable and partly manipulable, making them unsafe sources of randomness.
What is the risk of leaving an NFT contract's mint function without access control?
Answer: Anyone can mint unlimited tokens, destroying scarcity and value
Without onlyOwner or role checks, any caller can mint arbitrarily, breaking the intended supply model.