โ† All NFT Flashcard Decks

Smart Contract Security Audits Flashcards

7 cards from real NFT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Smart Contract Security Audits flashcards as text
  1. A reentrancy vulnerability in an NFT marketplace contract most commonly arises when which pattern is violated?

    Answer: Checks-Effects-Interactions

    Reentrancy occurs when external calls happen before state is updated, violating the Checks-Effects-Interactions ordering.

  2. During an audit, you find an ERC-721 mint function using tx.origin for authorization. Why is this a security risk?

    Answer: It can be phished through an intermediary contract

    tx.origin lets a malicious contract relay a legitimate user's call, enabling phishing attacks, so msg.sender should be used instead.

  3. Which tool is a symbolic execution engine commonly used to audit Ethereum smart contracts?

    Answer: Mythril

    Mythril uses symbolic execution to detect security vulnerabilities in EVM bytecode.

  4. An NFT contract's royalty logic relies on an unbounded loop over all token holders. What audit finding does this represent?

    Answer: Denial-of-service via gas limit

    Unbounded loops can exceed the block gas limit, causing transactions to permanently fail and locking functionality.

  5. Why should an audited NFT contract avoid using block.timestamp as a source of randomness for trait assignment?

    Answer: Miners/validators can manipulate it

    Block producers have limited control over the timestamp, making it predictable and exploitable for on-chain randomness.

  6. A reviewer flags that an NFT contract's owner can change the metadata base URI at any time. What is the primary concern?

    Answer: Centralization / rug-pull risk on immutable assets

    Mutable metadata controlled by a single owner undermines the claimed immutability of the NFT and is a centralization risk.

  7. Which Solidity feature, available since version 0.8.0, removed the need for the SafeMath library in most audits?

    Answer: Built-in arithmetic overflow/underflow checks

    Solidity 0.8.0 added automatic reverting on overflow and underflow, making SafeMath largely redundant.