โ† All NFT Flashcard Decks

Smart Contract Security Audits Flashcards

7 cards from real NFT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Smart Contract Security Audits flashcards as text
  1. An upgradeable NFT contract uses delegatecall to a logic contract. Which vulnerability class is most critical to audit here?

    Answer: Storage layout collisions and uninitialized proxies

    Proxy patterns risk storage collisions and uninitialized implementation contracts that attackers can hijack.

  2. A famous proxy exploit occurred because the implementation contract's initializer could be called by anyone. What is the fix?

    Answer: Use the initializer modifier and lock it in the constructor/disableInitializers

    Initializers must be protected so they run once, and implementation contracts should disable initializers to prevent takeover.

  3. An auditor checks an NFT staking contract and finds rewards calculated from an oracle price with no staleness check. What should be added?

    Answer: Validate the oracle's updatedAt timestamp and round data

    Oracle data should be validated for freshness to avoid using stale or manipulated prices.

  4. Which condition makes a flash-loan attack against an NFT-collateralized lending protocol possible?

    Answer: Pricing based on manipulable on-chain spot liquidity

    If valuations rely on spot prices that a flash loan can move within one transaction, attackers can manipulate collateral value.

  5. During an audit you find a function marked payable that does not need to receive ETH. What is the recommended action?

    Answer: Remove payable to prevent accidental locked funds

    Unnecessary payable functions can trap ETH if there is no withdrawal path, so the modifier should be removed.

  6. An ERC-721 contract uses _mint instead of _safeMint in a public function. Why might an auditor flag this?

    Answer: _mint skips the onERC721Received recipient check

    _safeMint verifies contract recipients can handle NFTs, while _mint can send tokens to contracts that will lock them.

  7. What is the purpose of a reentrancy guard (e.g., nonReentrant) in an NFT auction contract?

    Answer: Prevent nested calls from re-entering before state finalizes

    A reentrancy guard uses a mutex to block a function from being re-entered during an external call.