Knowledgebase

Smart Contract Vulnerabilities Print

  • blockchaindigitalassets, blockchain, guide, howto, solution, zillionkinghost, hosting, support
  • 0

Known failure classes.

WHAT REENTRANCY IS

A contract calling out to another, which calls back before the first finished updating.

WHAT IT PERMITS

Repeated withdrawal before balances are reduced.

WHAT PREVENTS IT

Updating state before making external calls, and reentrancy guards.

WHY IT REMAINS COMMON

It is easy to introduce and not visible on casual reading.

WHAT ACCESS CONTROL FAILURES ARE

Functions callable by anyone that should not be.

WHAT THEY PERMIT

Anything the function does, including draining or destroying.

WHAT ARITHMETIC ERRORS CAUSE

Values wrapping around, producing enormous or negative results.

WHAT ADDRESSES THEM

Language-level checks, present in modern versions.

WHAT ORACLE MANIPULATION IS

Influencing the external price a contract relies on.

HOW IT IS DONE

Temporarily moving the price on a source the contract reads.

WHAT PREVENTS IT

Prices from several sources, averaged over time.

WHAT FRONT-RUNNING IS

Observing a pending transaction and acting before it.

WHY IT IS POSSIBLE

Pending transactions are publicly visible.

WHAT IT PERMITS

Extracting value from others' trades.

WHAT LOGIC ERRORS PRODUCE

Behaviour that is technically correct and commercially wrong.

WHY AUDITS MATTER MOST FOR THOSE

Tools find patterns; people find intent mismatches.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot