Skip to content
Tech Interview Prep home
Technical interview guide

Smart Contract Security & Common Vulnerabilities

Why smart contract bugs are uniquely costly — immutable, public, and directly holding funds — and the vulnerability classes that recur across major exploits.

Read
50 min
Practice MCQs
25
Interview QA
25
Edition
v3
Editorial status
Reviewed

Scope: OWASP Smart Contract Security Verification Standard and Smart Contract Top 10:2026 reviewed 2026-09-04; Solidity latest security guidance; OpenZeppelin Contracts 5.x and Upgrades documentation; Chainlink Data Feeds documentation.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Review a withdrawal function for reentrancy.

QA-2

Secure deployment and initialization of an upgradeable contract.

QA-3

Threat-model a new collateralized lending contract.

QA-4

Design roles for upgrade, pause, oracle, treasury, and routine operations.

QA-5

How do storage collisions occur in proxy-based upgradeable smart contracts, and how are they prevented?

QA-6

Test a contract for cross-function and cross-contract reentrancy.

QA-7

Prevent consumers from observing an inconsistent share price during callbacks.

QA-8

Harden a low-level external integration.

QA-9

Safely accept multiple token contracts into a vault.

QA-10

Review optimized unchecked arithmetic.

QA-11

Design share conversion without exploitable rounding.

QA-12

Implement a failure-aware oracle read.

QA-13

Choose a manipulation-resistant price for lending.

QA-14

Test a protocol under flash-loan-scale capital.

QA-15

Protect a public transaction from ordering manipulation.

QA-16

Design randomness for an on-chain allocation.

QA-17

Replace an unbounded settlement loop.

QA-18

Design a permit-like signed operation.

QA-19

Secure a modular contract that supports plugins.

QA-20

Define validation for a collateral configuration update.

QA-21

Define and test invariants for a tokenized vault.

QA-22

Design emergency controls for a lending protocol.

QA-23

Create a smart-contract security test matrix.

QA-24

Prepare and respond to a professional contract audit.

QA-25

Write an exploit-response runbook for an upgradeable protocol.