Skip to content

Course

DeFi, Smart Contracts & DAOs

How code replaces the middlemen: DeFi’s building blocks and risks, the classic smart-contract bugs, and how DAOs govern themselves and get attacked.

Intermediate–Advanced3 units · 13 lessons~30 min
0%

Certificate

Not earned yet · 0 of 3 unit checks passed

Syllabus

  1. Unit 1

    DeFi & Web3 Concepts

    Intermediate3 lessons~6 min
    1. Overview, CurrentCurrent1 min
    2. The building blocks, and how an AMM works, Not started1 min
    3. The risks DeFi adds, Not started2 min
    4. Unit check, Not passed5 questions
  2. Unit 2

    Smart Contracts — Spot the Bug

    Advanced6 lessons~16 min
    1. Overview, Not started1 min
    2. A 30-second Solidity primer, Not started1 min
    3. Spot the bug: reentrancy, Not started3 min
    4. Spot the bug: integer overflow, Not started3 min
    5. Spot the bug: access control, Not started3 min
    6. Spot the bug: front-running and MEV, Not started5 min
    7. Unit check, Not passed5 questions
  3. Unit 3

    DAOs & On-chain Governance

    Intermediate4 lessons~8 min
    1. Overview, Not started1 min
    2. Inside a DAO, and voting designs, Not started2 min
    3. On-chain vs off-chain, and treasuries, Not started1 min
    4. When DAOs go wrong, Not started4 min
    5. Unit check, Not passed5 questions

Cheat sheet

DeFi & Web3 Concepts

  • DeFi = financial services built from smart contracts — no bank/broker; the protocol’s code enforces the rules.
  • Building blocks: lending protocols, AMMs/DEXes (liquidity pools), yield, staking, governance tokens.
  • AMMs price via a pool formula (e.g. constant-product x·y=k); LPs earn fees for supplying liquidity.
  • Risks: smart-contract bugs, impermanent loss, oracle manipulation, liquidation, composable/cascading failures, regulatory uncertainty.
  • Every yield comes from somewhere — if you can’t explain it, you may be the source of someone else’s.

Smart Contracts — Spot the Bug

  • A smart contract is code deployed to a chain that executes automatically when called; the contract address holds state and code.
  • Solidity (Ethereum and EVM chains) is the dominant smart-contract language: state variables, functions, modifiers, and events.
  • The "spot the bug" snippets cover the four classic vulnerability classes: reentrancy, integer overflow (pre-0.8), access control, and front-running/MEV.
  • Reentrancy — a callback re-enters the contract before state updates settle — is the most famous class (the DAO hack, 2016).
  • Audits, formal verification, and battle-tested libraries (OpenZeppelin) reduce but never eliminate risk; immutability means bugs are forever.
  • Smart contracts are the substrate for DeFi, DAOs, NFTs, and most of what makes crypto programmable — and most of what makes it dangerous.

DAOs & On-chain Governance

  • A DAO coordinates people, rules, and funds via smart contracts and token-holder votes — replacing (some) corporate structure with code.
  • Voting designs span token-weighted (1 token = 1 vote), quadratic (favoring breadth over wealth), and conviction (rewarding persistent preference). Each has tradeoffs.
  • Treasuries hold protocol-owned assets under governance control; mismanaged or captured treasuries are a top attack vector.
  • On-chain voting is expensive, so most DAOs use off-chain Snapshot signaling and reserve on-chain execution for what passes.
  • Known attacks: flash-loan governance captures (borrow voting power for one tx), plutocracy (whale dominance), and low-turnout captures.
  • DAOs are powerful but experimental; legal status (are they general partnerships? liability shields?) remains unsettled in most jurisdictions.
Educational only, not financial or legal advice.