On this page
Spot the bug — front-running / MEV
MEV (Maximal Extractable Value) is value extractable from transaction ordering. A searcher or validator can see your pending transaction in the mempool and insert their own before it (front-running) or after it (back-running), profiting at your expense. Sandwich attacks (front-run + back-run around a swap) are the classic.
A sandwich around your swap
Vulnerable swap (front-runnable)
Click the line you think is the bugReal audit work involves far more: privilege analysis, oracle manipulation, cross-contract interactions, gas-griefing, and the interaction of multiple “individually safe” functions. The snippets here teach pattern recognition for the four most famous classes; they don't make you an auditor.
The canonical fix for reentrancy is the checks-effects-interactions pattern: do all precondition checks first, then update all state (effects), and only then make external calls (interactions). Because state is already updated when the external call happens, a reentrant call sees the new state and can't double-spend. The OpenZeppelin ReentrancyGuard provides a nonReentrant modifier as a belt-and-suspenders defense that reverts if a function is re-entered. Both are standard; use both for anything handling value.
Because smart contracts are immutable, projects often use upgradable proxy patterns: a thin proxy contract delegates calls to an implementation address that can be swapped by governance. This lets teams patch bugs — but it concentrates power (an upgradable contract is only as decentralized as the upgrade path), introduces storage collision bugs (new implementation variables must slot into the proxy's layout), and has itself been the source of major exploits (the Parity wallet freeze, 2017, was a proxy initialization bug). The tradeoff is fundamental: immutability gives users guarantees but no recovery; upgradability gives recovery but weakens guarantees.
How this connects to the rest of NodeScholar
Smart contracts are the substrate for DeFi and DAOs (most of the attacks in the DAOs unit are smart-contract bugs), and they underlie the cross-chain bridges in the Cross-chain Lab. The security unit covers the broader risk mindset.
Key takeaways
A one-page summary of Smart Contracts — Spot the Bug. Print it for quick reference.
- A smart contract is code deployed to a chain that executes automatically when called; the contract address holds state and code.
- Solidity (Ethereum and EVM chains) is the dominant smart-contract language: state variables, functions, modifiers, and events.
- The "spot the bug" snippets cover the four classic vulnerability classes: reentrancy, integer overflow (pre-0.8), access control, and front-running/MEV.
- Reentrancy — a callback re-enters the contract before state updates settle — is the most famous class (the DAO hack, 2016).
- Audits, formal verification, and battle-tested libraries (OpenZeppelin) reduce but never eliminate risk; immutability means bugs are forever.
- Smart contracts are the substrate for DeFi, DAOs, NFTs, and most of what makes crypto programmable — and most of what makes it dangerous.
Unit check
80% to complete this unitPass the unit check (4 of 5) to complete this unit.