Lesson 25 / 25
Revision and Interview Questions
Recall blockchain and Solidity concepts quickly for exams and interviews.
Cheat sheet
Blockchain: hash-linked blocks, nodes, consensus, proof of stake since The Merge (2022), trade-offs. Ethereum: EOAs vs contract accounts, addresses, wei/gwei/ether, nonces, the EVM, gas, EIP-1559 base fee (burned) plus tip, gas limit, L2 rollups (optimistic vs ZK), testnets (Sepolia). Keys: private key, seed phrase, signatures, ECDSA recover, EIP-712, multisigs, account abstraction. Solidity: SPDX, pragma, state variables, constructor, visibility (public, external, internal, private is not secret), msg.sender, msg.value, block.timestamp, view/pure/payable, modifiers and _;, events and indexed parameters, require, custom errors, revert, assert, try/catch. Types: uintN, address, bytes32, no floats, mappings, structs, enums, checked arithmetic since 0.8, unchecked, constant and immutable. Locations: storage, memory, calldata, transient storage. Reuse: inheritance, virtual/override, interfaces, abstract contracts, libraries, OpenZeppelin, Ownable2Step, AccessControl. Tokens: ERC-20 (approve/transferFrom, decimals, SafeERC20, permit), ERC-721 (safeTransferFrom, tokenURI), ERC-1155, Merkle allowlists. Ether: receive/fallback, call with checked result, pull payments. Calls: delegatecall, proxies (UUPS, transparent), initializers, storage layout. Security: reentrancy and CEI, ReentrancyGuard, tx.origin, MEV, oracle manipulation, replay, rounding, DoS, Slither, fuzz and invariant tests, audits, bounties. Tooling: Foundry (forge, cast, anvil, cheatcodes), Hardhat, viem, ethers, wagmi. Gas: storage dominates, packing, caching, events. DeFi: AMMs, slippage, lending, stablecoins, ERC-4626, flash loans.
Common interview questions
Answer each with a short code example or diagram.
1. What is the difference between an EOA and a contract account?
2. How are transaction fees calculated after EIP-1559?
3. storage vs memory vs calldata: when do you use each?
4. What is reentrancy and how do you prevent it?
5. Why should you not use tx.origin for authorisation?
6. Explain ERC-20 approve and transferFrom, and the risks of unlimited approvals.
7. How does a proxy upgrade work, and what is a storage collision?
8. What is the difference between call, delegatecall and staticcall?
9. Why is on-chain randomness hard, and how do you get secure randomness?
10. How would you prevent signature replay?
11. Name three gas optimisations and their trade-offs.
12. How would you test and secure a contract before mainnet deployment?Show your security thinking
In smart contract interviews, explaining how a function could be attacked and how you would test against it (fuzzing, invariants, CEI, access control) often matters more than syntax.
Quick check: Which pattern is the primary defence against reentrancy?
- Using tx.origin
- Using transfer instead of call everywhere
- Making all functions public
- Checks-effects-interactions: update state before making external calls
Answer
Checks-effects-interactions: update state before making external calls — CEI ensures re-entrant calls see updated state; ReentrancyGuard adds a safety net.