계약 보안 모범 사례
재진입 방지 장치, 검사-효과-상호작용 패턴 및 접근 제어를 포함한 스마트 계약 개발의 필수 보안 관행을 알아봅니다.
계약 보안 모범 사례은(는) CoddyKit의 무료 Web3 & DApp Development Fundamentals 강의입니다. 이것은 3개 중 2번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Web3 & DApp Development Fundamentals 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Web3 & DApp Development Fundamentals 강의에는 총 3개의 강의가 포함되어 있습니다.
이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.
Smart Contract Security Intro
Welcome to the critical world of smart contract security! Unlike traditional software, bugs in smart contracts can lead to irreversible loss of funds.
Because smart contracts are immutable once deployed, fixing vulnerabilities is extremely difficult, often requiring complex upgrade mechanisms or even redeploying a new contract.
In this lesson, we'll explore essential practices to build more secure and robust smart contracts.
Understanding Reentrancy
One of the most infamous vulnerabilities is reentrancy. It occurs when an external call to another contract or address "re-enters" the calling contract before the initial function's state updates are complete.
Imagine a bank ATM that lets you withdraw money. If it debits your account *after* giving you cash, a reentrancy attack would be like repeatedly asking for cash before the system updates your balance, draining the ATM.
Vulnerable Withdrawal Code
Consider this simplified contract where a user can deposit and withdraw Ether. Can you spot the danger?
The withdraw() function first sends Ether, then updates the balance. An attacker can call withdraw() again from their malicious contract during the external call, before their balance is set to zero.
/// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
contract VulnerableBank {
mapping(address => uint) public balances;
function deposit() public payable {
balances[msg.sender] += msg.value;
}
function withdraw(uint _amount) public {
require(balances[msg.sender] >= _amount, "Insufficient balance");
// Vulnerable point: send Ether BEFORE updating balance
(bool success, ) = msg.sender.call{value: _amount}("");
require(success, "Failed to send Ether");
balances[msg.sender] -= _amount; // This happens AFTER the external call
}
function getBalance() public view returns (uint) {
return address(this).balance;
}
}Preventing Reentrancy: State Locks
A common and effective way to prevent reentrancy is using a reentrancy guard. This involves locking the state of the contract during an external call and unlocking it afterward.
If a re-entrant call tries to execute the locked function, it will revert. OpenZeppelin's ReentrancyGuard is a popular implementation, but you can also build a simple one.
Implementing Reentrancy Guard
Let's add a simple reentrancy guard using a boolean flag. This ensures that the withdraw function cannot be called again until the current execution is complete and the state has been updated.
The nonReentrant modifier sets a lock, performs the operation, and then releases the lock.
/// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
contract SecureBank {
mapping(address => uint) public balances;
bool private _locked; // Reentrancy guard flag
modifier nonReentrant() {
require(!_locked, "Reentrant call detected");
_locked = true;
_;
_locked = false;
}
function deposit() public payable {
balances[msg.sender] += msg.value;
}
function withdraw(uint _amount) public nonReentrant {
require(balances[msg.sender] >= _amount, "Insufficient balance");
balances[msg.sender] -= _amount; // Update balance BEFORE external call (CEI)
(bool success, ) = msg.sender.call{value: _amount}("");
require(success, "Failed to send Ether");
}
function getBalance() public view returns (uint) {
return address(this).balance;
}
}The CEI Pattern
The Checks-Effects-Interactions (CEI) pattern is a fundamental security best practice. It dictates a specific order for operations within a function:
- Checks: Validate conditions (e.g.,
requirestatements,onlyOwner). - Effects: Update the contract's state (e.g.,
balances[msg.sender] -= amount). - Interactions: Perform external calls to other contracts or addresses.
Following CEI helps prevent various attacks, including reentrancy, by ensuring your contract's state is finalized *before* external calls.
CEI in Withdrawal Function
Notice how our SecureBank's withdraw function already follows the CEI pattern:
- Checks:
require(balances[msg.sender] >= _amount, ...)andrequire(!_locked, ...)from the modifier. - Effects:
balances[msg.sender] -= _amount;updates the state. - Interactions:
msg.sender.call{value: _amount}("");performs the external transfer.
This order is crucial for preventing reentrancy and ensuring consistent state.
/// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
contract CEIDemo {
mapping(address => uint) public balances;
bool private _locked;
modifier nonReentrant() {
require(!_locked, "Reentrant call detected");
_locked = true;
_;
_locked = false;
}
function deposit() public payable {
balances[msg.sender] += msg.value;
}
function withdraw(uint _amount) public nonReentrant {
// --- CHECKS ---
require(balances[msg.sender] >= _amount, "Insufficient balance");
// --- EFFECTS ---
balances[msg.sender] -= _amount; // State updated BEFORE external call
// --- INTERACTIONS ---
(bool success, ) = msg.sender.call{value: _amount}("");
require(success, "Failed to send Ether");
}
}Restricting Access
Not all functions in a smart contract should be callable by everyone. Access control ensures that only authorized addresses or roles can execute specific sensitive operations.
Common examples include:
- An
onlyOwnermodifier for administrative functions. - Role-based access control (RBAC) where different roles (e.g.,
MINTER,PAUSER) have specific permissions.
Proper access control is vital to prevent unauthorized actions and maintain contract integrity.
Owner-Restricted Function
Here's how to implement a simple onlyOwner access control using a modifier. The contract stores the deployer's address as the owner, and only this address can call the setNewAdmin function.
This pattern is widely used for critical administrative functions.
/// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
contract AccessControlled {
address public owner;
address public admin;
constructor() {
owner = msg.sender; // Deployer is the owner
admin = msg.sender;
}
modifier onlyOwner() {
require(msg.sender == owner, "Only owner can call this function");
_;
}
function setNewAdmin(address _newAdmin) public onlyOwner {
admin = _newAdmin;
}
function getAdmin() public view returns (address) {
return admin;
}
}Security Best Practices Check
You've learned about reentrancy, the CEI pattern, and access control. Which of the following statements are true regarding secure smart contract development?
Recap: Secure Contracts
Great job! You've grasped fundamental smart contract security practices:
- Reentrancy: A critical vulnerability where external calls can "re-enter" a function before state updates.
- Reentrancy Guards: Mechanisms (like mutexes or modifiers) to lock contract state during external calls.
- CEI Pattern: The recommended order of operations (Checks, Effects, Interactions) to ensure state is updated before external calls.
- Access Control: Restricting sensitive functions to authorized addresses, often using
onlyOwnermodifiers.
These practices are crucial for building robust and trustworthy decentralized applications. Keep practicing and stay vigilant!
자주 묻는 질문
“계약 보안 모범 사례” 강의는 무료인가요?
네 — “계약 보안 모범 사례” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Web3 & DApp Development Fundamentals 강의 전체를 잠금 해제할 수 있습니다. Web3 & DApp Development Fundamentals 강의에는 총 3개의 강의가 포함되어 있습니다.
“계약 보안 모범 사례”에서 뭘 배우나요?
재진입 방지 장치, 검사-효과-상호작용 패턴 및 접근 제어를 포함한 스마트 계약 개발의 필수 보안 관행을 알아봅니다. 브라우저에서 직접 실행하는 실습 코드로 Web3 & DApp Development Fundamentals을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.
Web3 & DApp Development Fundamentals을(를) 시작하는 데 경험이 필요한가요?
사전 경험은 필요하지 않습니다. CoddyKit의 Web3 & DApp Development Fundamentals은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 3개 중 2번째 강의입니다.
“계약 보안 모범 사례” 강의는 얼마나 걸리나요?
대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.
이 Web3 & DApp Development Fundamentals 강의에서 코드를 작성하고 실행할 수 있나요?
네. 모든 Web3 & DApp Development Fundamentals 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.
이 강의의 모든 강의
- ERC 표준(ERC-20, ERC-721)
- 계약 보안 모범 사례
- 업그레이드 가능한 계약