Smart-contract bugs are often irreversible and immediately monetizable, so this interview is really a security interview with blockchain vocabulary. These questions probe whether a candidate has internalized the adversarial mindset the domain demands, with notes on what strong answers cover.
What a strong answer covers
An external call that re-enters the contract before state is updated, draining funds through repeated withdrawals. Prevention: checks-effects-interactions ordering, reentrancy guards, and pull-payment patterns. A strong candidate can narrate a real historical exploit and mentions read-only reentrancy as a newer variant.
What a strong answer covers
Layered answer: extensive tests including fuzzing and invariant testing, static analysis, internal review, an external audit with time to fix findings, staged deployment with caps or timelocks, and a monitoring plan. Anyone who treats the audit as the whole process is junior.
What a strong answer covers
State reverts but the gas is consumed. Practices: avoiding unbounded loops over user-growable arrays, pull over push for distributions, storage-write economy, and awareness that block gas limits bound worst-case operations. Mentioning gas griefing in callbacks is a plus.
What a strong answer covers
Delegatecall-based proxies keeping state in the proxy while logic lives elsewhere; storage-layout compatibility across upgrades, initializer functions replacing constructors, and the governance question of who can upgrade. Storage-collision and uninitialized-implementation bugs are the sharp edges a real practitioner names.
What a strong answer covers
Spot prices are manipulable within a single transaction, especially with flash loans, enabling oracle-manipulation attacks. Alternatives: TWAPs, Chainlink-style decentralized oracles, and sanity bounds. This is a core DeFi-safety litmus test.
What a strong answer covers
EIP-712 typed signing, permit-style gasless approvals, and relayed transactions. Risks: replay across chains or contracts without domain separators, missing nonces, and signature malleability. Precise nonce-and-domain reasoning separates practitioners from tutorial followers.
What a strong answer covers
Value extractable by ordering, inserting, or censoring transactions β sandwiching swaps being the classic case. Design responses: slippage bounds, batch auctions, commit-reveal schemes, or private transaction routing. Awareness that users bear MEV costs is the point.
What a strong answer covers
Both inherit L1 security while executing off-chain; optimistic systems rely on fraud proofs with challenge periods affecting withdrawals, ZK systems on validity proofs with faster finality but historically harder proving. EVM-equivalence trade-offs and where each fits deployment plans show real familiarity.
What a strong answer covers
Fork testing against mainnet state, fuzzing and invariant testing with tools like Foundry, integration tests of multi-contract flows, and testnet or shadow deployments. Naming invariants they have actually written β total supply conservation, solvency checks β is the strong signal.
What a strong answer covers
Pause if a pause mechanism exists, quantify and scope the leak, coordinate privately rather than tweeting, consider white-hat counter-measures, and prepare user communication. Whether they designed pausability and an incident plan beforehand is the deeper test.
What a strong answer covers
When a trusted party already exists, when data is private or mutable by requirement, or when a database plus signatures solves it cheaper. Willingness to answer this honestly is a strong integrity signal in a hype-prone field.
What a strong answer covers
Hardware wallets or HSMs for deployer keys, multisig ownership of privileged functions, timelocks on sensitive operations, no keys in CI or env files, and separation between deployer and admin roles. Casualness here is disqualifying for funds-holding systems.
Skip the interviews entirely β get matched with pre-vetted Blockchain developers in 48 hours, $0 until you hire.
Need a custom question set?
Our free interview question generator builds a tailored list for any role, seniority, and focus area.
Try the interview question generator βIf the work is reading chain data, wallets, or calling existing contracts, a strong backend developer can learn it. Writing contracts that custody meaningful value is where you insist on specialist experience with audited, shipped code.
Ask for deployed contract addresses and read the code on a block explorer, ask which audit findings were filed against their code and how they fixed them, and look for public security write-ups or audit-contest results. On-chain history is unusually verifiable β use that.
The security core stays identical. For DeFi, weight the oracle, MEV, and economic-attack questions heavily; for infrastructure, push deeper on rollups and node operations; for NFT and consumer work, add questions on metadata, royalties, and gas-efficient minting.
Hire directly
Hire vetted Blockchain developers in the USA βOther interview guides
Vetted talent ready for US teams. No recruitment fees. Zero risk.
πΊπΈ Trusted by companies across the United States