3 ms·
tbf, the bug was triggered not only because of theDao's code, but because of a combination of other conditions, including the way the virtual machine executed t
by flashmob 9y ago
tbf, the bug was triggered not only because of theDao's code, but because of a combination of other conditions, including the way the virtual machine executed the code. The meat of the exploit was executed in the attacker's contract, as explained here https://medium.com/@MyPaoG/explaining-the-dao-exploit-for-beginners-in-solidity-80ee84f0d470 https://medium.com/@MyPaoG/explaining-the-dao-exploit-for-be...
The token holders of theDao did not approve running of the attacker's contract, since they did not agree to the attacker's contract. At least that's how I interpret it.
Also, the word "contract" is not the same as a contract in law, it's more of a buzzword. They are just programs. So I don't think a program can have legal meaning by itself because it also depends of the semantics of the machine & how it interprets the programs. What happens if the code is correct, but something in the machine is broken?
The rules of the Ethereum virtual machine were altered later. I think the 'fallback function' now has a limit of 23k gas, correct me if I'm wrong, so attacks like these are more difficult, if even possible.