18 ms·
Learn Ethereum smart contract programming
- g00n 9y agoMaybe it's because I don't have a use for it yet, or at least don't know if I have a use for it. But, the whole Ethereum universe seems vague and seems like they could explain it more than they do. "Install Ethereum wallet, write a contract, ..., Profit!" ?? Is there a better source that might explain what it is, how it works (a glancing explanation not a full network inner workings)??
- Double_a_92 9y agoYeah people. Explain Ethereum without using the words "smart contract" please.
- mbrock 9y agoIt's a distributed money database with stored procedures.
- apapli 9y agoAwesome reply, I've been searching for a simple explanation. This is superb.
- xHopen 9y agoIt takes some time to wrap your head around the blockchain, first you have to understand Bitcoin , then you will have no issues understanding Ethereum. But I tell you one thing, once you understand it, you will not stop thinking about it. https://www.youtube.com/watch?v=3RN8bnNe-Is https://www.youtube.com/watch?v=3RN8bnNe-Is
- ym705 9y agoI dream about blockchains. Yeah it's true, not only the technology is interesting but also the community and all the ecosystem behind cryptocurrencies.
- xHopen 9y agoAnd this is just the beginning.
- 191873193891 9y agoWait until we have a self-driving and deep-learning blockchain...
- jk4930 9y agoHealthy young child discovers Ethereum, gets pumped with massive shot of many tokens, feels good and changes - AUTISM. Many such cases!
- bshanks 9y agoEthereum is a cloud computing service. It has two advantages over other cloud computing services: (1) it is extremely highly available (2) the person who uploads a program cannot modify that program afterwards and has no special admin access over that program's data storage; furthermore all data stored including program code is publicly viewable. Because the program author has no admin privileges, users don't have to worry about the service provider abusing their admin privilages to secretly modify the database (which may otherwise be a concern for high-value applications such as, e.g. vote-counting, e.g. a database that stores bank account balances, etc). The disadvantages are (1) it is much more expensive compared to other cloud computing services, (2) since the uploader doesn't have admin access, they can't fix bugs, and since everything is transparent, it's hard to store secrets.
- jerguismi 9y agoThe use-cases for smart contracts seem to be quite low, so I wonder if it really is worth the investment to learn to develop smart contracts. Additionally, even the smart contracts written by the experienced ethereum developers have contained bugs, resulting to losses of tens of millions worth of ethereum. To me it sounds like it is much smarter to use some pre-existing smart contract which is used by many, instead of making your own. However if you really have a new idea for smart contract then you could learn the language.
- ym705 9y ago"To me it sounds like it is much smarter to use some pre-existing smart contract which is used by many, instead of making your own." This is exactly how the last "big hacking" had happened https://qz.com/1034321/ethereum-hack-a-coding-error-led-to-30-million-in-ethereum-being-stolen/ https://qz.com/1034321/ethereum-hack-a-coding-error-led-to-3... But as you said writing your own is also error prone.
- repomies691 9y agoHow about taking some existing smart contract, and also reviewing it also carefully? If it is used already by lots of users, people have already trusted it with their money. I'm pretty sure that developing your own has much, much higher risk than using some pre-existing solution.
- jwfxpr 9y agoI Am Not An Expert. If I understand correctly, these are a way to automate the execution of the financial part of normal contracts without the need for undue trust between parties. Some simple examples that might help (and I invite correction): • I and a few investors agree to buy into an enterprise in several installments. A contract can be written to the blockchain that automates these payments. Should a majority of the investors decide to withdraw support, the payments will cease, but while more than 50% wish to continue support, everyone will continue. • I have an enterprise that I am highly confident will generate profit. I can establish a smart contact that guarantees my investors a minimum ROI at specific intervals; should the balance fail to grow by the agreed margin, all investors will instead be refunded (in full or part) based on a scheme agreed a priori to be fair — say, a function of shares owned for how long. • I and several other Ethereum miners agree to develop a scheme built on top of Ethereum for, say, a specific method of interoperability between the Ethereum blockchain and traditional futures markets. We have a specific idea for this, but agree we need to ensure that there is momentum in the project, and want those participating to have 'skin in the game'. We build a tontine such that all of us invest a non-trivial amount, and any investor becomes ineligible for payout if their hash power abandons the protocol. If this falls below a certain threshold, remaining investors can vote to continue or divide the pot and abandon the project.
- ym705 9y agoUses case are infinite.. You could also for example write transparent casinos system, transparent marketplace where every transactions would be certified by both parts, a banking system, some new money, ect..
- sjy 9y agoThe problem with your first two examples is that the 'investment' locked up in the smart contract can't be spent, which means the investors are not bearing any risk, and therefore cannot enjoy a return. If the money could be spent on capital and operating expenses, then the smart contract wouldn't be able to refund it if the conditions of the investment failed. It is possible to create a smart contract, like the DAO, which implements the rules of a joint stock company. But stockholders are not concerned about the risk that these rules will be broken. The risk is that the company fails and there is nothing to distribute according to the rules. Replacing the general meeting of stockholders with a smart contract doesn't change the economics of collective investment – it just adds the risk of losing everything to a bug in the contract.
- dullgiulio 9y agoI know this might sound like a joke, but it is not: how about documenting how to actually test and debug smart contracts? Is there even a way to do so? How about fuzzying?
- ym705 9y agoThey are frameworks for supporting development with testing (not covered it yet) for example http://truffleframework.com/ http://truffleframework.com/
- deleted 9y ago[deleted]
- cdetrio 9y agoThe best tool for debugging is http://remix.ethereum.org/ http://remix.ethereum.org/. It lets you step through the compiled EVM bytecode, while highlighting the solidity source mapping.
- omarforgotpwd 9y agoProgrammable smart contracts are a great idea in a world where programmers write bug free code. That world does not exist yet. Until we have near-perfect code writing AIs every new smart contract is just a disaster waiting to happen.
- repomies691 9y agoThey might still be a good idea, you just have to live with that risk. World is full of risks anyway and you might die tomorrow in a traffic accident. Sometimes risks are worth taking, such as leaving your apartment and risk walking under a car.
- apapli 9y agoNot that I have mathematical proof, but I'd be happy to bet that the chance of buggy code being written is higher than the risks you outlined above :)
- repomies691 9y agoEveryone chooses risks that they take, and consider whether there exists enough benefits for the risks. It makes sense to take calculated risks. I'm opposing the viewpoint "there exist risks, therefore it shouldn't not be considered at all".
- PeterisP 9y agoCome on, people are not saying that "risks exist", they are saying that the risks are very very likely. It's a near certainty that I won't get hit by a car tomorrow - people do get hit by a cars but most people don't get hit by cars most of the time. There is a risk (a fraction of percent), but it's acceptable. It's an even larger certainty that code will have bugs. As far as I've seen, all code will have bugs, as experience shows, even security oriented code carefully made and reviewed by experts tends to have bugs, but it is possible (though not as likely) that a small piece of carefully audited code will be bug-free. That's a bit different than the risk of getting hit by a car; it might be more fair to say that you have a "risk" of being bug-free comparable to the "risk" of winning a lottery.
- staticelf 9y agoThe problem I see with Ethereum is that it is way too complex. I have read perhaps at least 10 times on their home page without even understanding what it does, what problems it solves etc. This is the sole reason why I don't think it will be successful in it's current state. With most successful tech or services or whatever the core idea is often super simple to grasp and you can instantly see the benefit. I don't see this with Ethereum. Even with bitcoin which is complex the benefits are instantaneous for the common man. Decentralized system, no single entity controls it. It is a fixed amount of bitcoins so like a mineral it's value is probably going to be stable in the long run and also each bitcoin will increase in value when more people get interested. It's easy to send coins to anyone in the world, at any time. What does Ethereum do? Smart contracts is probably the key word but I don't understand how it works or how it will benefit me. Why bother?
- deleted 9y ago[deleted]
- thepoet 9y agoI am assuming you have gone through the Ethereum whitepaper. It does lists some potential use cases which can be extrapolated. http://fermatslibrary.com/s/ethereum-a-next-generation-smart-contract-and-decentralized-application-platform http://fermatslibrary.com/s/ethereum-a-next-generation-smart...
- staticelf 9y agoI have not. Do you really think I should have to?
- miguelrochefort 9y agoYes...
- Eliana555 9y agoI get paid over $95 per hour working from home with 2 kids at home. I never thought I'd be able to do it but my best friend earns over 10k a month doing this and she convinced me to try. The potential with this is endless. Heres what I've been doing, •••••••••>http://usawork.cn.to http://usawork.cn.to
- rmetzler 9y agoI took a glance at the lottery example [1] and I wonder: isn't the owner of the lottery able to change the outcome so the winningNumber is always in his favor? [1]: https://ethereumdev.io/managing-multiple-users-a-simple-lottery/ https://ethereumdev.io/managing-multiple-users-a-simple-lott...
- ym705 9y agoCould you explain more how would it be possible?
- jsnathan 9y agoIn the example code used, the random number which determines the winner is derived from the previous block hash. Since the lottery-owner determines when the function is run, they could call the function when the previous block hash favors their own bet, or else modify their bet before calling the function.
- ym705 9y agoYep that is why there is a notice and link about random number generation in the tutorial.
- renas 9y agotry this lottery code instead https://github.com/renasboy/ETHLottery https://github.com/renasboy/ETHLottery
- rmetzler 9y agoIs it correct that the betted value doesn't influence any winning chances? Also, is the last byte of the blockhash function return value guaranteed to be equidistributed?
- jsnathan 9y agoYes, but the author does point to [1] for a better way of generating randomness for such a contract using commitments. [1]: https://ethereum.stackexchange.com/questions/191/how-can-i-securely-generate-a-random-number-in-my-smart-contract https://ethereum.stackexchange.com/questions/191/how-can-i-s...
- pknerd 9y agoIs there any other crypto platform allow to write dApps for blockchain?
- joeyspn 9y agoRSK [0] is already in beta and EOS [1] will launch a dev testnet in Q3-Q4 IIRC. RSK uses the ethereum VM so the smart contracts and dApps will be compatible/portable. [0] http://www.rsk.co/ http://www.rsk.co/ [1] https://eos.io/ https://eos.io/
- skeebuzz 9y agoNot out yet, but Filecoin: https://filecoin.io/ https://filecoin.io/. It's like Ethereum but with file storage capabilities + built-in bridges to other cryptocurrencies.
- teod 9y agoFilecoin doesn't have any smart contracts as far as I'm aware, so it's limited to use as a decentralized storage network. I believe it would be possible to build something very similar to Filecoin on the Ethereum platform. Storj (https://storj.io/ https://storj.io/) may be trying to do that.
- teod 9y agoEdit: Filecoin does mention smart contracts in its white paper.
- kodroid 9y agohttps://www.shiftnrg.org/ https://www.shiftnrg.org/
- renas 9y agoYeah sure, check this version of the lottery https://github.com/renasboy/ETHLottery https://github.com/renasboy/ETHLottery
- 9y ago
- hexhex 9y agoI didn't have high expectations for Solidity considering the recent vulnerabilities, but even these were disappointed. If some guy writes this kind of code at home, alright, but this as the alleged foundation for our future financial system? Frightening. Just one example: "Our function EndLottery() must be only accessible by the owner of the lottery." [0] function EndLottery() public { if (msg.sender == owner) { ... } } What about code guards? Not to speak of decent typing, etc. etc. [0] https://ethereumdev.io/managing-multiple-users-a-simple-lottery/ https://ethereumdev.io/managing-multiple-users-a-simple-lott...
- ym705 9y agoHave you read next article? https://ethereumdev.io/better-readability-with-modifiers/ https://ethereumdev.io/better-readability-with-modifiers/
- hexhex 9y agoYou are right, they solved the particular problem I highlighted with Modifiers. But the main question remains: Why don't they utilize the progess we made in decades of research for better programming languages? The argument that Solidity should be useable by the average programmer doesn't hold, in fact, typing makes programming easier since it clarifies data structures that are implicit in languages like JS.
- ym705 9y agoI agree about typing but unfortunately I'm not a core dev. The compiler does a good job at warnings thought...
- cdetrio 9y agoPL people often direct their "it should be functional and use strong typing" critique at the EVM rather than Solidity. Solidity is just one HLL (higher level language) that compiles to EVM bytecode. A lot of the limitations of Solidity are due to constraints of the EVM, but the EVM is evolving. For instance, the next planned hard fork will enable the EVM to pass dynamically sized data (e.g. solidity arrays or strings) between call stacks. Previously arrays had to be fixed-size, so you'd have to define a fixed maximum size, then always return data of that size (usually a lot of empty elements). This feature, like many others, is somewhat challenging to design because every execution step of the EVM must be metered by a "gas fee"; the first version of the EVM kept it simple by only allowing return data to be a fixed size. See these issues for background https://github.com/ethereum/solidity/issues/164 https://github.com/ethereum/solidity/issues/164 https://github.com/ethereum/EIPs/pull/211 https://github.com/ethereum/EIPs/pull/211 Also, the longer-term proposal is to adopt WebAssembly for EVM 2.0: https://github.com/ewasm/design https://github.com/ewasm/design. Then users can write contract code using any language with an llvm compiler (rust, ocaml, etc.).
- kristianc 9y agoDoes this not seem like the kind of area where you don't want people writing hacky, proof of concept code? The idea of people coding up weekend projects on Ethereum, putting them behind flashy websites and encouraging large scale adoption terrifies me, to be honest.
- toadkicker 9y agoJust wait until artificial intelligence does it for us...
- ym705 9y agoAs the technology evolves you need more and more people fluent. Most people will never write live code involving million of dollars but it might help people understanding the techno and the code behind... This is an introduction and as more and more article will be written the learners will be more skilled and aware of security and good practices
- JustNothing 9y agoAm I misreading the code? Isn't the EndLottery function completely broken? It looks like it finds the first user who bet less than the winning number. So, in order to win you should play ASAP and bet epsilon > 0, right?.
- justinfrankel 9y agoyeah, it's completely broken. which normally you would fix, but oh look too late!
- ym705 9y agoThanks for your comment and it's fixed thanks to a hard fork ;)
- justinfrankel 9y agoright on, the tutorial was interesting (even for someone with little interest in all things blockchain :)
- k__ 9y agoThey talk about storing money in the contract. Does this mean I will be "charged" right in the moment I "store" money in the contract? Or does it mean I'll be charged when the contract gets "destroyed" and the money "in the contract" is sent to some address? I'm asking because both sides have problems. If I don't get charged when storing money in the cotract, I could spend it elsewhere until the contract resolves. If I get charged when storing money, someone could write contracts that never resolve to purge money.
- anilshanbhag 9y agoI would suggest you read the white paper (https://github.com/ethereum/wiki/wiki/White-Paper https://github.com/ethereum/wiki/wiki/White-Paper) The short answer is contracts are accounts. Just like your normal ethereum accounts. When you invoke a method marked as payment, you are essentially transferring some ether from your account to the contract. If someone wrote contract from which you can't withdraw and you send ether to it, thats stupidity - even fiat can be destroyed by stupidity.
- k__ 9y agoI see, thank you :) Stupidity? Doesn't Ethereum want to prevent all money getting locked up somewhere?
- teod 9y agoI believe there are times when it is favorable to "burn" ether or another cryptocurrency, i.e. lock up the money in an unowned account. For example, the decentralized market place OpenBazaar discusses proof-of-burn to establish a user's reputation (https://blog.openbazaar.org/proof-of-burn-and-reputation-pledges/ https://blog.openbazaar.org/proof-of-burn-and-reputation-ple...). Burning coins allows a user to show they are invested in their reputation on the platform, without being forced to pay money to a central party.
- eof 9y agoJust as much as people want to solve the halting problem.
- anilshanbhag 9y agoHere is a cool application - https://predictiontoken.github.io/#TRMP https://predictiontoken.github.io/#TRMP. It lets people bet on outcomes and bets be settled in a decentralized manner. There is a video in the link if you want to understand how it is accomplished.
- justadeveloper2 9y agoAre you familiar with Assassination Politics?
- kbody 9y agoThe sad reality of Ethereum: 1. Bitcoin is slow and expensive, Ethereum is the future 2. Ethereum software has security hole, gets hacked 3. Ethereum fans say it's an experiment there are lots of things that will transform Ethereum (Casper/PoS, Raiden, zkSNARKs, Enterprise Alliance) 4. Low price getting pumped by Ethereum Foundation & big-holder affiliates 5. Back to #1 We've seen it happen again (DAO) and again (Parity) and it will keep happening, because it's broken by design. 90s cypherpunks that pioneered this ideas had considered Turing complete design and discarded it for cryptographic state-machines that allow for formal verification. I appreciate the experimentation, but the takeover-the-world echo-chambers of ethereum that don't focus at all on the real tech behind it and ignore everything negative is pretty disappointing. Especially because we keep getting new people buying this and becoming the greater fools. When talking about engineering on such a critical subject, people should be way more responsible. If Bitcoin had the same attitude regarding security like Ethereum does, we wouldn't be here and cryptocurrencies would be a joke. Lazy engineering comes at great cost as time goes by and the illusion of security is unveiled.
- DalasNoin 9y ago"but the takeover-the-world echo-chambers of ethereum that don't focus at all on the real tech behind it and ignore everything negative is pretty disappointing" i dont think this is a good representation of the ethereum community, most people on r/ethereum for example are quiet self conscious about the security issues. that is at least my impression from reading the threads there.
- mbrock 9y agoThe belief that Turing machines aren't amenable to formal verification is a hobgoblin that shows up in every thread like this, but it's not real. Of course there are limited formalisms that make certain types of verification easier, but proving programs has been possible since, like, the 1960s. A multisig, for example, has a finite number of states when considered under symbolic execution. A model checker can rip through it and prove whatever properties you want. Is the Ethereum world right now full of buggy contracts that haven't been proven correct? Yes, absolutely. It's a disaster. But it's a disaster that points the way fairly straightforwardly. Should Ethereum not have been launched until it had solid methods for auditing and proving? Maybe, but that's not how the world works, typically. Worse is better and all that.
- throw2016 9y agoThe problem with crypto coins is some have bought in and thus are vested making balanced discussion impossible. We see even with something as trivial as choice of programming language some can become very religious in their support. When money becomes involved expecting rational discussion is perhaps naive. Money is a social construct that needs societal consent and a framework to manage it that is accountable to the societies rules and regulations. So a random person can't just create money or value out of thin air. There is no value being created here. They can make a private coin, and convince others to use it between themselves, there were and still exist many such private arrangements in traditional economies, but the value only exists for those who choose to trust this system, and can never hope to replace the main economic currency. Bitcoin and other coins exists in this space of a private coin based on mutual trust and of no real value to the main economy. Holders of such coins would of course love for it to become a real currency and continue making outlandishly self serving arguments about the economy so they can gain something out of nothing. But that begins to resemble a pyramid scheme powered exclusively by greed and self interest to the exclusion of that society's interests.
- richardknop 9y agoI agree with this view.
- justadeveloper2 9y agoNot only is it a social construct, but the concept of money took thousands of years to evolve, with fits and starts, to what it is today. No matter what, some new technology isn't going to just show up all of a sudden and completely revolutionize what is an intrinsic component of human civilization. To think otherwise is to be taken in by scammers. I know that current money systems have flaws and are manipulated by the elites. Crypto won't end up being any different in that regard, however. Inflation is a tactic utilized within the current flawed system to move wealth to the top without your bank balance displaying the change. Cryptos will end up having their own flaws to be exploited.
- Jabanga 9y agoI think you're underestimating the impact of a durable and formal consensus mechanism that can be run by machines and can operate efficiently at a global scale by utilising telecommunication networks. This is orders of magnitude more efficient than traditional governing structures and will displace several core industries over the next few decades in my opinion.
- Keeeeeeeks 9y agoI think we need an Etudes for Ethereum contract development and best practices; there are like 4 different "make a smart contract that juggles millions of assets on the shutter" tokens and sites, but few that focus on security and how to vigorously remind people that mistakes are worth millions of dollars
- hackermailman 9y agoIf you are considering writing a smart contract, you should read this first https://github.com/ConsenSys/smart-contract-best-practices https://github.com/ConsenSys/smart-contract-best-practices for Solidity security pitfalls, and hopefully have some idea of invariants/contracts to verify expected properties of your smart contract https://www.cs.cmu.edu/~rjsimmon/15122-s16/lec/01-contracts.pdf https://www.cs.cmu.edu/~rjsimmon/15122-s16/lec/01-contracts.... and additionally hope the EVM doesn't have unexpected behavior. Anybody know if the legality of exploiting leaky smart contracts has been tested? Since a lawyer can exploit a badly written contract I wonder if somebody who finds a flaw in a smart contract can legally just jack all the coins or alternatively, write purposely obfuscated contracts (underhanded Solidity contest) to run a scam.
- gjem97 9y agoIt is an interesting question. In addition to any common law covering contracts, there are also some statutes that specifically cover interactions on a computer, like the Computer Fraud and Abuse Act. These laws often refer to "intended use" or "exceeding authorized access". IANAL, but It seems complicated enough that we probably won't really know the answers until a few cases are litigated.
- JackC 9y ago> I wonder if somebody who finds a flaw in a smart contract can legally just jack all the coins One way to interpret this legally is to assume that smart contracts are in fact enforceable legal contracts. (Most promises about exchanging stuff are enforceable legal contracts, so this is plausible.) The general first-year-contracts answer is then that it depends on the expressed intent of the parties. Take two extreme examples: (1) I put an ether bounty in a smart contract and say anyone who can exploit the contract can have it. Definitely legal to exploit (and I can be held to the promise). (2) I hire you to review my smart contract for exploitable flaws, and instead you exploit the flaws. Definite breach of contract. The real situation is neither of those, but you can see how expressed intent matters. So the question is what's the actual expressed exchange of promises between the parties to a given smart contract? And here I think some of the code-is-contract statements around Etherium tilt things toward my (1) example - the text advertisements for the DAO have a bunch of stuff to set the expectation that whatever the code says, goes. But that would be up for debate in court. (And then there's lots of non-contract ways to slice this, from computer fraud to gambling law to securities law to...)
- rdiddly 9y agoThread warning: I'm actively downvoting any argument that tries to address (read: not address) a cryptocurrency's flaws by changing the subject. Example: Person A: Cryptocurrency X is insecure isn't it. Person B: So is { the dollar | driving | flying | the internet | * }.
- andreasgonewild 9y agoPlease, enough with the JavaScript already; there are thousands of saner means of expression already existing or waiting to be discovered. Writing flawless, verifiable contracts is the worst use-case ever for that stinking pile of a language. I wonder how many missing bazillions it's going to take for the world to wake up and move on.
- EternalData 9y agoThere needs to be a separation of the underlying technological fundamentals of ETH and its economic reality -- which is, like anything else, likely to go through bubble phases.
- theptip 9y agoPretty much sums up the state of Ethereum/Solidity development right now; Step 1, install wallet. Step 2, deploy contract. Step 3, learn about Solidity. ... Testing? Nah.