3 ms·
It was a hack, clear as day. I really don't like this mindset of "code is law" that has arisen by calling the code being executed on the blockchain "contracts".
by valuepack 9y ago
It was a hack, clear as day. I really don't like this mindset of "code is law" that has arisen by calling the code being executed on the blockchain "contracts". I think people sometimes forget that these "smart contracts" are just code, no different than the code running HN or any other web app. This is a hack in the same sense that dumping a database from web app vulnerable to SQL injection would be considered a hack. Even though the code allowed it, it clearly isn't intended behavior.
It just seems so silly -- no system is perfectly secure; any developer can attest to this. There is always going to be a way skirt around the smart contract owner's intent, especially as the apps being run on the blockchain grow in complexity. To not blatantly call this malicious activity just doesn't sit well with me.
- jacoblambda 9y agoTo be fair, the whole point of "code is law" is that there is no intent beyond the code. The developer may not intend to write bugs in their code but that does not change the fact that they wrote it that way. This is much in the same way that by not catching a bug, both the developer and the person accepting the contract are equally at fault. Now is it ethical to exploit a bug in a contract? In almost all cases the answer is no, however that is besides the point as smart contracts are devoid of any ethics or intent. The whole problem with smart contracts is the mindset behind the community. Tech circles far to often follow the mantra "move fast and break things" and this is the issue. If smart contracts were treated like real contracts, then this issue would be largely avoided. Who do you blame for writing a shitty contract? The lawyer. The same should apply for smart contracts. Smart Contracts should be written or at least reviewed by "lawyers" specializing in smart contracts. They should be trained to be able to write contracts that are bulletproof. If the smart contract is defective, they should be responsible just like with normal contract lawyers. If there is a flaw in a contract, there should be a migration strategy for addressing it. Smart Contracts are a developing technology and an extremely powerful one at that and as such they should be used with extreme caution but that does not mean they are a bad idea. The whole problem is that they are being used haphazardly and often for purposes which are far better served by a more benign and low risk solution.