5 ms·
The problem is that it is totally possible for there to be a hidden bug in an old smart contract that everyone trusts. And only a single bug like that can destr
by GhostVII 5y ago
The problem is that it is totally possible for there to be a hidden bug in an old smart contract that everyone trusts. And only a single bug like that can destroy the entire ecosystem. It's not enough for trusted smart contracts to be less buggy, they have to be so secure that they don't have any bugs ever
- legutierr 5y agoYes, the process I described above would not be sufficient to ensure that smart contracts are perfectly safe, with zero exceptions ever. It is also important that scrutiny be applied to these protocols, and I imagine that at some point DeFi protocols may be be subject to regulator audit and approval before they are opened up and made available for use by retail customers. If the right people pay enough attention to the implementation of these protocols, then it should be possible to trust them. Also, if you yourself are risking significant funds, it wouldn't be a bad idea to personally review and understand the smart contract code. That being said, over extended periods of time (decades), long-lived smart contracts will tend to be safer, and insecure smart contracts will tend to be identified as such. If enough value is at risk, and if enough time has passed, then it is extremely unlikely that an exploitable bug will exist that has not already been exploited. Keep in mind that as a general rule smart contract implementations are immutable, so any bug that exists within a protocol is typically a bug introduced to the protocol when it is first deployed. There are never any "new" bugs that are introduced to an existing smart contract; if a bug emerges after a long period of time has passed, it is a bug that existed at the beginning but had not been previously identified. At a certain point the passage of time will have reduced this risk below a tolerable threshold that is more than outweighed by the value that people get from using the software. So in practical terms, in the aggregate, such long-lived systems could reasonably be treated as secure.