4 ms·
Excuse my extremely informal and probably dumb thought process behind this, but can't de-fi be rug-pulled as follows 1) Create code with subtle but privately k
by notch656a 4y ago
Excuse my extremely informal and probably dumb thought process behind this, but can't de-fi be rug-pulled as follows
1) Create code with subtle but privately known "bug" that allows profitable behavior far outside the bounds of what you advertise to the public as your code doing.
2) Wait for liquidity pools within the contract to build up.
3) Exploit the "bug"
Yes according to "Code-is-law" you're not doing anything "unlaw(code)ful." But it's a rug pull in everything but name. De-fi is basically never introduced as "there's contract 0x343cdc.... on the blockchain, go read the EVM code as nothing will be explained" so intent in the way something is introduced is instrumental here.
- pa7x1 4y agoNothing dumb about what you said, that's a valid argument. A bug, either unintended or intended as a hidden "feature" for the scammer. Is one possible way to execute a rug-pull on DeFi or, in general, result in losses for its users. But IMHO this is still a better approach. Serious contracts go through multiple audits, deploye hefty bug bounties and if you are very risk averse you can avoid a new deployed contract for certain amount of time until it's not only audited but battle-tested. As a user perhaps you don't know and shouldn't care about the specificities of the contract or its security but you can rely on the thousands of other eyeballs that do. For instance, a few audits of Uniswap: - https://github.com/ConsenSys/Uniswap-audit-report-2018-12/blob/master/Uniswap-final.md https://github.com/ConsenSys/Uniswap-audit-report-2018-12/bl... - https://rskswap.com/audit.html https://rskswap.com/audit.html Bug bounty program of Uniswap (up to 0.5M USD per critical bug): https://uniswap.org/bug-bounty https://uniswap.org/bug-bounty