Smart contract exploits are more ethical than hacking... or not?

Smart contract exploits are more ethical than hacking... or not?

There has been a lot of talk about the recent “hacks” in the decentralized finance realm, particularly in the cases of Harvest FInance and Pickle Finance. That talk is more than necessary, considering hackers stole more than $100 million from DeFi projects in 2020, accounting for 50% of all hacks this year, according to a CipherTrace report.

Related: Roundup of crypto hacks, exploits and heists in 2020

Our top trading bots

Some point out that the occurrences were merely exploits that shined a light on the vulnerabilities of the respective smart contracts. The thieves didn’t really break into anything, they just happened to casually walk through the unlocked back door. By this logic, since the hackers exploited flaws without actually hacking in the traditional sense, the act of exploiting is ethically more justifiable.

But is it?

The differences between an exploit and a hack

Security vulnerabilities are the root of exploits. A security vulnerability is a weakness that an adversary could take advantage of to compromise the confidentiality, availability or integrity of a resource.

An exploit is the specially crafted code that adversaries use to take advantage of a certain vulnerability, and to compromise a resource.

Even mentioning the word “hack” in reference to blockchain might baffle an industry outsider less familiar with the technology, as security is one of the centerpieces of distributed ledger technology’s mainstream appeal. It’s true, blockchain is an inherently secure medium of exchanging information, but nothing is totally unhackable. There are certain situations in which hackers can gain unauthorized access to blockchains. These scenarios include:

  • 51% attacks: Such hacks occur when one or more hackers gain control of over half of the computing power. It’s a very difficult feat for a hacker to achieve, but it does happen. Most recently in August 2020, Ethereum Classic (ETC) faced three successful 51% attacks in the span of a month.
  • Creation errors: These occur when security glitches or errors go overlooked during the creation of the smart contract. These scenarios present loopholes in the most potent sense of the term.
  • Insufficient security: When hacks are done through gaining undue access to a blockchain with weak security practices, is it really as bad if the door was left wide open?

Are exploits more ethically justifiable than hacks?

Many would argue that doing anything without consent cannot possibly be considered ethical, even if worse acts could have been committed. That logic also raises the question of whether an exploit is 100% illegal. For example, having a U.S. company registered in the Virgin Islands can also be seen as performing a legal tax “exploit,” though it isn’t considered outwardly illegal. As such, there are certain gray areas and loopholes in the system that people can use for their own benefit, and an exploit can also be seen as a loophole in the system.

Then there are cases such as cryptojacking, which is a form of cyberattack where a hacker hijacks a target's processing power to mine cryptocurrency on the hacker's behalf. Cryptojacking can be malicious or nonmalicious.

It may be safest to say that exploits are far from ethical. They are also entirely avoidable. In the early stages of the smart contract creation process, it’s important to follow the strictest standards and best practices of blockchain development. These standards are set to prevent vulnerabilities, and ignoring them can lead to unexpected effects.

It is also vital for teams to have intensive testing on a testnet. Smart contract audits can also be an effective way to detect vulnerabilities, though there are many audit companies that issue audits for little money. The best approach would be for companies to get several audits from different companies.

The views, thoughts and opinions expressed here are the author’s alone and do not necessarily reflect or represent the views and opinions of Cointelegraph.

Pawel Stopczynski is the researcher and R&D director at Vaiot. He was previously the R&D director and a co-founder at Veriori and at UseCrypt. Since 2004, Pawel has been involved in the development of 18 IT projects in Poland and the United Kingdom, focusing on the private sector. He was a speaker at several IT conferences, and the organizer of two TEDx conferences. For his work, Pawel was awarded a gold medal at the Concours Lépine International Innovation Fair 2019 in Paris, and a gold medal of the French minister of defense.
Read on about Cointelegraph
Dogecoin signals bottoming out as DOGE rebounds 30% in two weeks — What's next?
A brutal correction witnessed in the Dogecoin (DOGE) market between May 2021 and February 2022, which saw the price dropping by almost 85%, appears to have...
Marvel NFT partner Veve closes its marketplace after an in-app token exploit
Veve, a nonfungible token (NFT) marketplace with licensed digital collectibles, faced an exploit on Tuesday, resulting in millions of gems (in-app tokens)...
Bitcoin faces new ‘milestone’ in 2022 as new forecast predicts BTC price ‘in the millions’
Bitcoin “may be primed” for a quantum leap in its development thanks to inflation this year, a Bloomberg analyst has claimed.In a tweet on March 17, Mike...
Blockchain-enabled digital fashion creates new business models for brands
Nonfungible tokens (NFT) may be disrupting the trillion-dollar fashion industry, but NFTs are just one piece of a much larger puzzle that is revolutionizing...
Catch the Bitcoin dip? BTC price pares losses with a fresh surge to $57K
Bitcoin (BTC) was back at $57,000 on Oct. 13 as a classic move left hopeful traders liquidated to the tune of $200 million.BTC/USD 1-hour candle chart (Bitstamp)....
New Australian ransomware plan allows for seizure of crypto
Australian lawmakers are taking a tougher stance against ransomware with a new plan that increases penalties for offenders.The new measures and proposed...
Powercrypto Holdings to launch BTC & ETH mining in Hong Kong
A subsidiary of the blockchain software provider Powerbridge Technologies, Powercrypto Holdings, has announced the launch of a sustainable cryptocurrency...
XRP price chart 'double bottom' puts next bullish target at $1
Ripple's XRP token could hit $1 in the coming days, according to a classic technical chart setup.Dubbed a "double bottom," the trend reversal indicator...
Large VCs are sidelining smaller crypto investors, PwC crypto lead says
As cryptocurrency continues to take over mainstream finance, formerly cautious investors across the globe are rethinking their stance of counting crypto...
US megabank JPMorgan to hire more blockchain talent
Major American investment bank JPMorgan is upping its blockchain hiring spree by posting a series of new blockchain-related job applications.JPMorgan has...
XRP Falls 13% In Rout
Investing.com - XRP was trading at $0.57073 by 12:37 (16:37 GMT) on the Investing.com Index on Tuesday, down 13.30% on the day. It was the largest one-day...
EOS Tumbles 22% In Rout
Investing.com - EOS was trading at $6.0361 by 00:46 (04:46 GMT) on the Investing.com Index on Thursday, down 22.16% on the day. It was the largest one-day...
GBTC discount presents a unique challenge for Grayscale and investors
Since 2013 the Grayscale Bitcoin Trust Fund (GBTC) has offered its investors exposure to Bitcoin (BTC) through a publicly quoted private instrument. However,...
Rari Capital falls victim to $11 million exploit
After a $11 million attack earlier today, Rari Capital is the latest decentralized finance (DeFi) protocol to fall victim to a high-priced exploit The platform,...
Fei Protocol genesis locks up $1 billion in ETH, but LPs could face losses
The launch of Ethereum-backed stablecoin called Fei has locked up almost a billion dollars’ worth of ETH during its genesis event. But the launch hasn't...