Smart contract exploits are more ethical than hacking... or not?

Smart contract exploits are more ethical than hacking... or not?

There has been a lot of talk about the recent “hacks” in the decentralized finance realm, particularly in the cases of Harvest FInance and Pickle Finance. That talk is more than necessary, considering hackers stole more than $100 million from DeFi projects in 2020, accounting for 50% of all hacks this year, according to a CipherTrace report.

Related: Roundup of crypto hacks, exploits and heists in 2020

Our top trading bots

Some point out that the occurrences were merely exploits that shined a light on the vulnerabilities of the respective smart contracts. The thieves didn’t really break into anything, they just happened to casually walk through the unlocked back door. By this logic, since the hackers exploited flaws without actually hacking in the traditional sense, the act of exploiting is ethically more justifiable.

But is it?

The differences between an exploit and a hack

Security vulnerabilities are the root of exploits. A security vulnerability is a weakness that an adversary could take advantage of to compromise the confidentiality, availability or integrity of a resource.

An exploit is the specially crafted code that adversaries use to take advantage of a certain vulnerability, and to compromise a resource.

Even mentioning the word “hack” in reference to blockchain might baffle an industry outsider less familiar with the technology, as security is one of the centerpieces of distributed ledger technology’s mainstream appeal. It’s true, blockchain is an inherently secure medium of exchanging information, but nothing is totally unhackable. There are certain situations in which hackers can gain unauthorized access to blockchains. These scenarios include:

  • 51% attacks: Such hacks occur when one or more hackers gain control of over half of the computing power. It’s a very difficult feat for a hacker to achieve, but it does happen. Most recently in August 2020, Ethereum Classic (ETC) faced three successful 51% attacks in the span of a month.
  • Creation errors: These occur when security glitches or errors go overlooked during the creation of the smart contract. These scenarios present loopholes in the most potent sense of the term.
  • Insufficient security: When hacks are done through gaining undue access to a blockchain with weak security practices, is it really as bad if the door was left wide open?

Are exploits more ethically justifiable than hacks?

Many would argue that doing anything without consent cannot possibly be considered ethical, even if worse acts could have been committed. That logic also raises the question of whether an exploit is 100% illegal. For example, having a U.S. company registered in the Virgin Islands can also be seen as performing a legal tax “exploit,” though it isn’t considered outwardly illegal. As such, there are certain gray areas and loopholes in the system that people can use for their own benefit, and an exploit can also be seen as a loophole in the system.

Then there are cases such as cryptojacking, which is a form of cyberattack where a hacker hijacks a target's processing power to mine cryptocurrency on the hacker's behalf. Cryptojacking can be malicious or nonmalicious.

It may be safest to say that exploits are far from ethical. They are also entirely avoidable. In the early stages of the smart contract creation process, it’s important to follow the strictest standards and best practices of blockchain development. These standards are set to prevent vulnerabilities, and ignoring them can lead to unexpected effects.

It is also vital for teams to have intensive testing on a testnet. Smart contract audits can also be an effective way to detect vulnerabilities, though there are many audit companies that issue audits for little money. The best approach would be for companies to get several audits from different companies.

The views, thoughts and opinions expressed here are the author’s alone and do not necessarily reflect or represent the views and opinions of Cointelegraph.

Pawel Stopczynski is the researcher and R&D director at Vaiot. He was previously the R&D director and a co-founder at Veriori and at UseCrypt. Since 2004, Pawel has been involved in the development of 18 IT projects in Poland and the United Kingdom, focusing on the private sector. He was a speaker at several IT conferences, and the organizer of two TEDx conferences. For his work, Pawel was awarded a gold medal at the Concours Lépine International Innovation Fair 2019 in Paris, and a gold medal of the French minister of defense.
Read on about Cointelegraph
Binance tells regulators it will cease operations in Ontario... for real this time
Binance confirmed in an undertaking to the Ontario Securities Commission, or OSC, in Canada dated Wednesday that the crypto exchange will cease activities...
Drake bets $1.3M in Bitcoin on Bengals vs. Rams Super Bowl match
Drake spends his time betting more than $1 million in Bitcoin (BTC) on Super Bowl matches when he’s not running through the six with his woes.The award-winning...
Youtuber and alleged thief publicly refuses to return investors' funds after $750k rug pull
On Wednesday, American Youtuber and "internet detective" Coffeezillaa published a recorded interview of himself and disgraced Youtuber Paul "Ice Poseidon"...
Ethereum hash rate scores new ATH as PoS migration underway
Over the previous year, Ether (ETH) has increased in value to the point that it significantly outperformed Bitcoin (BTC) in terms of returns. The rise of...
Kevin O’Leary-backed WonderFi to buy Bitbuy parent company for $162M
Kevin O’Leary-backed decentralized finance (DeFi) platform WonderFi Technologies is increasing its footprint in Canada by buying the first regulated crypto...
Shiba Inu now accepted as payment at a French bistro in Paris
Le Bistrot d'Eleonore et Maxence, a restaurant in Paris, France joins the growing list of mainstream businesses to add Shiba Inu (SHIB) as a payment method.The...
Billionaire Bill Miller advocates for Bitcoin, but doubtful on altcoins
Bill Miller, a seasoned Wall Street investor and founder of Miller Value Partners, advocated for the riseof Bitcoin (BTC) during a recent conversation with...
El Salvador to use bitcoin gains to fund veterinary hospital, president says
By Nelson RenteriaSAN SALVADOR (Reuters) - El Salvador will invest some of the $4 million gains it has obtained from its bitcoin operations to build a veterinary...
Morgan Stanley doubles exposure to Bitcoin through Grayscale shares
Major U.S. investment bank Morgan Stanley has more than doubled its shares of Grayscale Bitcoin Trust since April.According to a report from the United...
Coinbase users can now buy crypto with Apple Pay
Crypto exchange Coinbase announced on Thursday that users can now use Apple Pay to purchase crypto assets on its platform, with Google Pay integration to...
Foreign CBDCs and stablecoins unlikely to threaten US dollar, says Fed vice chair
Randal Quarles, vice chair for supervision of the Federal Reserve Board of Governors, said he believed neither dollar-pegged stablecoins nor digital currencies...
Data shows derivatives had little to do with Bitcoin's drop to $29K
After a brief recovery to $41,000 on June 14, Bitcoin (BTC) investors might have thought that the bear market was finally over. After all, it was the highest...
Do 46 million Americans really own crypto?
Crypto social media was abuzz after Newsweek published the article headlined “46 Million Americans Now Own Bitcoin, As Crypto Goes Mainstream” on May 11....
Biden’s capital gains tax plan to pull crypto down to earth from the moon?
There are often multiple causes for an asset’s sharp decline, but Bitcoin’s (BTC) 10% “nosedive,” which took place on April 22, may be blamed on the Biden...
Square Got License to Trade Cryptos in New York, Letting Bitcoin Soar
Cash App, a person-to-person payments service, can now be used by New Yorkers to trade cyber coins. The app is a small business service provided by a financial...