Smart contract exploits are more ethical than hacking... or not?

Smart contract exploits are more ethical than hacking... or not?

There has been a lot of talk about the recent “hacks” in the decentralized finance realm, particularly in the cases of Harvest FInance and Pickle Finance. That talk is more than necessary, considering hackers stole more than $100 million from DeFi projects in 2020, accounting for 50% of all hacks this year, according to a CipherTrace report.

Related: Roundup of crypto hacks, exploits and heists in 2020

Our top trading bots

Some point out that the occurrences were merely exploits that shined a light on the vulnerabilities of the respective smart contracts. The thieves didn’t really break into anything, they just happened to casually walk through the unlocked back door. By this logic, since the hackers exploited flaws without actually hacking in the traditional sense, the act of exploiting is ethically more justifiable.

But is it?

The differences between an exploit and a hack

Security vulnerabilities are the root of exploits. A security vulnerability is a weakness that an adversary could take advantage of to compromise the confidentiality, availability or integrity of a resource.

An exploit is the specially crafted code that adversaries use to take advantage of a certain vulnerability, and to compromise a resource.

Even mentioning the word “hack” in reference to blockchain might baffle an industry outsider less familiar with the technology, as security is one of the centerpieces of distributed ledger technology’s mainstream appeal. It’s true, blockchain is an inherently secure medium of exchanging information, but nothing is totally unhackable. There are certain situations in which hackers can gain unauthorized access to blockchains. These scenarios include:

  • 51% attacks: Such hacks occur when one or more hackers gain control of over half of the computing power. It’s a very difficult feat for a hacker to achieve, but it does happen. Most recently in August 2020, Ethereum Classic (ETC) faced three successful 51% attacks in the span of a month.
  • Creation errors: These occur when security glitches or errors go overlooked during the creation of the smart contract. These scenarios present loopholes in the most potent sense of the term.
  • Insufficient security: When hacks are done through gaining undue access to a blockchain with weak security practices, is it really as bad if the door was left wide open?

Are exploits more ethically justifiable than hacks?

Many would argue that doing anything without consent cannot possibly be considered ethical, even if worse acts could have been committed. That logic also raises the question of whether an exploit is 100% illegal. For example, having a U.S. company registered in the Virgin Islands can also be seen as performing a legal tax “exploit,” though it isn’t considered outwardly illegal. As such, there are certain gray areas and loopholes in the system that people can use for their own benefit, and an exploit can also be seen as a loophole in the system.

Then there are cases such as cryptojacking, which is a form of cyberattack where a hacker hijacks a target's processing power to mine cryptocurrency on the hacker's behalf. Cryptojacking can be malicious or nonmalicious.

It may be safest to say that exploits are far from ethical. They are also entirely avoidable. In the early stages of the smart contract creation process, it’s important to follow the strictest standards and best practices of blockchain development. These standards are set to prevent vulnerabilities, and ignoring them can lead to unexpected effects.

It is also vital for teams to have intensive testing on a testnet. Smart contract audits can also be an effective way to detect vulnerabilities, though there are many audit companies that issue audits for little money. The best approach would be for companies to get several audits from different companies.

The views, thoughts and opinions expressed here are the author’s alone and do not necessarily reflect or represent the views and opinions of Cointelegraph.

Pawel Stopczynski is the researcher and R&D director at Vaiot. He was previously the R&D director and a co-founder at Veriori and at UseCrypt. Since 2004, Pawel has been involved in the development of 18 IT projects in Poland and the United Kingdom, focusing on the private sector. He was a speaker at several IT conferences, and the organizer of two TEDx conferences. For his work, Pawel was awarded a gold medal at the Concours Lépine International Innovation Fair 2019 in Paris, and a gold medal of the French minister of defense.
Read on about Cointelegraph
Is the bottom in? Institutional crypto funds record second week of inflows
After recording heavy outflows at the start of 2022, cryptocurrency investment funds have seen a gradual uptick in investor demand over the past two weeks,...
Down, but not out: Here’s why Theta could be a breakout star in 2022
2021 was a rollercoaster ride for many projects in the cryptocurrency market but as is the nature of crypto, many tokens hit new all-time highs and then...
Price analysis 1/10: BTC, ETH, BNB, SOL, ADA, XRP, LUNA, DOT, AVAX, DOGE
Bitcoin (BTC) dipped below the $40,000 level on Jan. 10 for the first time since September 2021. The crypto markets were not alone as the U.S. equity markets...
Aurora raises $12M in debut funding to scale Ethereum ecosystem
Aurora, an Ethereum Virtual Machine (EVM) designed to scale decentralized applications (DApp) built on the Near protocol, has announced a $12-million debut...
These 3 indicators flashed bullish ahead of the recent Bitcoin price pump
In stock markets and the crypto sector, traders are always looking for a definite reason to explain an asset's price action, which means it's important...
Arca Labs partners with Securitize on regulated, tokenized financial products
Arca Labs, the innovation arm of digital asset investment firm Arca has partnered with blockchain tech firm Securitize to launch regulated, tokenized financial...
Goldman Sach's new 'DeFi' ETF is anything but
The proposed fund, dubbed the Goldman Sachs Innovate DeFi and Blockchain Equity ETF, strives to track the Decentralized Finance and Blockchain Index from...
Visa reports over $1 billion in crypto spending in H1 2021
Global payments giant Visa will continue to support the development and adoption of the cryptocurrency industry as part of its business, the company said...
Bitcoin's key momentum metric hints at bullish divergence as BTC clings to $33K
A recent run-down in the Bitcoin (BTC) market faces the prospects of exhaustion before confirming a full-fledged bearish breakdown, so reflects a classic...
UK’s NatWest bank limits transactions to crypto exchanges
As the crypto crackdown continues in Britain, another high street bank has intensified its efforts to curtail  its customers' use of digital assets. The...
Even Elon Musk can't save Dogecoin from crashing another 60%, analyst asserts
If one looks at Dogecoin (DOGE) charts from the point of view of a financial chartist, he/she will notice an alarming presence of a classic bearish structure.For...
Almost all major Bitcoin mining pools now signaling for Taproot activation
Disclaimer: This article has been updated to reflect that BTC.Top has begun signaling for Taproot activation.The top-10 Bitcoin (BTC) mining pools by hash...
Tyler Winklevoss thinks Bitcoin is past the risk of a US ban
The United States government has increasingly stepped up its overwatch on crypto in recent years, although an outright ban on Bitcoin is now unlikely —...
Seoul Intends to Set Off Its Own Crypto-Coin
Despite the fact the government of South Korea overall tries to be CoinDesk Korea reported. S-Coin Like No Other Coin According to the report, this...
Nobel Prize Winner Shiller Says Bitcoin is a ‘Clever Idea’
The American Nobel Laureate and Sterling Professor of Economics at Ivy League Yale University Robert Shiller considers bitcoin as an exciting experiment...