September 24, 2026

Capitalizations Index – B ∞/21M

Smart Contracts Might Not Be as Smart as You Think

Smart contracts might not be as smart as you think

Smart Contracts Might Not Be as Smart as You Think

Adam James · February 24, 2018 · 7:30 pm

Smart contracts are supposed to be just that: smart. However, some smart contracts currently circulating aren’t quite making the grade — with vulnerabilities exposing millions of dollars worth of Ethereum to potential theft.


How Smart are Smart Contracts?

Smart contracts are computer protocols meant to digitally facilitate, verify, or enforce the execution of contracts. Smart contracts’ ability to partially or fully self-execute and self-enforce makes third parties unnecessary when completing transactions — and thus provides superior security and lower costs when compared to traditional contracting.

However, not all smart contracts are created equal, and some house rather serious security vulnerabilities.

According to Motherboard, upwards of 34,200 smart contracts in circulation currently feature coding bugs, potentially exposing millions of dollars to potential theft.

Smart contracts

The first warning sign came last November, when an individual known as “DevOps199” took control of an Ethereum smart contract, destroyed it, and permanently locked up $150 million worth of cryptocurrency — a feat which, theoretically, should never have been allowed to happen.

Millions of Dollars at Risk

Now, a team of researchers from the National University of Singapore, Yale-NUS College in Singapore, and University College London claim to have discovered 34,2oo more unsecured smart contracts. They also claim that $6 million worth of Ether (ETH) could be stolen from roughly 3,000 of those not-so-smart contracts — which doesn’t bode well for the other 31,200.

One of the report’s authors, Ilya Sergey, told Motherboard:

We’re dealing with applications that have two very unpleasant traits: They manage your money, and they cannot be amended.

Smart contracts

Sergey also put breaking into smart contracts into layman’s terms, likening the process to breaking into a vending machine. He told Motherboard:

Imagine your goal isn’t to interact with the vending machine in a proper way, but rather you want to break it or get it to serve you for free. Assume we put a few coins in the machine, and just start randomly pushing buttons hoping that the inner workings of the vending machine—which we have no knowledge about, springs and whatnot—eventually releases the latch so you can take the candy.

The researchers’ report — which claims they were able to “reproduce real exploits at a true positive rate of 89 percent” — is currently being peer-reviewed.

The team was unsuccessful in their attempts to notify the creators of the unsecured smart contracts, and the likelihood that said vulnerabilities will be fixed isn’t particularly strong. Said Sergey:

If someone wants to exploit this idea, they’ll have to do at least as much work as we did.

With millions of dollars at stake, cyber thieves doing just that is far from inconceivable.

Do these researchers’ finding worry you? Does this change your opinion of smart contracts? Let us know in the comments below!


Images courtesy of AdobeStock and Bitcoinist archives.

blockchain technologyETHEthereumhacksmart contract Show comments

Published at Sun, 25 Feb 2018 00:30:01 +0000

Blockchain Technology

Previous Article

Bangla today news 24-Feb-2018 Bangladesh latest news today atn bangla news bd news all bangla update

Next Article

I REJECTED JAKE AND LOGAN PAUL (Episode)

You might be interested in …

Steemit 101 - steem, steem dollars, and steem power

Steemit 101 – Steem, Steem Dollars, and Steem Power

Steemit 101 – Steem, Steem Dollars, and Steem Power A lot has changed on Steemit! Check out this updated video: https://youtu.be/z-V6HnfbGUA In this video I explain the differences between Steem, Steem Dollars, and Steem Power […]

Technology & Choice #23, People and Projects at the Texas Bitcoin Conference (part 1)

I had some great talks with folks at the Texas bitcoin Conference in late October.

This episode:

Paul Puey, CEO of Airbitz and the new Edge wallet, on taking the core concepts and success of Airbitz and taking it to a new level of reach and implementation, rebranding as Edge, and making it much more than just a wallet, but a real tool for security.

Julian Smith, Pres. and CEO of Blockfreight, about integrating blockchain tech into the vastly important movement of freight round the world.

Dhruv Bansal, Co-founder and CSO, Unchained Capital, about why “friends don’t let friends sell bitcoin” and the advantages of borrowing rather than selling an appreciating asset.

John Bushe, Pres. and Permaculture Designer for ZeroWaste, about the vast resources squandered in wasteage, the opportunities and benefits of exploiting them, and how blockchain tech is being targeted for integration to improve outcomes.

Ernest Hancock, Editor and Chief of the publishing and activist site Freedoms Phoenix, and host of the broadly popular radio show, Declare Your Independence. Ernie was at the conference to network and share the collaborative project called “Pirates Without Borders.”

Thanks to Paul and Linda Snow, and all who made the Texas bitcoin Conference possible.

Music

Bumper music: Rocket Power by Kevin MacLeod.

Links

Edge Secure

Airbitz

Blockfreight

Blockfreight on github

Unchained Capital

ZeroWaste

Freedoms Phoenix

Pirates Without Borders