• bitcoinBitcoin(BTC)$77,241.000.45%
  • ethereumEthereum(ETH)$2,513.762.63%
  • tetherTether(USDT)$1.000.02%
  • binancecoinBNB(BNB)$730.002.54%
  • rippleXRP(XRP)$1.361.41%
  • usd-coinUSDC(USDC)$1.00-0.02%
  • solanaSolana(SOL)$101.792.43%
  • tronTRON(TRX)$0.339190-0.35%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.34%
  • zcashZcash(ZEC)$1,137.866.26%
  • HyperliquidHyperliquid(HYPE)$78.760.09%
  • dogecoinDogecoin(DOGE)$0.0844531.12%
  • RainRain(RAIN)$0.015328-2.51%
  • moneroMonero(XMR)$524.143.20%
  • USDSUSDS(USDS)$1.000.00%
  • whitebitWhiteBIT Coin(WBT)$80.170.72%
  • chainlinkChainlink(LINK)$11.520.30%
  • leo-tokenLEO Token(LEO)$9.140.46%
  • cardanoCardano(ADA)$0.2086980.79%
  • stellarStellar(XLM)$0.1803192.59%
  • bitcoin-cashBitcoin Cash(BCH)$230.051.37%
  • Ethena USDeEthena USDe(USDE)$1.000.04%
  • daiDai(DAI)$1.000.00%
  • USD1USD1(USD1)$1.000.05%
  • litecoinLitecoin(LTC)$53.962.21%
  • CantonCanton(CC)$0.0989100.63%
  • uniswapUniswap(UNI)$6.101.95%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.360.98%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • avalanche-2Avalanche(AVAX)$7.46-0.02%
  • hedera-hashgraphHedera(HBAR)$0.074623-0.69%
  • nearNEAR Protocol(NEAR)$2.36-2.00%
  • shiba-inuShiba Inu(SHIB)$0.0000052.85%
  • suiSui(SUI)$0.73-1.04%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.01%
  • crypto-com-chainCronos(CRO)$0.0569930.91%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • MemeCoreMemeCore(M)$1.204.61%
  • tether-goldTether Gold(XAUT)$4,350.060.59%
  • Circle USYCCircle USYC(USYC)$1.140.03%
  • Ripple USDRipple USD(RLUSD)$1.000.01%
  • okbOKB(OKB)$115.115.52%
  • BittensorBittensor(TAO)$234.87-0.16%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.14-0.22%
  • aaveAave(AAVE)$125.303.00%
  • mantleMantle(MNT)$0.581.01%
  • pax-goldPAX Gold(PAXG)$4,355.520.58%
  • AsterAster(ASTER)$0.68-2.35%
  • polkadotPolkadot(DOT)$1.05-5.57%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.054358-4.53%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Smart contracts might not be as smart as you think

July 15, 2023
in AI & Technology
Reading Time: 5 mins read
A A
Smart contracts might not be as smart as you think
ShareShareShareShareShare

Head over to our on-demand library to view sessions from VB Transform 2023. Register Here


Blockchain technology has piqued the interest of enterprises worldwide. Its advantages, including immutability and transparency, have led legacy companies outside of finance, such as BMW and Bosch, to experiment with smart contracts to create more efficient supply chains and make smarter engineering products.

YOU MAY ALSO LIKE

Musk’s Boring Co. Gets $23 Billion Valuation

The Future of Health | Bloomberg Tech: Europe 9/11/2026

Smart contracts, which are essentially software coded into a specific blockchain, formalize and execute agreements between multiple parties, removing the need for a trusted third-party intermediary, saving time, and allowing a multi-party consensus-based validation. They can be used across a variety of activities, such as wills, chess games and even transferring deeds.  

But despite all the disruptive potential and the highly-touted capabilities blockchain promises, the number of heists targeting smart contracts has risen more than 12-fold over the last two years. If they are so smart, why are we seeing such a massive uptick in heists?

To better understand, let’s clarify the relationship between blockchain and smart contracts.

Event

VB Transform 2023 On-Demand

Did you miss a session from VB Transform 2023? Register to access the on-demand library for all of our featured sessions.

 

Register Now

Decentralization

Think of a blockchain network like Amazon’s AWS platform and each one of its smart contracts as a server. With blockchain, there isn’t a single centralized server for hackers to exploit, making it more difficult for cybercriminals to use traditional hacking methods, such as Trojan horses, physical attacks and ransomware. Blockchain counters these by eliminating a network’s single point of failure.

While a blockchain network can’t exactly be hacked, many distributed apps and smart contracts that blockchain facilitates can. 

Thanks to the gradually growing success and influence of decentralized finance (DeFi), large amounts of value are being funneled through smart contracts, making them appealing to hackers. And this threat will likely only grow as more assets move on-chain with the rise in tokenized real-world assets. Hacking poses a serious threat to this burgeoning blockchain sector because assets nicked from smart contracts are extremely difficult to recover.

Threats to smart contracts

Like all code, smart contracts are subject to human error. These errors can come in the form of typos, misrepresentations of specifications, or more serious mistakes that can be used to hack or “trick” the smart contract. As opposed to blockchain, there is no guarantee that the contracts have been peer-reviewed or validated.

While faulty coding may be avoided by a smart contract audit, other threats are more complex. The default-visibility vulnerability, for example, is a common mistake that occurs when the visibility of functions is not specified and certain functions are left public. For example, hackers could access the mint function and create billions of relevant tokens. Fortunately, this vulnerability can be prevented by running an audit that ensures all functions are set to private by default. 

Another more complicated and serious threat caused by coding errors is a reentrancy attack. This happens when an attacker takes advantage of the smart contract’s external function calls and deploys a malicious smart contract to interact with the one holding the funds. 

In 2016 the DAO incident, which occurred in the early days of Ethereum, demonstrated just how dangerous this type of attack can be and, ultimately, led to the creation of Ethereum Classic. Preventing reentrancy attacks isn’t simple, but there are frameworks and protocols that can mitigate the damage, which include CEI (check, effects and interactions), reentrancy guards and more.

If you’re competent in smart contract code, reading the code itself is always a massive advantage. Just as reading a contract before moving into a new apartment protects you from any surprises, being able to read a smart contract’s code can reveal flaws, malicious functions, or features that don’t work or make sense.

However, if you are an end user who is not particularly tech-savvy, use only smart contracts with publicly accessible code that are widely used. This, as opposed to compiled smart contracts, where the code is hidden and people are unable to review it, is the preferred option.

Addressing smart contract vulnerabilities

Let’s not forget that most smart contract administrators leave themselves some admin privileges, usually to make post-launch changes. To access these privileges, the admins need to use their private keys. These private keys are yet another vulnerability, and if they are not custodied correctly (i.e., in an offline cold vault), hackers who somehow gain access can make changes to the smart contract and funnel the funds anywhere they wish.

Lately, the European Parliament mandated a kill switch mechanism be employed to mitigate damage in the event a smart contract is compromised. While the intention of the regulators was to give people more protection over their own personal data, the act has generated concerns in the Web3 community. 

If not implemented correctly, a kill switch could destroy the entire smart contract and any value stored on it. A better implementation would be to activate a pause function which, in the event of a security threat, could freeze the smart contract and reactivate it once the issue is resolved. 

Should the pause function be implemented, it’s advised that the admin utilize two different private keys. Because once the private key (used to pause the contract) goes online, it becomes vulnerable to attack. As mentioned in my article on the mandate, separating the pause and unpause admin keys and storing them offline strengthens the smart contract’s security by eliminating potential points of failure.

As with all technologies, security threats exist in the DeFi and blockchain ecosystems. Smart contracts certainly have their advantages, as we’ve seen with the emergence of DeFi platforms and protocols, but understanding their vulnerabilities, doing diligent research and following the guidelines set forth in this article can help mitigate them. With time, enhanced security protocols will take shape, strengthening smart contract use cases and ushering in a more robust blockchain ecosystem. 

Shahar Shamai is CTO and cofounder of GK8.

DataDecisionMakers

Welcome to the VentureBeat community!

DataDecisionMakers is where experts, including the technical people doing data work, can share data-related insights and innovation.

If you want to read about cutting-edge ideas and up-to-date information, best practices, and the future of data and data tech, join us at DataDecisionMakers.

You might even consider contributing an article of your own!

Read More From DataDecisionMakers


Credit: Source link

ShareTweetSendSharePin

Related Posts

Musk’s Boring Co. Gets  Billion Valuation
AI & Technology

Musk’s Boring Co. Gets $23 Billion Valuation

September 12, 2026
The Future of Health | Bloomberg Tech: Europe 9/11/2026
AI & Technology

The Future of Health | Bloomberg Tech: Europe 9/11/2026

September 12, 2026
Oracle’s AI Cloud Growth Eases Buildout Concerns
AI & Technology

Oracle’s AI Cloud Growth Eases Buildout Concerns

September 12, 2026
OpenAI’s Altman May Slow Down AI Development
AI & Technology

OpenAI’s Altman May Slow Down AI Development

September 12, 2026
Next Post
Researchers from the University of Massachusetts Lowell Propose ReLoRA: A New AI Method that Uses Low-Rank Updates for High-Rank Training

Researchers from the University of Massachusetts Lowell Propose ReLoRA: A New AI Method that Uses Low-Rank Updates for High-Rank Training

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Cantor heir recalls family’s 9/11 losses — and the kindergarten run that spared Howard Lutnick

Cantor heir recalls family’s 9/11 losses — and the kindergarten run that spared Howard Lutnick

September 11, 2026
X-Energy Could Be Building One Of Nuclear Energy's Most Valuable Platforms

X-Energy Could Be Building One Of Nuclear Energy's Most Valuable Platforms

September 6, 2026
Building a GPT-6 Kalshi AI Trading Bot From Scratch (full guide)

Building a GPT-6 Kalshi AI Trading Bot From Scratch (full guide)

September 8, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!