{
 "@context": "https://schema.org",
 "@type": "DefinedTerm",
 "@id": "https://wulfkaal.github.io/entities/smart-contract-security",
 "identifier": "kaal:entity:smart-contract-security",
 "name": "Smart contract security",
 "termCode": "smart-contract-security",
 "inDefinedTermSet": {
  "@id": "https://wulfkaal.github.io/entities/index.json"
 },
 "author": {
  "@type": "Person",
  "name": "Wulf A. Kaal",
  "identifier": "https://orcid.org/0000-0003-0757-275X"
 },
 "dateModified": "2026-07-29",
 "canonicalForm": "https://wulfkaal.github.io/entities/smart-contract-security.md",
 "sha256": "f217bc03fb44ecaf091c05b2047c4887dbed8b53219144cd88815d841688007c",
 "additionalProperty": [
  {
   "@type": "PropertyValue",
   "name": "status",
   "value": "derived"
  },
  {
   "@type": "PropertyValue",
   "name": "claim_count",
   "value": 2
  },
  {
   "@type": "PropertyValue",
   "name": "work_count",
   "value": 2
  },
  {
   "@type": "PropertyValue",
   "name": "year_span",
   "value": [
    "2020",
    "2024"
   ]
  },
  {
   "@type": "PropertyValue",
   "name": "non_current_claims",
   "value": 0
  }
 ],
 "subjectOf": [
  {
   "@type": "Claim",
   "@id": "https://wulfkaal.github.io/claims/3652481-009",
   "identifier": "kaal:claim:3652481-009",
   "text": "The immutability of blockchain ledgers is itself a vulnerability, because once a DAO is in operation its essential construction is very difficult to alter should a bug in the code appear.",
   "abstract": "The immutable nature of blockchain ledgers could also make the DAO vulnerable to attacks because it is so difficult to alter the essential construction of the DAO once the system is in operation, should a bug in the code arise.",
   "citation": "Wulf A. Kaal, Decentralized Autonomous Organizations – Internal Governance and External Legal Design (2020). SSRN: https://ssrn.com/abstract=3652481",
   "datePublished": "2020",
   "claim_type": "failure",
   "confidence": "evidenced",
   "is_failure_mode": true,
   "scope_conditions": [
    "a bug exists in deployed DAO code"
   ],
   "source_pdf_sha256": "530b3a40c244aeca2eb4c53f4c9b4d6b2962bd6be9f92b4ebe17139c17f4c0e0",
   "status": "current"
  },
  {
   "@type": "Claim",
   "@id": "https://wulfkaal.github.io/claims/4734750-004",
   "identifier": "kaal:claim:4734750-004",
   "text": "Bug bounty programs fail at their own premise because the hackers they pay to demonstrate exploitability frequently sell or exploit the bugs they find instead of disclosing them.",
   "abstract": "Alas, hackers often sell the bug or exploit them when they discover them.",
   "citation": "Wulf A. Kaal, Code Review DAO (2024). SSRN: https://ssrn.com/abstract=4734750",
   "datePublished": "2024",
   "claim_type": "failure",
   "confidence": "argued",
   "is_failure_mode": true,
   "scope_conditions": [
    "community audit and bug bounty programs for smart contracts"
   ],
   "source_pdf_sha256": "60eadf91c0913468505afc664c8d8d1e1673d6c5326d031ca7060addb8ab2eda",
   "status": "current"
  }
 ],
 "description": "2 claims in the published works of Wulf A. Kaal carry the concept tag 'smart-contract-security'. Derived node: a roster, not an adjudicated definition."
}