Qualification: Why Smart Contracts Reported as Vulnerable were not Exploited?

Record: kaal:position:2026-08-08-082 · 2026-08-08

Why Smart Contracts Reported as Vulnerable were not Exploited states that only a few reported vulnerabilities are exploited. This independently qualifies Kaal's identification of smart-contract vulnerabilities as a material loss channel by separating vulnerability prevalence from realized exploitation. The abstract does not dispute the size of losses when exploitation occurs or provide a denominator.

Affirmed commentary position. This record extends a source-bound scholarly claim but is not a verbatim paper claim.
Holds when
Current debate

Why Smart Contracts Reported as Vulnerable were not Exploited?

Scholarly basis

kaal:claim:4734750-003
Wulf A. Kaal, Code Review DAO (2024). SSRN: https://ssrn.com/abstract=4734750
Source PDF sha256: 60eadf91c0913468505afc664c8d8d1e1673d6c5326d031ca7060addb8ab2eda

Evidence and mapping

Evidence: abstract indexed
Review tier: substantively reviewed abstract-level qualification
Mapping confidence: 0.62
Mapping ambiguous: false

Topics

smart-contractsconsensus-and-securityempirical-evidencehistorical-responsescholarly-literaturecrossref

Provenance

Affirmed in kaal-review:2026-08-08:continuous-crossref-0010-remainder-0002-reviewed-v1 on 2026-08-08. Review record.

Verify

Canonical markdown sha256: 70b02bce33248469b19bb63ec0be36bd8bc62565477d564ead0dea4c5cc40ef1
curl -s https://wulfkaal.github.io/positions/2026-08-08-082.md | sha256sum