If people find getting into interest bearing products to be complicated, then you would create a contract to make it less complicated.
Pooltogether.com is an example of something people like, I didnt write that. It just gives people a chance of earning more interest than they could alone, at the expense of earning no interest in the mean time. They bill it as a “no-loss lottery”, while it is really just helping people deposit into other onchain financial services. It is analogous to many people depositing into a single savings account to earn more interest than they could as an individual, and only one person getting paid all of the interest. So some people like doing that because their alternatives are non-existent.
You can make a competitor to that or something slightly different and get people using it.
I don’t post or advertise audits, third party smart contract audits are expensive and purely a marketing racket.
A) users dont care
B) Vulnerabilities come from closed source pricing oracles.
C) users that do care understand that vulnerabilities are not really coming from the code and more so from pricing oracles
D) Users can buy smart contract insurance.
E) They can also buy their own smart contract audit, I at least make sure the block explorer has the code and ABI available
As to your point that user's don't care, I think that's the real answer, and it's a shame. Do you think the user base is not technical enough to care?
Secondly, another thing I was alluding to is that you can just copy working code. You can deploy the exact same service as someone else and compete directly. Too many developers think they need uniqueness, which may have been true in the "I can only get recognition from VCs to make real money" world. DeFi development is analogous to launching a grocery store offering slightly different brands. The code you copied from having already been audited.
Third, everything I wrote before was assuming no malicious intent. So if we are copying code for the most part, it moves the vulnerabilities to the closed source oracles and the behavior of the oracle's sources of data.
I'm always open to having this conversation, in general top level hackernews has not been ready for that conversation and they want to debate largely irrelevant things about their feelings over blockchain, as opposed to the state of various sectors in the space that they aren't aware of. So leading with nuanced discussion would hurt the visibility of what I actually have to contribute.
It seems to me like you've found an interesting way to play in an adversarial space by selling shovels during a gold rush.