The person who lost the 50 million probably insured his money with something like https://nexusmutual.io/. If you invest a large sum, you should always insure it against hacks.
Being decentralized does not prevent them from making the job of an insurer.
Nexus Mutual just told on Twitter that since it is not a smart contract attack, they're not going to pay.
The only thing riskier than smart contracts would be smart contract insurance products atop smart contracts. I'm sure they only allow for vetted contracts, but the incident discussed in this article was not a contract hack, it was a website hack to change the approve addresses. If that type of thing is going to be covered then it's well beyond smart contract due diligence. That would require evaluating end-to-end op sec practices on an ongoing basis.
Looks like they’re refusing to cover it because it was a supply chain attack.
I always found that phrase misleading. Code is automation, law is for the stupid things people do.
If they didn't use a centralized service like Cloudflare, this might not even have happened, lol.
Perhaps, but we know this kind of thing happens all the time even without something like Cloudflare in the mix
There are definitely takesies-backsies if a majority of validators agree on it.
While technically correct, amounts that have been stolen since the DAO hack have been 10x larger and no hard forks have occurred. I think the community consensus on this has evolved.
*if Vitalik agrees on it
Well, no, because the community voted on it, and people decided to run nodes that accept that.