at 1:22:50 Smart contracts are just code, they’re software, there’s no reason they can’t be viruses or worms, the primary limitation is processing power. But, also, it’s a virus that someone can drop directly into your bankless bank account and just wait for you to activate it. And, yeah, that’s right, there’s no offer/confirmation step in sending tokens back and forth, someone who knows your wallet can just drop stuff right into it, so, like, pin that somewhere in your brain.
Line Goes Up – The Problem With NFTs
While it's true that NFTs can be sent without permission and can contain code, users normally invoke contracts via (hopefully trusted) dapp websites, such as app.uniswap.org. Invoking code from an NFT I found in my wallet is possible, but not part of any normal/legitimate workflow that I'm aware of.
It looks like the message in this case would have given the attacker permission to transfer the victim's aWETH, which represents ETH that has been deposited into an Aave lending pool. These transfer permissions are something all ERC-20 tokens support.
Typically users will only sign messages sent from trusted websites, just as they would only install software from trusted sources. Or they can sign a questionable message from a separate wallet which doesn't hold much value, as the victim did here.
Granted, this isn't a great situation. It can be hard to know which websites to trust, and even trusted websites can be hacked and then send malicious messages to unsuspecting users.
[1] Think of these as being similar to Word or Excel macros embedded in a document... nothing bad ever happened with them, did it? ;-)
There's nothing broken here. A smart contract is just a piece of code that moves money. You better be sure about what it's doing before you allow it to run. There's blue chip smart contracts that are proven and thoroughly audited, but anything else you need to read the code. Same as reading a contract before you sign it.
I'm still not convinced that Ethereum isn't just a strange RPG that people who don't really want to play are accidentally getting involved in.
We had illegal p2p sharing where you could download a virus from bad people and then Jobs came along and made iTunes which set the standard for streaming. I am sure someone will come along in the crypto space and make crypto easy for the rest of us.
People wanted easy access to music, itunes provided that service.
Right now with the world of crypto is confusing to the average guy, so hopefully in the future someone will create a good UX and the underlying to protocol for instant decentralised payments.
So... Napster and LimeWire?
You can't break cryptocurrency's weakness for this kind of adoption without dropping decentralization. Same conclusion that iTunes came to. People wanted downloadable music, not a specific implementation detail about how that music is delivered.
I wouldn't touch it with a ten foot pole. I just don't see any sense or reason in the concept.
It's mighty arrogant from crypto enthusiasts to assume that everybody will jump on it as soon it just can be made mainstream and "safe".
Thanks, but no thanks