Why Unauthorized Whitehacking Is Unethical

Why Unauthorized Whitehacking Is Unethical
by chrsmaral.eth21 🥝 • 3y • medium.com
AI summary of the linked article

Unauthorized whitehacking, where a security researcher exploits a project's vulnerable smart contracts without its explicit consent, is argued to be unethical and to expose the whitehat to serious liability. The article, written from the perspective of Immunefi, says even well-intentioned exploits are theft-like trespass, since a failed attempt can brick the contract and permanently lose user funds. It cites Immunefi's early 2021 whitehack of Primitive Finance's non-upgradeable contracts, which the project executed itself, and recommends reporting vulnerabilities through bug bounty programs or privately to the project instead. It also states that projects cannot authorize giving user funds away as a "ransom bounty."

Characters remaining: 10,000

comment guidelines