Discussion of "Auditing Smart Contracts:" Assurance in the World of Decentralized Finance
Abstract
Smart contracts implement financial logic on public blockchains, and external code audits are a primary means of providing assurance about their security. This paper discusses Landsman, Lyandres, Maydew, Rabetti, and Zhang (Journal of Accounting and Economics, forthcoming), who describe and analyze the market for smart contract audits. I provide a brief primer on blockchains and smart contracts, explain what distinguishes blockchainbased finance from traditional finance, outline why no audit can guarantee security in an open, permissionless environment, and discuss how Landsman et al.s findings relate to financial auditing. A central result in their paper is that pre-launch audits do not predict fewer breaches, which is noteworthy and consistent with the view that a smart contract audit, like a financial audit, is a snapshot, not a shield. Beyond the conceptual and methodological parallels between smart contract and financial audits, two distinctive features merit the attention of accounting scholars: open code forking, which creates networks of common-code exposure and correlated systemic risk, and bug bounty programs, which provide a crowdsourced and potentially continuous form of assurance.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.