TGViewer
Curious facts from Michael@Curve Curious facts from Michael@Curve @michael_curve · 1.22K subscribers
Post #103 1.9K
Upgradable smart contracts are a bug [https://medium.com/consensys-diligence/upgradeability-is-a-bug-dba0203152ce]. Remember this? It's mostly controversial now because very few projects do immutable smart contracts these days (but Curve and Yield Basis do).

So why immutable smart contracts are good?

- Humans make bugs in code. Steve McConnell in his book "Code Complete" famously wrote that average for software engineering industry is 1-25 per 1000 lines of code, which get to 0.5 defects per 1000 lines in Misrosoft after good testing. Average smart contract is several thousand lines = 1 bug after rigorous testing, hopefully not critical (critical parts should be smaller than few thousand lines). Now, imagine that smart contracts will be upgraded again and again and again - and now you need to secure not 2000 lines but 100000 lines (smart contracts in each release).

- Yes upgradability can save you if you find a mistake before hackers. But if you don't? Whoosh!

- Upgrades can break integrations. Remember Curve pools which use Aave tokens which are now disabled? Not nice.

- What if devs will be replaced by new devs? Will they be as competent as before? Less trust to humans = better!

- Maybe not an issue now, but upgradability does increase regulatory attack surface.

So, immutable smart contracts for the win!

#DeFi #security
Medium Upgradeability Is a Bug Upgradeability Is a Bug tl;dr Smart contracts are useful because they’re trustless. Immutability is a critical feature to achieve trustlessness. Upgradeability undermines a contract’s …
  • ❤ 12
  • 👍 6
  • 🔥 2
More from @michael_curve
  1. Jul 20, 2026In his recent interview, Andre Cronje weighted heavily (https://x.com/therollupco/status/2…
  2. Jun 25, 2026So looks like Uniswap finds out tech which was used by Curve since its start in 2020 (usin…
  3. Jun 9, 2026Seeing a lot of fears about Claude Mythos allegedly being released today or tomorrow and "…
  4. May 26, 2026Here we go again. Custodial stablecoins EURR and USDR were hacked by company-s multisig wa…
  5. May 11, 2026Seeing many people getting their telegram hacked. The malware uses telegram of someone fro…
  6. Apr 26, 2026I've made a proposal on how to recover bad debts in lending protocols, starting with Curve…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →