Earlier quoted context omitted.
> With this worldview, if the attacker simply exploited poorly-written code to find a loophole, how do the owners of Index have a leg to stand on? They don’t. They simply have to accept it as a bug bounty successfully collected and paid out, and treat it as a learning experience and evolutionary process. Do better next time, if there is a next time.
Good luck making that argument in court. Intent is key, and if this is not the intent of the "smart" (lol) contract, "finder's keeper's" is not a legal defense. The legal system doesn't care about your blockchain arguments.
Ianal and don't know how a court would see it, but the way smart contracts are advertised would probably give you a fighting chance to make this argument where in normal finance you would have no chance.