This isn't a hack, it was straight arbitrage. I distinguish them because there was at no time a transfer of administrative power or control over the contract or targets infrastructure to Medjedovic. In a smart contract, I'd make a legal distinction between syntactic parsing and calculation, which has to do with the purity of functions and data. An arbitrage would be fair game if it levered an unanticipated calculatio…
>He used logic endogenous to the contracts, with no exogenous control of the systems running the contracts The same description can be said for using XSS to steal someone's cookies. XSS doesn't escape the JavaScript virtual machine similar to how you aren't escaping Ethereum's virtual machine. Technically the code allows you to inject arbitrary JavaScript, but that behaviour wasn't intend to be possible by the design…
The argument I'm using is that the casino didn't shuffle their deck and a player calculated an advantage. He didn't have hidden cards, a secret view of anyone elses. I'd like to verify that aspect of the strategy though as it's potentially a powerful heuristic.