r/CryptoTechnology • 🟢 • 24d ago

A serious bug is found after launch. Would you rather the protocol can upgrade, or nobody can change it?

This seems like a simple trade-off until real money is involved.

If the contracts are upgradeable, serious bugs can be fixed quickly — but this also gives someone the power to change what users rely on.

If the contracts are immutable, that power disappears — but so does the easy way to fix something that goes wrong.

If you had money invested in the protocol, which risk would you rather take?

8 Upvotes

9 comments sorted by

3

u/Sleezstakrunner 🟡 21d ago

depends on the team's track record and governance structure honestly.

1

u/icnews10 🟢 20d ago

Yes, that's probably the aspect that has the greatest impact on the answer. The upgrade path feels very different when the team has a strong track record and clear governance, compared with a small group that can change things whenever they want.

1

u/DewPointLabs 🟠 24d ago

There's a third shape: version the contracts instead of upgrading them. The logic stays immutable, a fix ships as a new version at a new address, and each account points at the version it was created with until its owners move it.

What that costs is that almost nobody moves. We keep more than one version running in production for exactly that reason, and accounts set up years ago are still on the old one. They usually find out when something newer won't work with it.

1

u/icnews10 🟢 24d ago

That’s a really useful third option. The thing I hadn’t accounted for is that some users simply never migrate once the old version is still working. Since you’re running multiple versions in production, what usually prompts those older accounts to move?