Appearance in the Field of Smart Contracts
Rezumat
The accelerated development of new technologies inevitably generates certain effects on contract law. One of the theoretical pillars of these technologies is the anonymity of those who take action through such devices. This anonymity, although a well-intentioned endeavor, creates numerous difficulties when viewed from the perspective of legal protection, as the legal concept of appearance seems to no longer be the exception, but to become the rule.
Studiu publicat în volumul In Honorem Flavius Antoniu Baias. Aparența în drept, tomul III, Ed. Hamangiu, 2021, p. 117-126.
§1. Appearance and anonymity
At first glance, the title of this research might seem inappropriate to those who only belong to one of the (still) separate worlds of technology and law. For them, the title and, consequently, the whole premise of this paper will be at least unfortunately chosen, if not entirely wrong.
This uncommon introduction is aimed to reconcile two interfering concepts, to the point of accepting that one affects the other and that the introduction of new concepts can affect traditional solutions.
Furthermore, in order to explain why the title is not a mistake, but e precise and intended union of terms, definitions, although brief, become necessary.
1.1. The legal concept of appearance
The modern legal concept of appearance was introduced into continental law by the French jurists[1]. It may be defined as the theory of recognizing legal effectiveness to acts which do not fully comply with the strictly legal conditions and which, as a consequence, should be null[2]. However, these acts are concluded in good faith and are the result of an increased diligence[3].
A somewhat similar construction exists in the common law, achieved through the protection of the concepts of reliance and confidence. Reliance protects the trust of the subject as a result of objective and external reasons. On the other hand, confidence protects the subject from changes in the coherent and reasonable attitude of their partners.
This protection is achieved through the notion of estoppel, which was summarized as follows: “It comes to this: when a man, by his words or conduct, has led another to believe in a particular state of affairs, he will not be allowed to go back on it when it would be unjust or inequitable for him to do so”[4].
Therefore, the legal tradition owns the means to protect realities that are formed outside the will of the subject, consequently protecting the dynamics of the economic circuit. However, this protection is limited in practice to only a handful of particular cases and is rightly viewed and regulated as an exceptional event.
Of course, the theory of appearance represents the result of a long process of observing particular and repeated cases of a similar conduct and responding accordingly, in order to fairly settle situations that fall outside all other principles and theories.
This process, although complicated and long lasting, had the benefit of only a handful of cases regarding the identity of those involved in an economical operation. For example, when the apparent reality consists in contracting with a different person than that of the real beneficial, even if the identity of the real beneficial of the operation remains hidden, the identity of his forefront can still be known (as in the case of a mandate).
1.2. The relative anonymity of the internet
The fast expansion and development of the internet generated a whole new universe of particular and repeated cases that may or may not be treated as a manifestation of the theory of appearance in law.
Furthermore, the possibilities regarding the identification of the participants in the digital space seem to be infinite, as there are many cases when it becomes nearly impossible to identify the person at the other end of the data transmission.
It is quite simple to create an apparent reality on the internet, one that is quite difficult to be distinguished as false even by a diligent observer.
One of the elements that may stand at the core of creating such a reality is the relative anonymity provided by the long-distance way of communication named internet.
Although the concepts of being anonymous or pseudo-anonymous were used for many purposes throughout history, the internet increased the ease to be anonymous and pseudo-anonymous. There are also several cases when being anonymous on the internet is of the essence of the particular activity performed online.
However, there should be said that anonymity on the internet cannot be absolute, as there is always a chance to find the real person behind an anonymous action.
While not inherently bad, as it presents many beneficial use cases[5], some use cases of internet anonymity-based solutions are prone to creating a false and dangerous way of relating to others.
One of this use cases and the one that concerns this paper is the pseudo-anonymous nature of blockchains, especially of those that implement smart contracts.
1.3. The connection between appearance and anonymity
Based on the above definitions and explanations, a series of correlations can be observed in order to establish the problems to be treated.
First of all, the theory of appearance has an obviously larger area of application than that of anonymity in contractual relations.
Secondly, anonymity poses problems of appearance only in certain cases, more precisely in those in which it is the basis for the creation of a false digital reality.
Finally, the spread of the use of anonymity in the context of digital contractual decentralization can lead to exceptional situations that cannot be resolved by the current theory of appearance in law.
All these theses are to be treated from the perspective of one of the most interesting digital applications in the field of contracts law, which is based on a pseudo-anonymity, namely from the perspective of smart contracts implemented on blockchains.
Concluding, the title of this paper should be understood as referring to the particular case in which the pseudo-anonymity of the smart contracts is colliding with the theory of appearance in law.
§2. The pseudo-anonymity of smart contracts and its legal aspects
To facilitate the approach, the pseudo-anonymity specific to blockchains will be hereinafter referred to as the pseudo-anonymity of smart contracts. Although not technically rigorous, this substitution allows readers a better understanding of the legal problem.
Also, for the complete framing of the problem, a brief presentation of the technical environment in discussion is necessary.
2.1. The world of smart contracts
A smart contract is an algorithm for computers that automatically executes, in whole or in part, a contract, in the traditional meaning of the term, while being stored on a blockchain-based platform[6].
The blockchain platforms are distributed, decentralized and public databases, representing a series of immutable records of data which are managed by a group of computers which are not owned by any single entity[7]. Each data block (hence the term block) is secured and linked to the others by using cryptographic methods (hence the term chain)[8].
In its essence, the blockchain is a database with the potential to store and transfer tangible (cars, real estate, etc.) and intangible (such as votes, reputation, intent, information, software) assets[9].
Without going into the technical characteristics of the blockchain, it should be noted that these are the ones that make the various applications of this type of database attractive, applications such as cryptocurrencies, smart contracts, decentralized ledgers and others, as they propose to increase efficiency through automatic execution, and, ideally, the removal of the intermediary (notary, lawyer, public institution) in carrying out certain operations[10].
What a smart contract does is that it autonomously performs an action (of digital nature) when a certain condition set prior to its launch on the blockchain is met. In this regard, as soon as the condition is met (e.g., the goods arrive at the port of destination) the contract acts in the way it was designed (i.e., transfers funds, issues documents for the transport of goods, etc.), without any action or will manifestation from outside[11].
It should also be mentioned that smart contracts can also be contracts in the traditional sense, and not only the automation of the performance of contractual obligations. Thus, traditional consensual contracts can be concluded in full through a smart contract, generating rights and obligations.
2.2. The pseudo-anonymity of smart contracts
As shown above, blockchains are, at least in principle, public and decentralized, which means that anyone can see any registration made in these ledgers. However, that does not mean that anyone may check everyone’s else’s smart contracts and discover their identities.
The reconciliation of the public nature of blockchain platforms with the private nature of a (smart) contract is achieved through pseudo-anonymity, which implies that every user has a public address (i.e., the digital identity used on the blockchain) “that could theoretically be traced back to an exchange account or IP address via network analysis, thus revealing the user’s real identity”[12].
Made simple, pseudo-anonymity means that the real identity of the parties to a smart contract is hidden behind a cryptographic code, so that they cannot be identified by third parties who query the blockchain ledger.
In addition, even the parties may not know the real identity of the contractor, which is, as an example, the case of smart contracts that allow loans between non-professionals (implemented on the so-called peer to peer networks), where the identity of the contractor is irrelevant to those interested in attracting funds.
However, pseudo-anonymity is differentiated from anonymity by the possibility for third parties to find out the identity of the parties to a smart contract, if they have access to a series of real-world information about the parties and the object of the contract[13].
For example, if a competitor of a company that trades grains notices smart contracts for the payment of large quantities of grains in an area close to the target competitor, it may identify both the parties of the contract, as well as the object and price.
Currently, the problem is treated in the sense of developing solutions that allow anonymization, and, consequently, the absolute protection of the private nature of the smart contract, without limiting the possibility of public verification of information, the essence of decentralized databases[14].
Nevertheless, until anonymity becomes the rule for smart contracts, pseudo-anonymity allows for a number of legal issues, some of which will be addressed further.
2.3. The legal aspects of the pseudo-anonymous smart contracts
Given the way pseudo-anonymity works, which was presented above, some consequences of the smart contract may be the result of a legal appearance. Thus, two scenarios will be treated.
In the first scenario, Company X produces breakfast cereals. For its activity, Company X needs a significant quantity of high-quality grains. Through a platform, Company X discovers the only grain supplier that can provide the high-quality grains, Company Y, without knowing its real identity. Company Y has such a quantity available and is willing to alienate it at a price below that of the market.
However, Company Y wants the payment to be made automatically, in cryptocurrencies, as a result of the delivery of goods, through the conclusion of a smart contract that meets all the conditions of validity of a traditional contract. In consequence, the two companies conclude a smart contract and proceed to create a business relationship based on trust.
Company Z, breakfast cereal producer and competitor of Company X, interrogating the blockchain ledger and knowing the real identities of Companies X and Y, discovers the smart contract between the two and the preferential price at which Company X buys the grains.
Out of the desire to destabilize its competitor, Company Z, by technological means, recreates the public address of Company X and concludes a smart contract with Company Y, ordering a quantity of grains far beyond the needs of Company X.
Given the nature of the smart contract, as a result of the performance by Company Y of its own obligation, by delivering the grains to the agreed place, the consideration should be transferred automatically from the digital wallet of Company X.
However, the wallet provided (which is owned by Company X) had insufficient funds in it. In consequence, Company Y, which trusted Company X and the way smart contracts work enough to not ask for any security, demands the payment of the grains in court.
As it can be seen, this scenario deals with a pseudo-anonymous smart contract that an interested third party manages to de-anonymize with the help of data from outside the blockchain, thus finding out the identity, object and price of the contract.
Additionally, the third party manages to create an apparent digital reality that is almost unreasonably difficult for Companies X and Y to discover.
In this regard, when it is, eventually, discovered that behind the same public address are two different entities, Company Y should be entitled to invoke the theory of appearance to avoid the damages arising from the last smart contract and, in consequence, to claim the payment for the grains.
The real problem arises in the situation of Company X, who although it knows that it has suffered damages, consisting at least in the excess of grains that it cannot use, does not know the real identity of the perpetrator.
A second scenario is the one called honeypot. As it has been defined, “a honeypot is a smart contract that pretends to leak its funds to an arbitrary user (victim), provided that the user sends additional funds to it. However, the funds provided by the user will be trapped and at most the honeypot creator (attacker) will be able to retrieve them”[15].
This type of scams usually operates in three phases, which are[16]:
a) the attacker deploys a seemingly vulnerable contract and places a bait in the form of funds;
b) the victim attempts to exploit the contract by transferring at least the required amount of funds and fails; and
c) the attacker withdraws the bait together with the funds that the victim lost in the attempt of exploitation.
It is interesting that this type of fraud uses both computer means and the speculation on the victims’ desire to obtain fast and significant earnings.
Thus, a smart contract which appears to be technologically vulnerable is created, in the sense that by investing a certain amount, a much larger amount can be withdrawn from the smart contract.
The peculiarity of such a method of fraud consists in the degree of specialization of the attacker, which may even include that of a basic user[17]. In this regard, the lack of a specialized perpetrator is what raises great concern.
In this scenario, as in the previous one, the appearance created by a third party generates effective damages, some of which are almost impossible to cover, due to the fact that the real identity of the perpetrator is hidden by the pseudo-anonymity of the smart contract, with little or usually no out-of-network data concerning them.
§3. Perspectives and approaches to the pseudo-anonymity generated appearance
The above scenarios can be found at any time on any public and decentralized blockchains that anyone can access without the prior approval of any entity, with the obvious condition that these blockchains support smart contracts.
For this reason, researchers and professionals in the field propose the further development of smart contract technology in two directions: the existence of an entity that knows the real identity of the participants on a certain blockchain[18] and the total anonymization of smart contracts[19].
3.1. Permissioned blockchains and their owners
To present this solution, a classification of blockchain registers into permitted and permissionless must be performed.
In regard to the permissioned blockchain, the owner (which may be a governmental body or a private entity entrusted with organizing and managing a certain market) has the ability to decide who can be part of the blockchain. Furthermore, the owner is the one that controls which transactions are written and validated on the blockchain[20].
In contrast to this approach, the fully liberalized version is the permissionless blockchain, which implies that anyone can join and participate and that transactions are validated by anyone on the blockchain by consensus[21].
Applying the theoretical model of permissioned blockchains to the first scenario, it can be seen that the problem of appearance disappears completely.
Thus, the owner of the platform (regardless of its public or private nature) will know the real identities of Companies X, Y and Z. Moreover, the Companies, as simple participants in that particular market, will not have access to transactions, so they will not be able to identify and de-anonymize the smart contracts of others.
In regard to the second scenario, the existence of honeypots is very unlikely, as access to such a blockchain is made only on the basis of permission from the owner. Also, the identity of all participants is known by the owner, which makes the latter to be able to identify and eliminate blockchain participants who do not comply with the law.
Of course, scams and frauds are highly improbable on any centralized system, so this conclusion can be translated to a permissioned blockchain, which is closer to centralization rather than decentralization.
In conclusion, in such an environment, deprived of the completely decentralized character, the security and privacy of the participants are increased, while the appearance is being completely eliminated.
3.2. The complete anonymization of smart contracts
On a different path to a possible solution, there are several techniques that aim to fully anonymize the identities of all the participants to a certain blockchain[22].
These techniques have the advantage of compatibility with both permissioned and permissionless blockchains, also removing the need for an owner or any individual or collective entity that operates and manages the network.
Returning to the analyzed scenarios, it can be seen that the first scenario becomes again very unlikely, as the real identity of a participant can no longer be discovered based on external information.
Specifically, Company Z, even if it knew the object of the contract, since it knows the object of Company X’s activity, would not have sufficient data to identify whether a smart contract having as object high-quality grains was concluded by Company X. There are even less chances for Company Z to find out the identity of the seller, Company Y.
Thus, for such a scenario, this solution proves viable and with very extensive applicability in terms of configuring the blockchain in order to use smart contracts.
Regarding the second scenario, the anonymization solution does not imply a removal of the appearance, but can even protect the perpetrator.
In this sense, given that anonymization targets public and permissionless blockchains, the way remains open for anyone to participate, without their identity being known in any way or by any participant.
In addition, in this case, anonymization does not solve the actual problem of fraud, namely the technological trap set by the perpetrator. On the contrary, it encourages it through the increased protection of the perpetrator’s real identity.
As it can be seen, the solution of anonymity, alone, may address some of the presented issues, but is not likely to remove the apparent situations that arise on a public and decentralized environment.
Conclusions
As it has been shown above, there are cases in which the theory of appearance cannot produce the effects desired by legislators, in the sense that keeping the smart contract always harms one of the parties to the smart contract, without any fault, contractual or otherwise.
In addition, the cancellation of smart contracts cannot, as a rule, be ordered in terms of public and permissionless blockchains, which is why the court which is eventually invested with this type of request may order the cancellation of the smart contract as regulations state, but this decision will have no practical effect.
Offering a solution of traditional law, which makes use only of the legislation in force, is complicated to achieve, as it stops in each case at the use of the concept of judicial equity, which would involve judicial interventions that generate new legal rules.
An example to demonstrate this thesis is the first analyzed scenario. Thus, Company X automatically paid part of the grains, as a result of the delivery made by Company Y
In this case, the court, invested by Company Y to obtain the remaining price for delivery, may ascertain the created appearance, which relative to Company Y has an objective and external character, as it cannot know that it has not contracted with Company X, and may keep the contract in full, forcing Company X to pay the remaining price. It is obvious that in this case, Company X pays for goods for which it has not manifested its will and which it does not, in part, need (the amount of grain being too large), without being able to obtain any damages from Company Z because it does not know its real identity.
Another option for the court is to reduce the contract to the quantity of grains that where already paid and force Company X to return the exceeding grains. Presuming that the grains are still usable and can be returned, this solution is at most an equitable one, as it does not make use of the theory of appearance, but of the general sense of justice.
The last option is also the most controversial, as it involves the cancellation of the smart contract (as negotium iuris) and the return of benefits. Such a court decision can be enforced by the parties in two ways.
The first way implies that the refund of benefits, especially of the benefit of Company Y, should be made outside the blockchain, in which case the benefit of Company Y should be refunded in national currency, thus generating a new obligation, with a different object.
The second way involves forcing the parties to conclude a smart contract in reverse, in which case the court’s decision creates an obligation which currently seems impossible to enforce.
It can be seen that the solutions presented tend to complicate the relationship between the parties, thus antagonizing the purpose of smart contracts. This is one of the reasons why, currently, in the absence of regulation, smart contracts remain underused.
From a technological point of view, the directions shown above lead us to the conclusion that the transfer of entire markets on the blockchain must be done with great care, as the ideal solution of a completely decentralized system without any form of authority seems impossible to achieve, even with great computational power. However, a combination of the envisaged technological solutions and the emergence of unified legislation, at least at regional level, can support the transfer of significant domains, on the blockchain, thus giving a major impulse to areas that tend to underperform when compared to modern standards.
Footnotes
[1] O. Massot, L’erreur au fond du droit, Revue interdisciplinaire d’études juridiques 2006/2, Vol. 57, p. 157.
[2] I. Dogaru, Drept civil. Idei producătoare de efecte juridice, Ed. All Beck, Bucharest, 2002, p. 158.
[3] Ibidem.
[4] Lord Denning in Moorgate Mercantile v. Twitchings (1976), apud E. Cooke, The Modern Lay Of Estoppel, OUP, 2000, p. 2.
[5] For examples of good purposes of anonymity and pseudo-anonymity on the internet: Jacob Palme, Mikael Berglund, Anonymity on the Internet, link: https://people.dsv.su.se/~jpalme/society/anonymity.html, date of last access: 24.08.2021.
[6] S.D. Levi, A.B. Lipton, An Introduction to Smart Contracts and Their Potential and Inherent Limitations, Harvard Law School Forum on Corporate Governance, 26 May 2018, link: https://corpgov.law.harvard.edu/2018/05/26/an-introduction-to-smart-contracts-and-their-potential-and-inherent-limitations/, date of last access: 24.08.2021.
[7] For a detailed, but yet accessible, presentation of the blockchain technology, please see: https://blockgeeks.com/guides/what-is-blockchain-technology/, date of last access: 24.08.2021.
[8] Ibidem.
[9] M. Corrales et al., Digital Technologies, Legal Design and the Future of the Legal Profession, in M. Corrales (ed.), Legal Tech, Smart Contracts and Blockchain, Springer, 2020, p. 3.
[10] S. McJohn, I. McJohn, The Commercial Law of Bitcoin and Blockchain Transactions, Suffold University Law School, Legal Studies Research Paper Series, p. 7.
[11] For more information regarding how smart contracts work from a technical perspective, please see: https://www.computerworld.com/article/3412140/whats-a-smart-contract-and-how-does-it-work.html, date of last access: 24.08.2021.
[12] A. Buczak, Is Cryptocurrency Anonymous? The Myth of Anonymity Debunked, link: https://www.ulam.io/blog/is-cryptocurrency-anonymous/, date of last access: 25.08.2021.
[13] For technical insight on how the identification is made, please see S. Linoy et al., De-anonymizing Ethereum blockchain smart contracts through code attribution, International Journal of Network Management, Vol. 31, no. 1, January 2021, link: https://onlinelibrary.wiley.com/doi/epdf/10.1002/nem.2130, date of last access: 26 august 2021. For other methods, please see F. José de Haro-Olmo et al., Blockchain from the Perspective of Privacy and Anonymisation: A Systematic Literature Review, Sensors, 2020, p. 16.
[14] For technical insight on such a solution, please see R. Saket et al., Smart Contract Protocol for Authenticity and Compliance with Anonymity on Hyperledger Fabric, link: https://researcher.watson.ibm.com/researcher/files/in-rissaket/entrypoint.pdf, date of last access, 26 august 2021.
[15] C. Ferreira Torres et al., The Art of The Scam: Demystifying Honeypots in Ethereum Smart Contracts, link: https://www.arxiv-vanity.com/papers/1902.06976/, date of last access: 26.08.2021.
[16] Ibidem. For the extensive analysis on all types of honeypots, please see Yu Han, Tiantian Ji, Zhongru Wang et al., An Adversarial Smart Contract Honeypot in Ethereum, CMES-Computer Modelling in Engineering & Sciences, Vol. 128(1), p. 247-267.
[17] Ibidem.
[18] F. José de Haro-Olmo et al., op. cit., p. 17.
[19] Ibidem.
[20] Ibidem.
[21] For more on how permissioned and permissionless blockchains work, please see A. Miller, Permissioned and Permissionless Blockchain, in S. Shetty et al., Blockchain for Distributed Systems Security, John Wiley & Sons, 2019, p. 193 et seq.
[22] For an overview of the anonymization solutions, please see F. José de Haro-Olmo et al., op. cit., p. 17.