What a smart contract is — and is not

A program with state and permissions. Neither a contract in the legal sense nor an entity that knows what happens off the chain.

This lesson has had no expert review. It was written for this platform and against the evidence it cites; nobody has gone through it independently.

Learning objectives

  • You can explain why a smart contract knows nothing about the world outside the chain.
  • You can name the three places where a smart contract depends on something else.

Check your prior knowledge

Answer these for yourself before reading on. Wherever you hesitate is where this lesson pays off.

Core concept

Fact

A program that holds value

A smart contract is code at an address on the chain. It has state — balances, parameters, permissions — and functions that change that state by fixed rules. Every execution is a transaction, is paid for, and is traceable in the ledger.

Fact

The contract sees only the chain

A smart contract can query nothing that is not on the chain. It knows no exchange rate, no weather, no delivery. Everything external has to be written in by someone as a transaction — which is exactly what an oracle does. Every statement the contract makes about the outside world is therefore only as reliable as the source that wrote it in.

Risk

Three dependencies not visible in the code

A contract depends on the data an oracle supplies; on the contracts it calls itself; and on the rights someone retains over it. The code alone shows only the second of the three. The other two must be established from documentation and chain state — and their absence from an overview says nothing about their absence in fact.

Definitions

Smart contract in the glossary
Program code at a chain address that manages assets by fixed rules.
Oracle
A mechanism that writes data from outside the chain into a contract.
State
A contract's stored values at a point in time.

Model

  1. Own code — inspectable, versioned, auditable

  2. Called contracts — visible in the code, risk of their own

  3. Oracle data — not in the code, determine the outcome

  4. Retained rights — not in the code, determine the rules

What a contract depends on — Only the first two levels are fully shown by a code audit.

Worked example

A liquidation nobody triggered

Price according to the oracle
USD 1,800
Price at liquid venues
USD 1,950
Liquidation threshold
USD 1,850

The contract works with USD 1,800 because that is the value inside it. As far as the contract is concerned, the fact that USD 1,950 is traded elsewhere does not exist.

The position is liquidated.

Reading: It was not the market that liquidated, it was the data source. Whoever held the position was exposed to the oracle, not to the price.

Retrieval

How does a smart contract know an asset's price?

Exercise on real data

Open a market in the Explorer and look at the dependency chain shown. For each link ask: would a failure here be visible to me before it takes effect?

Inspect a market's dependency chain →

Application

A provider advertises that its protocol is “fully audited”. Which risks does that statement not cover?

Related case studies

Institutional reading

Bank
Which of these dependencies would internal standards require to be documented?
Insurance
Which of the four levels could be formulated in an insurable way at all?

Key takeaways

Evidence