Risks in Crypto
A contract cannot tell that its rule is wrong. It runs it anyway.
Smart contracts replace part of human trust with code. Code is not automatically free of faults — and the automation that makes a contract useful carries out a faulty rule exactly as faithfully as a correct one.
The problem
One contract, two branches. Press the safe one first.
This contract holds balances for four wallets. Its two rules were written by people, and one of the two conditions is wrong. Nothing in the system knows that.
Contract · deployed
IDLETwo branches. One handles a deposit, one handles a withdrawal. Each fires the moment its own condition is satisfied, with nobody standing in between.
Nothing has run yet. Press Deposit and watch the contract work correctly.
Automation is the whole point of a smart contract: the rules execute without anyone having to agree, approve or step in. That is exactly why a mistake in the rules is dangerous. The contract checked the condition it was given, found it satisfied, and carried out the wrong action with the same speed and certainty as the right one — for every balance it held, in one go. A small programming error is enough, and there is no point in the sequence where anything notices.
Contracts are often published unchangeable. That is deliberate, and it is what makes the rules dependable — nobody can quietly rewrite them afterwards. The same property is the third source of risk: a fault discovered later cannot simply be edited out. Where a stop or an upgrade path was designed in beforehand, it can limit what happens next; whatever already executed has already settled. Which is why the first two sources matter as much as they do — the cheapest place to catch a fault is before the contract is deployed at all.
The definition
Three things “it runs on-chain” does not mean.
Tap each card for what is actually being claimed — and what is not.
Hands on
Automated code becomes a risk on three routes.
Five situations, three risk sources. Tap each situation and place it.
Pick a situation
—Each of the five belongs to exactly one of three sources: a bug in the logic, an external dependency, or the fact that a live contract is hard to correct.
The bridge
What raises the risk, what lowers it, and what settles it.
Five statements, in order. Only the last one is unconditional.
That is the honest shape of it. Capital at stake raises what a fault costs; complexity and dependencies raise the chance of one; audits, tests and transparent architecture lower the risk — and none of it is a guarantee. Security is not something a contract inherits from the chain it runs on. When weaknesses like these are actively exploited rather than merely present, that has its own name and its own lesson: hacks, which is where the section goes next.
Check yourself
Five questions.
Answers come straight from this lesson. Submitting completes it.