A smart contract is a program stored on a blockchain that runs automatically when its conditions are met, with no company, server, or person administering it. In 1994, Nick Szabo coined the term, two decades before Ethereum made it practical in 2015. Every decentralized exchange, lending protocol, and stablecoin is a smart contract or a set of them, and DefiLlama's hack tracker records $7.6 billion in cumulative losses from the ones that failed.
What "smart contract" actually means
Neither smart nor a contract, in the ordinary sense of either word.
Code, in other words. Once written and deployed to a blockchain, it does exactly what the code says whenever someone interacts with it. No judgment, no discretion, no interpretation. If the code says send 100 tokens when condition X is true, that is what happens, whether or not anyone intended it.
From the original idea, agreements that enforce themselves, comes the "contract" framing. As the classic analogy, a vending machine holds up. Insert the coin, receive the item, no cashier required.
How a smart contract works
Four steps.
- A developer writes the contract, usually in a language like Solidity for Ethereum-compatible chains.
- The contract is deployed to the blockchain, where it receives an address and becomes permanent.
- Users send transactions to that address, calling the contract's functions.
- Every node on the network executes the same code and reaches the same result, which is what makes the outcome trustworthy.
That fourth step is the important one. The contract does not run on a company's server. It runs on every computer in the network simultaneously, and they all have to agree.
The trust problem self-executing code solves
Trust between strangers.
For ordinary agreements, an enforcer is needed: a court, a bank, an escrow agent. Costing money and taking time, that enforcer can also fail or be corrupted.
With code, a smart contract replaces the enforcer. Because neither is trusting the other, two parties who do not trust each other can transact. What both trust is that the code does what it says, which anyone can verify by reading it.
Inflexibility is the cost. When circumstances change, code cannot exercise judgment. Just as reliably as the intended behavior, a mistake in the code is enforced.
Common uses, from token issuance to bridges
| Use | How the contract works | Examples |
|---|---|---|
| Token issuance | Defines supply, transfers, and balances | USDT, USDC, most tokens |
| Decentralized exchanges | Prices swaps against pooled reserves using a formula | Uniswap, Curve |
| Lending | Holds collateral, issues loans, liquidates automatically | Aave, Morpho |
| Stablecoins | Mints and burns tokens against collateral | DAI |
| NFTs | Records ownership of unique items | Collections on Ethereum and Solana |
| Bridges | Locks assets on one chain, mints on another | Cross-chain infrastructure |
Bugs, oracles, and other ways contracts fail
Honestly, since the failures are as instructive as the successes.
Bugs. Code does what it says, including when what it says is wrong. The most expensive smart contract failures have been ordinary programming errors that attackers found before developers did.
Oracle dependence. Contracts cannot see the outside world. They rely on external data feeds for prices, and a manipulated feed produces wrongful liquidations or drained pools.
Upgrade keys. Many contracts can be changed by whoever holds an administrator key, which means the "no one controls it" property depends on who holds that key.
Immutability cuts both ways. A deployed contract with a flaw cannot be patched unless upgrade functions were built in. If they were not, the flaw is permanent.
Infrastructure failure. Kelp DAO lost roughly $292 million in April 2026 without any flaw in its contract code. Attackers compromised the infrastructure feeding data to the contract, which then did exactly what it was told.
Audits, and what they do and do not prove
An audit is a review of contract code by a security firm, checking for known vulnerability patterns.
Risk is reduced by audits, not eliminated. Repeatedly, audited contracts have been drained, because auditors look for known problems and attackers look for unknown ones. With three audits and a year in production, a contract is a better bet than one with none, and it remains a bet.
Check who conducted the audit, when, and whether the code has changed since. Then check whether the audit report is published by the auditor or only summarised by the project.
Where mb.io fits
Removing the intermediary, smart contracts remove everything the intermediary provides, including recourse when something breaks.
mb.io takes the regulated route, with an intermediary that can be held accountable by a licensing authority.
mb.io is a regulated crypto spot exchange backed by MultiBank Group, a financial institution founded in 2005 that serves more than 2 million clients across 100+ countries.
- Regulated by VARA in the UAE and AUSTRAC in Australia
- 10/10 security score from Hacken, an independent blockchain security auditor
- Institutional-grade MPC custody powered by Fireblocks, with segregated client funds
- A curated list of assets, so you're not sorting through thousands of tokens to find the ones worth trading
- Buy, sell, and swap in three steps, from sign-up to purchase
- 24/7 multilingual client support
Open your account and start trading on mb.io.
Frequently asked questions
What is a smart contract in simple terms?
A program stored on a blockchain that runs automatically when its conditions are met, with no person or company operating it. A vending machine is the standard analogy.
Who invented smart contracts?
In 1994, Nick Szabo coined the term. Launched in July 2015, Ethereum was the first blockchain to make general-purpose smart contracts practical.
Are smart contracts legally binding?
Not automatically. They enforce themselves technically, but their legal status depends on jurisdiction and on whether the parties intended a legal agreement. Some jurisdictions have passed laws recognizing them.
Can a smart contract be changed?
Only if it was built with upgrade functions, in which case whoever holds the administrator key can change it. Contracts without those functions are permanent, flaws included.
Which blockchains support smart contracts?
Ethereum and every EVM-compatible network, including Arbitrum, Base, Polygon, BNB Chain, and Avalanche. Solana, Cardano, and others use their own contract systems. Bitcoin's scripting is deliberately limited.
Why do smart contracts get hacked?
Including when what it says is wrong, code does what it says. Attackers find programming errors, manipulate the external data feeds contracts rely on, or compromise the infrastructure around them.
Does an audit make a smart contract safe?
Safer, not safe. Audits check for known vulnerability patterns. Audited contracts have been drained repeatedly, and Kelp DAO lost roughly $292 million in 2026 through infrastructure rather than code.
What language are smart contracts written in?
For Ethereum-compatible chains, Solidity is the most common. On Solana, Rust. Others include Vyper and Move. The language matters less than whether the code has been reviewed and tested.

