Skip to content
Basis Desk
Tech & Protocols · 5 min read Last reviewed September 28, 2026

What Are Smart Contracts? The Architecture of On-Chain Code

An engineering and market-focused guide to how self-executing code runs on decentralized networks, exploring gas mechanics, immutability, and the risks of smart contract vulnerabilities.

Neutral

Key points

  • Smart contracts are self-executing programs stored on a blockchain that run automatically when predetermined conditions are met.
  • Gas is the computational unit used to measure and pay for the resources required to execute smart contract operations on a network.
  • Once deployed, smart contract code is immutable, requiring developers to use proxy patterns if they need to upgrade logic.
  • Smart contracts cannot natively access external real-world data and must rely on decentralized oracle networks to import off-chain information.

A smart contract is a self-executing computer program that runs on a decentralized blockchain network. Unlike traditional software that runs on a centralized server controlled by a single entity, these programs execute automatically once predefined conditions are met, with the results permanently recorded on a shared ledger 1. By eliminating the need for intermediaries to enforce agreements, smart contracts serve as the foundational building blocks for decentralized finance, digital assets, and automated market protocols 1.

The Mechanics of On-Chain Execution

To understand how a smart contract functions, it is helpful to view a blockchain not merely as a ledger of transactions, but as a distributed state machine. In the case of Ethereum, this environment is the Ethereum Virtual Machine (EVM), a sandboxed runtime environment that executes contract bytecode 2.

When a developer writes a smart contract, they typically use a high-level programming language such as Solidity or Vyper 2. This code is then compiled into low-level bytecode—a series of hexadecimal instructions—and deployed to the blockchain via a transaction 2. Once deployed, the contract is assigned a unique address.

Unlike traditional applications, a smart contract cannot run continuously in the background or initiate its own execution. It remains dormant until a user or another contract sends a transaction to its address, invoking one of its compiled functions 2. This invocation triggers the nodes on the network to execute the code, update the state of the blockchain, and reach a consensus on the new state 1.

Gas and the Cost of Computation

Because network resources are finite, blockchains charge a fee to execute smart contracts to prevent spam and allocate computational capacity. This mechanism is known as gas 3.

Every low-level instruction in a smart contract's bytecode has a fixed cost measured in gas units, which reflects the computational effort required to execute it 3. For example, adding two numbers together requires very little gas, while writing a new piece of data to the blockchain's storage requires significantly more 3.

To calculate the transaction fee, the network uses the following formula:

$$\text{Transaction Fee} = \text{Gas Used} \times \text{Gas Price}$$

Suppose a user interacts with a smart contract, and the execution of the requested function consumes exactly 50,000 units of gas. If the prevailing market price of gas on the network is 20 gwei (where 1 gwei is $10^{-9}$ of the native token, $ETH$), the transaction fee is calculated as:

$$50,000 \times (20 \times 10^{-9}\text{ ETH}) = 0.001\text{ ETH}$$

If the user is executing a simple transfer of native ETH, the network protocol dictates this requires exactly 21,000 units of gas 3. However, interacting with complex smart contracts that manage decentralized exchanges or lending pools can easily consume hundreds of thousands of gas units. Users must specify a "gas limit" when submitting a transaction—the maximum amount of gas they are willing to consume. If the contract execution runs out of gas before completion, the transaction is reverted, the state changes are rolled back, but the user still forfeits the gas consumed up to that point to compensate the network validators for their computational work 3.

Immutability vs. Upgradeability

One of the defining characteristics of a smart contract is immutability 1. Once deployed to a blockchain, the code of a specific contract address cannot be altered, deleted, or patched 1. This ensures that the rules of the contract are predictable and cannot be unilaterally changed by any party, including the original creator.

While immutability provides security and trust, it presents a significant engineering challenge: if a developer discovers a critical bug or vulnerability in a deployed contract, they cannot simply upload a patch to the same address. To balance security with the need for software maintenance, developers utilize specific design patterns to achieve upgradeability:

  • Proxy Contracts: This pattern separates the contract's storage and state from its business logic. A user interacts with a "proxy" contract, which holds the state and delegates all code execution to an "implementation" contract. To upgrade the system, the administrator deploys a new implementation contract and updates the proxy to point to the new address, while the historical state remains intact.
  • Multi-Signature Governance: To prevent a single developer from abusing proxy contracts to alter the rules maliciously, the authority to point a proxy to a new implementation is often restricted to a multi-signature wallet or a decentralized autonomous organization (DAO) governed by token holders.

Common Failure Modes and Vulnerabilities

Because smart contracts often manage substantial financial assets directly, they are high-value targets for exploits. Unlike traditional web applications where a database breach can be mitigated by restoring backups, smart contract exploits result in irreversible asset transfers. Common vulnerabilities include:

  • Reentrancy Attacks: This occurs when a contract sends funds to an untrusted external contract before updating its own internal balance state. The receiving contract can recursively call the withdrawal function again before the first invocation finishes, draining the contract's funds.
  • Oracle Failures: Many smart contracts rely on external data feeds, known as oracles, to determine asset prices or real-world outcomes 4. If an attacker manipulates the external market that the oracle tracks, or if the oracle itself fails to report accurate data, the dependent smart contract may execute incorrect financial transactions automatically.
  • Integer Underflow and Overflow: In older programming languages, if an arithmetic operation exceeded the maximum or minimum size of a variable type, the value would wrap around, leading to unintended balances. Modern compiler versions have largely mitigated this specific issue, but legacy contracts remain exposed.

Common Misconceptions

  • Smart contracts are legally binding agreements. Despite the name, a smart contract is not inherently a legal contract in the eyes of regulatory bodies like the SEC or the UK Financial Conduct Authority (FCA). It is a technical mechanism for executing code. While parties can agree to use a smart contract to execute terms of a legal agreement, the code itself is not a substitute for legal compliance, and local jurisdictions vary on how they interpret on-chain actions.
  • Smart contracts can access real-world data directly. Blockchains are isolated, deterministic systems. A smart contract cannot query an external API or website directly to check the price of an asset or the weather. It must rely on specialized middleware called oracles to push that data onto the blockchain ledger first 4.
  • Smart contracts are completely secure because the blockchain is secure. While the underlying blockchain protocol may be highly secure and resistant to double-spending, the smart contracts running on top of it are only as secure as the code written by the developers. A bug in a smart contract can be exploited even if the underlying blockchain functions perfectly.

How This Connects to the Market

The utility of smart contracts directly influences the market dynamics of layer-1 and layer-2 networks. The demand for native tokens like $ETH, $SOL, or $AVAX is driven in large part by the need to pay for gas to execute these contracts. As decentralized applications grow in complexity and user adoption increases, the demand for block space rises, which can lead to higher transaction fees and influence the tokenomics of the underlying network. Understanding the mechanics, limitations, and risks of smart contracts is essential for evaluating the fundamental value of blockchain platforms and the protocols built upon them.

Questions this story raises

Can a smart contract be stopped or deleted once it is deployed?
Generally, no. Because of blockchain immutability, deployed smart contract code cannot be deleted. However, some contracts are programmed with a 'self-destruct' function that disables the contract and forwards remaining funds to a designated address, or they use proxy patterns to redirect users to a new version.
What happens if there is a bug in a smart contract?
If a bug is present, anyone can exploit it if they find it first. Because transactions are irreversible, lost funds usually cannot be recovered unless the network validators collectively agree to roll back the entire blockchain state, which is extremely rare and controversial.
Do smart contracts run on Bitcoin?
Bitcoin supports basic scripting capabilities for transactions, such as multi-signature requirements or timelocks. However, it is not Turing-complete and does not support the complex, stateful smart contracts found on platforms like Ethereum or Solana.

References

  1. [1] Oracles — Ethereum Foundation
  2. [2] Ethereum Virtual Machine (EVM) — Ethereum Foundation
  3. [3] Gas and Fees — Ethereum Foundation
  4. [4] Introduction to Smart Contracts — Ethereum Foundation

Evergreen explainer written by Basis Desk's system and checked by an independent model pass for factual errors and advice language. Figures, fees and rules change — the references above are where to verify current specifics. Market figures marked "at the time of writing" come from live exchange data. Report an error: hello@basisdesk.news.

Not financial advice. Basis Desk publishes information, not recommendations. Crypto assets are volatile and you can lose what you invest.