157. Cybersecurity Risks In Smart Contracts

157. Cybersecurity Risks in Smart Contracts – Detailed Explanation With Case Laws

1. Meaning

A smart contract is a computer program that automatically performs an agreement when specified conditions are satisfied.

Simple example:
Suppose an electricity company agrees to pay a solar producer when 1,000 units of electricity are delivered. A smart contract can automatically release payment when the required data is received.

Smart contracts are useful in:

Renewable-energy trading

Electricity payments

Power Purchase Agreements (PPAs)

Carbon-credit transactions

EV charging

Energy certificates

Supply-chain management

But because they depend on computer code and digital networks, they create cybersecurity risks.

2. Major Cybersecurity Risks

A. Hacking

A hacker may attack the smart-contract code and change its operation or steal digital assets.

B. Coding Errors

A small programming mistake can produce a large financial loss because the contract may automatically execute the wrong transaction.

C. Oracle Manipulation

A smart contract often needs outside information called an oracle.

For example:

Smart Contract → Oracle → Electricity-generation data

If someone manipulates the oracle, the smart contract may make an incorrect payment.

D. Private-Key Theft

Digital transactions may depend on cryptographic keys. If a key is stolen, an unauthorised person may control the relevant account or assets.

E. No Easy Cancellation

Traditional contracts can often be stopped through courts or negotiations. A blockchain-based smart contract may execute automatically, making reversal technically difficult.

F. Denial-of-Service Attacks

Attackers may overload a system so that legitimate users cannot access or execute transactions.

3. Legal Problems

Cybersecurity failures can create questions such as:

Who is responsible for the loss?

Is the smart contract legally binding?

Can a court stop automatic execution?

Who bears the risk of faulty code?

Can a transaction be reversed?

What happens when an oracle provides incorrect information?

Which country's law applies to a cross-border blockchain transaction?

Therefore, technical security and legal responsibility must work together.

4. Indian Legal Framework

Information Technology Act, 2000

The IT Act provides a legal framework for electronic records and electronic transactions and addresses certain forms of cyber offences and unauthorised access.

Indian Contract Act, 1872

Traditional contract principles can remain relevant where a smart contract represents an agreement between parties.

Important concepts include:

Offer

Acceptance

Consideration

Consent

Capacity

Breach

Remedies

A computer program does not automatically remove ordinary contractual principles.

Digital Personal Data Protection Act, 2023

Where smart-contract systems process personal data, applicable data-protection obligations can become relevant.

5. Smart Contracts in Energy Law

Smart contracts can be particularly useful in the energy sector.

Example:

Solar panel → Smart meter → Blockchain → Smart contract → Automatic payment

If the meter reports electricity generation, the smart contract may automatically calculate and release payment.

But if the meter is hacked or the data is manipulated, the contract could make an incorrect payment.

Therefore, energy smart contracts need:

Secure software,

reliable data sources,

authentication,

audit trails,

human oversight,

emergency shutdown mechanisms.

6. Important Case Laws

Direct Indian Supreme Court cases specifically dealing with cybersecurity risks in blockchain smart contracts are still very limited. Therefore, related electronic-contract and technology cases are useful.

1. Trimex International FZE Ltd. v. Vedanta Aluminium Ltd. (2010)

The Supreme Court recognised that contractual obligations can arise through electronic communications, depending on the facts.

Importance: It supports the principle that modern electronic methods can create legally significant contractual arrangements.

Smart-contract relevance: A contract implemented through digital technology cannot be dismissed merely because it is electronic.

2. Shakti Bhog Foods Ltd. v. Kola Shipping Ltd. (2009)

The Court considered contractual formation and communications between parties.

Importance: It demonstrates that courts can examine electronic communications to determine whether a binding agreement exists.

Smart-contract relevance: The underlying agreement and parties' intention remain important even when technology is used for execution.

3. State of Tamil Nadu v. Suhas Katti (2004)

This was one of India's early convictions involving cybercrime under the Information Technology Act.

Importance: It demonstrates that cyber activities can have legal consequences under Indian law.

Smart-contract relevance: Hacking, unauthorised access and other cyber offences affecting digital contracts can attract legal consequences.

4. K.S. Puttaswamy v. Union of India (2017)

The Supreme Court recognised privacy as a fundamental right.

Smart-contract relevance: If smart-contract platforms collect personal information, cybersecurity must also protect users' privacy.

5. Internet and Mobile Association of India v. Reserve Bank of India (2020)

The Supreme Court considered RBI's restriction concerning banking services for cryptocurrency-related businesses and applied the principle of proportionality.

Smart-contract relevance: It is useful for understanding judicial treatment of emerging blockchain-related technology and regulatory restrictions, although the case was not directly about smart contracts.

7. How to Reduce Cybersecurity Risks

Smart contracts should include:

Code audits – independent experts check the program.

Multi-factor authentication – additional security for users.

Reliable oracles – trustworthy external data.

Human oversight – important transactions should not always be completely automatic.

Emergency stop mechanism – execution can be suspended during a cyberattack.

Clear contractual clauses – parties should define liability for hacking and coding errors.

Regular security testing – systems should be continuously tested.

8. Conclusion

Smart contracts can make energy transactions faster, cheaper and more automatic, but cybersecurity failures can cause serious financial and legal consequences.

The important principle is:

Smart Contract + Secure Code + Reliable Data + Legal Responsibility + Human Oversight

A smart contract should therefore not be treated as “code without law.” It operates within a legal environment involving contract law, cyber law, data protection and sector-specific regulation.

Exam Line

“Cybersecurity risks in smart contracts arise from hacking, coding errors, oracle manipulation, key theft and automatic execution; therefore, smart contracts require secure technology, clear contractual liability and effective legal oversight.”

LEAVE A COMMENT