Course 12 - Blockchain Security Fundamentals
A blockchain is a distributed ledger — a record of transactions copied across many computers, where each new block of data is cryptographically linked to the one before it. Northwind's supply-chain team is evaluating a blockchain-based system to track shipments between warehouses.
*Important: being a blockchain does not automatically make a system confidential, correct, or trustworthy. Blockchains are good at making tampering with already-recorded data difficult to hide. They do nothing on their own to guarantee that the data entered was accurate in the first place, or that the software built on top of them is bug-free.
A smart contract is code that runs automatically on a blockchain when certain conditions are met. Because deployed smart contracts are often very difficult or impossible to change afterward, a bug found after launch can be permanent and, in some cases, directly exploitable for financial gain. This is why independent security audits before deployment are standard practice, not optional extras.
Access to a blockchain account is controlled by a private key — a piece of secret data that proves ownership. Unlike a forgotten website password, there is usually no "reset my key" option: if a private key is lost or stolen, whatever it controls can be permanently lost or stolen along with it. Key custody — how carefully a private key is generated, stored, and backed up — is often the single biggest security factor in any blockchain system.