Library · Crypto, word by word · Ideas and debates
What does open source mean in crypto?
Open source means a program's code is published for anyone to read, use, copy and modify. Most blockchain software, many wallets and many smart contracts are open source, so anyone can inspect what the code actually does instead of relying on the developer's description.
Where people disagree
Supporters say open code is what makes verification possible: no one has to take a developer's word, anyone can audit or improve the software, and if a project goes wrong others can copy the code and carry on. bitcoin.org notes that anyone in the world can review the Bitcoin code or release a modified version.
Critics say open code also hands attackers a map. The US Treasury's 2023 assessment names open-source smart contract code, together with missing audit requirements and concentrated administrator rights, among the conditions behind thefts from decentralized services, and notes many services lack a quick way to stop an exploit once found.
What it means for you
Open code lets you, or reviewers you rely on, check what a wallet or contract really does, and lets anyone run their own copy of a network's software. It does not mean the code has been reviewed or is free of bugs: published code is also readable by attackers looking for flaws, and a public repository can differ from what an app actually runs.
A common mistake: “Open-source code has been checked by many people, so it's secure.”
In fact: Being public means anyone can review it, not that anyone has. Exploited contracts are often open source; whether code was audited, and by whom, is a separate question.
How it works
bitcoin.org states that the Bitcoin protocol and software 'are published openly' and that any developer can review the code or make a modified version. The practice traces to the cypherpunks: Eric Hughes wrote 'Cypherpunks write code' and 'our code is free for all to use, worldwide'. Openness lets users verify, audit and fork networks. The US Treasury's 2023 assessment lists the availability of open-source smart contract code among the factors behind hacks of decentralized services, alongside missing audit requirements and concentrated administrator rights.
Sources: bitcoin.org: Frequently Asked Questions, Eric Hughes, A Cypherpunk's Manifesto (1993), US Treasury: Illicit Finance Risk Assessment of Decentralized Finance (2023) · checked 4 October 2026
Related words
Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.