# Security against malicious smart contracts

**URL:** <https://forum.scrt.network/t/security-against-malicious-smart-contracts/202>\
**Category:** Secret Contracts and Secret Apps\
**Created:** [August 5, 2018, 6:08pm UTC](https://forum.scrt.network/t/security-against-malicious-smart-contracts/202 "2018-08-05T18:08:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hass](https://avatars.discourse-cdn.com/v4/letter/h/51bf81/32.png) [@Hass](https://forum.scrt.network/u/Hass)\
**Post date:** [August 5, 2018, 6:08pm UTC](https://forum.scrt.network/t/security-against-malicious-smart-contracts/202/1 "2018-08-05T18:08:40Z")

</div>

If smart contracts are kept secret, how does one ensure that the code within these contracts is not malicious?

---

<div class="post-metadata">

**Author:** ![Avret](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.scrt.network/avret/32/603_2.png) [@Avret](https://forum.scrt.network/u/Avret)\
**Post date:** [August 6, 2018, 12:00am UTC](https://forum.scrt.network/t/security-against-malicious-smart-contracts/202/2 "2018-08-06T00:00:54Z")

</div>

Secret smart contracts, in Enigma’s case, refers to the _data_ within the contracts being kept secret. The code in those contracts remains public (at least if implemented naively) and can thus be examined for malicious functionality. (in other words, Enigma obfuscates data, not program)
