What a smart contract is
What makes it different from ordinary software
Three properties, and each has a cost attached.
It is deterministic
The same input always produces the same output, on every machine running the network. This is what allows thousands of independent participants to agree on the result without trusting each other.
It is immutable
Once deployed, the code cannot be edited. A bug is permanent, and fixing it means deploying a new contract and persuading everyone to move to it.
It executes automatically
No intermediary decides whether the conditions were met. If the code says the funds release, they release.
Why that cuts both ways
That last property is the appeal and the danger in the same sentence. There is nobody to appeal to when the code does what it says rather than what was intended.
An example you already use
USDT is a smart contract. So is USDC, and so is every token that is not a network’s own coin.
The contract maintains a ledger of who holds how much and rules for transferring between them. When you send USDT, you are calling a function on that contract, which is why the transfer costs more gas than sending the network’s native coin: the contract has to run.
It also explains why the same token behaves as a separate asset on each network. There is one contract on Ethereum, another on TRON, another on Solana, and they have no knowledge of each other. This is the mechanism behind the network boundary that loses funds when somebody sends across it.
What it is not, and where it fails
What a smart contract is not
Not a legal contract. The name is unfortunate and causes real confusion.
A legal agreement is enforceable through courts and can be interpreted, disputed and set aside. A smart contract executes. It has no concept of intent, fairness or exceptional circumstances, and no judge can reverse a transaction it performed correctly.
Some arrangements pair the two, with a legal document governing the relationship and code handling the mechanics. That combination works. Treating the code as the legal instrument does not.
Where the risk sits
In the code, and the record is not reassuring.
Bugs in deployed contracts have cost billions of dollars, and the immutability that makes contracts trustworthy also makes their mistakes permanent. Bridges between networks have been the most attacked category of all, for the straightforward reason that they hold large balances behind complex code.
Audits reduce the risk without removing it. An audited contract has been reviewed by people looking for problems, which is better than nothing and considerably less than a guarantee.
Relevance to accepting payments
Less than you might expect, and that is worth knowing.
A payment gateway receiving a simple transfer involves no contract of its own. The customer sends, the network records, the merchant is credited. Where contracts appear is in the tokens themselves, which is unavoidable and well tested at this point.
More elaborate arrangements exist, with payments held in escrow by contract code until conditions are met. These solve real problems and add the risk described above, and most businesses accepting crypto have no reason to touch them.