Reviewed Aug 2026
DE
DA-01 · LESSON 07

External trust and availability

KEY DEFINITIONS

Terms used in this lesson

Guardian
A Ducat policy-checking signer that can authorize or reject defined protocol transactions.
Oracle
A system that reports outside information, such as a market price, for use by a protocol.
Validator
Software or a participant that independently checks state transitions under a system's rules. The exact role depends on the protocol being discussed.
Preimage
The original secret data whose hash equals a previously committed value.

Guardians, oracles, validators, relays, clients, and operators remain explicit honesty or liveness dependencies even where Bitcoin constrains the final spend.

55 min Difficulty 4/5 Not started

Loading lesson visuals...

01

Learn the idea

Honesty means an actor follows the required rule. Liveness means the actor remains available in time. Safety means a failure does not authorize a forbidden loss or inconsistent state. Visibility means evidence exposes what happened, even when it cannot prevent or repair the failure. Ducat can constrain actions with Bitcoin while still depending on Guardians, oracle workflows, relays, clients, validators, and operators.

GUIDED EXPLANATION1/4 ideas inspected
1

Model safety

Ask whether a dishonest actor or colluding threshold can authorize a loss, publish false data, or cause participants to reconstruct incompatible state.

Inspect each idea before the worked example.
The worked example follows the explanation

Inspect every idea above to open it.

Important distinctionIf funds are locked in Bitcoin, external downtime can only delay the web interface.

A required signer, oracle preimage, data path, or fee path can block an on-chain transition even when Bitcoin itself is operating normally.

02
FINISH LEARNING FIRST

The questions unlock after every required learning activity

Inspect every guided idea, open the worked example, rebuild its mechanism, and complete the deterministic lesson tool. Your progress is saved automatically.