DeFi urged to hard-code ‘spec is law.’ with invariant checks

  • DeFi security should shift from reactive patches to built-in safety rules that block invalid transactions.
  • Daejun Park of a16z proposed using standardised specifications or invariant checks to enforce correct protocol behaviour.
  • Many recent hacks could have been halted by such runtime checks; the sector lost large sums last year.
  • Experts warn invariant checks raise costs and can be hard to design without false positives or missed attacks.
  • Some projects, including Kamino and the XRP Ledger, already use invariant checking tools and practices.

Daejun Park, a senior security researcher at a16z, said in a January 11 post that decentralized finance must embed safety guarantees into protocol code to mature. He argued developers should adopt standardised specifications that constrain allowed actions and automatically revert transactions that violate assumptions. “Almost every exploit to date would have tripped one of these checks during execution, potentially halting the hack,” he wrote, adding that “So the once-popular idea of ‘code is law’ evolves into ‘spec is law.'”

- Advertisement -

The push for runtime enforcement, also called invariant checks, comes as DeFi sustained heavy losses to code exploits last year. A security report found attackers stole more than $649 million, and even established systems like Balancer lost about $128 million in November after a bug. The sector overall is valued at roughly $168 billion.

Experts caution that invariant checks are not a cure-all. Gonçalo Magalhães, head of security at Immunefi, said the added checks would raise gas costs and could cost protocols users who compete on low fees, adding “It’s not the silver bullet.” Felix Wilhelm, co-founder of Asymmetric Research, noted design challenges: “For many vulnerabilities and real-life hacks, it is difficult or even impossible to write an invariant that detects the hack without also triggering under normal circumstances.” He added that runtime enforcement often detects anomalies or limits damage rather than fully stopping attacks: “While helpful, this often serves only to limit impact or alert the team, rather than stopping the attack outright.”

Some projects are adopting these measures. Kamino, a Solana lending protocol, began checking critical invariants with Certora Prover in March. The XRP Ledger, which underpins the $120 billion XRP token ecosystem, has implemented invariant checking and explains the approach in its documentation. A wider industry report on last year’s breaches is available from SlowMist.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -

Latest News

SEC Drops Gemini Suit After $40M Push to Restore Earn Today!

SEC civil suit against Gemini Trust Company and Genesis Global Capital dismissed with prejudice...

DeFi surge, three hacks and MEV bot returns majority funds!!

Three separate DeFi attacks this week drained millions and prompted on-chain recovery efforts.Makina reported...

BitGo shares tumble 22% after $212M IPO; dip below $15 at 2B

BitGo shares fell nearly 22% on the second trading day after its IPO debut...

Intel Slides 17% After Q1 Guidance Miss; Supply Constraints.

INTC shares fell more than 17% on Friday after a quarterly report and weak...

Gold’s FOMO Drains Bitcoin: Prices Falling, Metals Rise Soon

The author argues that Bitcoin prices are likely to weaken because fewer groups need...
- Advertisement -

Must Read

9 Best Trading Platforms for Crypto Beginners

Many newcomers to the crypto space are looking for platforms to buy, sell and exchange cryptocurrencies. While there are hundreds of crypto exchanges around...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!