DeFi urged to hard-code ‘spec is law.’ with invariant checks

  • DeFi security should shift from reactive patches to built-in safety rules that block invalid transactions.
  • Daejun Park of a16z proposed using standardised specifications or invariant checks to enforce correct protocol behaviour.
  • Many recent hacks could have been halted by such runtime checks; the sector lost large sums last year.
  • Experts warn invariant checks raise costs and can be hard to design without false positives or missed attacks.
  • Some projects, including Kamino and the XRP Ledger, already use invariant checking tools and practices.

Daejun Park, a senior security researcher at a16z, said in a January 11 post that decentralized finance must embed safety guarantees into protocol code to mature. He argued developers should adopt standardised specifications that constrain allowed actions and automatically revert transactions that violate assumptions. “Almost every exploit to date would have tripped one of these checks during execution, potentially halting the hack,” he wrote, adding that “So the once-popular idea of ‘code is law’ evolves into ‘spec is law.'”

- Advertisement -

The push for runtime enforcement, also called invariant checks, comes as DeFi sustained heavy losses to code exploits last year. A security report found attackers stole more than $649 million, and even established systems like Balancer lost about $128 million in November after a bug. The sector overall is valued at roughly $168 billion.

Experts caution that invariant checks are not a cure-all. Gonçalo Magalhães, head of security at Immunefi, said the added checks would raise gas costs and could cost protocols users who compete on low fees, adding “It’s not the silver bullet.” Felix Wilhelm, co-founder of Asymmetric Research, noted design challenges: “For many vulnerabilities and real-life hacks, it is difficult or even impossible to write an invariant that detects the hack without also triggering under normal circumstances.” He added that runtime enforcement often detects anomalies or limits damage rather than fully stopping attacks: “While helpful, this often serves only to limit impact or alert the team, rather than stopping the attack outright.”

Some projects are adopting these measures. Kamino, a Solana lending protocol, began checking critical invariants with Certora Prover in March. The XRP Ledger, which underpins the $120 billion XRP token ecosystem, has implemented invariant checking and explains the approach in its documentation. A wider industry report on last year’s breaches is available from SlowMist.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -

Latest News

Investors Sue Kalshi Over Iran Leader Bet Resolution

Prediction market platform Kalshi is facing a class action lawsuit in California for its...

Meta Eyes Texas Data Center Site After OpenAI, Oracle Split

The collapse of a major AI data center expansion deal between Oracle and OpenAI...

Former CFO Gets Two Years for $35M Crypto Theft

A Seattle judge sentenced former CFO Nevin Shetty to two years in prison for...

Microsoft Stock Rises on OpenAI Partnership News

Microsoft's partnership with OpenAI has evolved from a 2019 research effort to a major...

Binance Denies $1.7 Billion Iran Sanctions Violations

Binance has firmly denied a U.S. Senator's allegations that it facilitated over $1.7 billion...

Must Read

What Are Sniper Bots Used in Defi Trading?

You've heard about DeFi, but what about sniper bots? These high-speed trading tools are shaking up the crypto scene.But don't fret, you're not...