DeFi protocols must move beyond “patch-after-the-hack” security and hard-code safety guarantees into their software if the $168 billion sector is to mature, accordingDeFi protocols must move beyond “patch-after-the-hack” security and hard-code safety guarantees into their software if the $168 billion sector is to mature, according

A16z Crypto wants DeFi to ditch ‘code is law’ for ‘spec is law’ to combat $649m exploit problem

2026/01/20 02:13
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

DeFi protocols must move beyond “patch-after-the-hack” security and hard-code safety guarantees into their software if the $168 billion sector is to mature, according to a16z Crypto.

In a January 11 post, Daejun Park, a senior security researcher at the firm, argued that DeFi developers should adopt a more principled approach to security instead of relying on trial and error.

At the core of that shift, Park said, is the use of standardised specifications that constrain what a protocol is allowed to do, and automatically revert any transaction that violates those predefined assumptions about correct behaviour.

“Almost every exploit to date would have tripped one of these checks during execution, potentially halting the hack,” Park said. “So the once-popular idea of ‘code is law’ evolves into ‘spec is law.’”

Such an idea, sometimes referred to as runtime enforcement or invariant checks, isn’t new. But it’s getting a fresh look as DeFi protocols struggle to defend against hackers exploiting bugs in their code.

Last year, hackers swiped over $649 million through code exploits according to a report from Slowmist, a blockchain security firm.

Even battle-tested protocols like Balancer, whose code had been live on the Ethereum blockchain since 2021, were not immune. It lost $128 million in November after a hacker exploited a code bug.

In recent months, DeFi developers fear hackers are increasingly using artificial intelligence to find DeFi protocol vulnerabilities and exploit them.

‘Not the silver bullet’

Park’s suggestions, if widely adopted, could go a long way in preventing exploits. But they’re not without downsides.

DeFi protocols often gain an edge over their competitors by having the cheapest fees. Adding extra checks on transactions would increase gas costs, potentially losing them users, Gonçalo Magalhães, head of security at Immunefi, told DL News.

Magalhães said invariant checks are a great security strategy, but they can’t account for everything — especially exploits that a protocol’s developers can’t reasonably anticipate. “It’s not the silver bullet,” he said.

It’s also tricky to get the checks to work properly, Felix Wilhelm, co-founder of Asymmetric Research, a crypto security firm, told DL News.

“For many vulnerabilities and real-life hacks, it is difficult or even impossible to write an invariant that detects the hack without also triggering under normal circumstances,” he said.

Wilhelm said runtime enforcement is an important part of protocol security. But it is typically used to detect anomalies, like an unusual flow of funds in a short timeframe.

“While helpful, this often serves only to limit impact or alert the team, rather than stopping the attack outright,” he said.

Many protocols are already adopting invariant checks.

Kamino, a Solana-based lending protocol, began checking for critical invariants using Certora Prover in March last year.

The XRP Ledger, the blockchain behind the $120 billion XRP token, has also implemented invariant checking. The blockchain’s developers said the checks are necessary because XRP Ledger is complicated, and there is a high potential for code to execute incorrectly.

“Invariants should not trigger, but they ensure the XRP Ledger’s integrity from bugs yet to be discovered or even created,” XRP Ledger developers said.

Tim Craig is DL News’ Edinburgh-based DeFi Correspondent. Reach out with tips at [email protected].

Market Opportunity
DeFi Logo
DeFi Price(DEFI)
$0,000337
$0,000337$0,000337
+9,41%
USD
DeFi (DEFI) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Today’s Biggest Crypto Movers: Dogecoin Leads the Pack

Today’s Biggest Crypto Movers: Dogecoin Leads the Pack

Today's Biggest Crypto Movers: Dogecoin Leads the Pack 🚀 Crypto Markets Heat Up Today Major cryptocurrencies are showing strong gains. Let's dive into today's top
Share
Blockchainmagazine2026/04/03 13:00
RWA Boom Accelerates As Tokenized Assets Hit New Highs In Early 2026

RWA Boom Accelerates As Tokenized Assets Hit New Highs In Early 2026

RWA distributed value rose from about $21B to $27.5B in Q1 2026, a gain of roughly 30%. Tokenized US Treasuries reached about $10B, creating an on-chain yield base
Share
LiveBitcoinNews2026/04/03 13:00
Cryptos Signal Divergence Ahead of Fed Rate Decision

Cryptos Signal Divergence Ahead of Fed Rate Decision

The post Cryptos Signal Divergence Ahead of Fed Rate Decision appeared on BitcoinEthereumNews.com. Crypto assets send conflicting signals ahead of the Federal Reserve’s September rate decision. On-chain data reveals a clear decrease in Bitcoin and Ethereum flowing into centralized exchanges, but a sharp increase in altcoin inflows. The findings come from a Tuesday report by CryptoQuant, an on-chain data platform. The firm’s data shows a stark divergence in coin volume, which has been observed in movements onto centralized exchanges over the past few weeks. Bitcoin and Ethereum Inflows Drop to Multi-Month Lows Sponsored Sponsored Bitcoin has seen a dramatic drop in exchange inflows, with the 7-day moving average plummeting to 25,000 BTC, its lowest level in over a year. The average deposit per transaction has fallen to 0.57 BTC as of September. This suggests that smaller retail investors, rather than large-scale whales, are responsible for the recent cash-outs. Ethereum is showing a similar trend, with its daily exchange inflows decreasing to a two-month low. CryptoQuant reported that the 7-day moving average for ETH deposits on exchanges is around 783,000 ETH, the lowest in two months. Other Altcoins See Renewed Selling Pressure In contrast, other altcoin deposit activity on exchanges has surged. The number of altcoin deposit transactions on centralized exchanges was quite steady in May and June of this year, maintaining a 7-day moving average of about 20,000 to 30,000. Recently, however, that figure has jumped to 55,000 transactions. Altcoins: Exchange Inflow Transaction Count. Source: CryptoQuant CryptoQuant projects that altcoins, given their increased inflow activity, could face relatively higher selling pressure compared to BTC and ETH. Meanwhile, the balance of stablecoins on exchanges—a key indicator of potential buying pressure—has increased significantly. The report notes that the exchange USDT balance, around $273 million in April, grew to $379 million by August 31, marking a new yearly high. CryptoQuant interprets this surge as a reflection of…
Share
BitcoinEthereumNews2025/09/18 01:01

Trade GOLD, Share 1,000,000 USDT

Trade GOLD, Share 1,000,000 USDTTrade GOLD, Share 1,000,000 USDT

0 fees, up to 1,000x leverage, deep liquidity