MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: A16z Crypto wants DeFi to ditch ‘code is law’ for ‘spec is law’ to combat $649m exploit problem
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$67,929.00-2.94%
  • ethereumEthereum(ETH)$2,048.08-3.34%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$620.29-2.05%
  • rippleXRP(XRP)$1.35-2.29%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.04-4.22%
  • tronTRON(TRX)$0.3157690.30%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-0.55%
  • dogecoinDogecoin(DOGE)$0.091778-0.53%
Blockchain

A16z Crypto wants DeFi to ditch ‘code is law’ for ‘spec is law’ to combat $649m exploit problem

Last updated: January 20, 2026 12:35 am
Published: 2 months ago
Share

Many protocols are already adopting so-called invariant checks.

DeFi protocols must move beyond “patch-after-the-hack” security and hard-code safety guarantees into their software if the $168 billion sector is to mature, according to a16z Crypto.

In a January 11 post, Daejun Park, a senior security researcher at the firm, argued that DeFi developers should adopt a more principled approach to security instead of relying on trial and error.

At the core of that shift, Park said, is the use of standardised specifications that constrain what a protocol is allowed to do, and automatically revert any transaction that violates those predefined assumptions about correct behaviour.

“Almost every exploit to date would have tripped one of these checks during execution, potentially halting the hack,” Park said. “So the once-popular idea of ‘code is law’ evolves into ‘spec is law.'”

Such an idea, sometimes referred to as runtime enforcement or invariant checks, isn’t new. But it’s getting a fresh look as DeFi protocols struggle to defend against hackers exploiting bugs in their code.

Last year, hackers swiped over $649 million through code exploits according to a report from Slowmist, a blockchain security firm.

Even battle-tested protocols like Balancer, whose code had been live on the Ethereum blockchain since 2021, were not immune. It lost $128 million in November after a hacker exploited a code bug.

In recent months, DeFi developers fear hackers are increasingly using artificial intelligence to find DeFi protocol vulnerabilities and exploit them.

Park’s suggestions, if widely adopted, could go a long way in preventing exploits. But they’re not without downsides.

DeFi protocols often gain an edge over their competitors by having the cheapest fees. Adding extra checks on transactions would increase gas costs, potentially losing them users, Gonçalo Magalhães, head of security at Immunefi, told DL News.

Magalhães said invariant checks are a great security strategy, but they can’t account for everything — especially exploits that a protocol’s developers can’t reasonably anticipate. “It’s not the silver bullet,” he said.

It’s also tricky to get the checks to work properly, Felix Wilhelm, co-founder of Asymmetric Research, a crypto security firm, told DL News.

“For many vulnerabilities and real-life hacks, it is difficult or even impossible to write an invariant that detects the hack without also triggering under normal circumstances,” he said.

Wilhelm said runtime enforcement is an important part of protocol security. But it is typically used to detect anomalies, like an unusual flow of funds in a short timeframe.

“While helpful, this often serves only to limit impact or alert the team, rather than stopping the attack outright,” he said.

Many protocols are already adopting invariant checks.

Kamino, a Solana-based lending protocol, began checking for critical invariants using Certora Prover in March last year.

The XRP Ledger, the blockchain behind the $120 billion XRP token, has also implemented invariant checking. The blockchain’s developers said the checks are necessary because XRP Ledger is complicated, and there is a high potential for code to execute incorrectly.

“Invariants should not trigger, but they ensure the XRP Ledger’s integrity from bugs yet to be discovered or even created,” XRP Ledger developers said.

Read more on DL News

This news is powered by DL News DL News

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

8 Coins Heating Up Right Now: Apeing Steals the Best Crypto to Watch Now Spotlight Before Traders React
Sumsub Partners with Fireblocks To Power the Digital Asset Economy with Seamless Travel Rule Compliance
ServiceNow Acquires Armis for $7.75B Cybersecurity Deal – News Directory 3
Ripple Expands To Bahrain Through Strategic Partnership With Bahrain Fintech Bay – FinanceFeeds
BlackRock Buys 31,470 ETH Worth $140.9M in Latest Accumulation

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article The Government of Bermuda Announces Plans to be the World’s First Fully Onchain National Economy with Support from Circle and Coinbase
Next Article How Has Civil Unrest in Iran Affected UK Cyber ​​Security?
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d