HomeNewsDeFi urged to adopt invariant 'spec is law' checks to curb hacks...

DeFi urged to adopt invariant ‘spec is law’ checks to curb hacks as AI aids attackers now.

-

On January 11, Daejun Park of a16z Crypto argued that DeFi protocols must hard-code safety guarantees to reduce hacks. He said standardized specifications should automatically revert transactions that violate protocol assumptions.

Park wrote that many attacks would have been stopped by such checks. “Almost every exploit to date would have tripped one of these checks during execution, potentially halting the hack,” he added and argued that “So the once-popular idea of ‘code is law’ evolves into ‘spec is law.’” (See the full post here.)

Interest in runtime enforcement has risen as exploits continue. A report by Slowmist reported hackers swiped over $649 million through code exploits last year (Ed. note: the total highlights recurring security gaps).

Even established projects proved vulnerable. The protocol Balancer lost about $128 million in November despite code running on Ethereum since 2021.

Security experts note trade-offs. Gonçalo Magalhães of Immunefi said, “It’s not the silver bullet.” He warned that extra checks raise gas costs and may hurt competitiveness.

Researchers also stress limits to invariants. Felix Wilhelm of Asymmetric Research said, “For many vulnerabilities and real-life hacks, it is difficult or even impossible to write an invariant that detects the hack without also triggering under normal circumstances.”

Some projects already use invariant checks. Kamino began such checks with Certora Prover (details), and the XRP Ledger implemented invariant checking with safeguards described here.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST POSTS

Intel stock plunges 11% after Q4 beat but weak Q1 2026 guidance amid supply shortages -11%

Shares of Intel fell after the company released its fourth-quarter 2025 results and its first-quarter 2026 outlook on Thursday. Investors reacted to weaker guidance and...

Shiny Hunters demand ransom from Waltio after breach exposed data of 50k French users now!

French authorities opened a preliminary probe this week after a breach at Waltio. The Paris Public Prosecutor's Office and the country's National Cyber Unit are...

Amazon to cut about 30,000 jobs next week; Jassy cites bloated culture, not AI or demand..

Amazon plans to cut about 30,000 jobs next week, reports say. They may start Tuesday, January 27, and will target retail, AWS, Prime Video, and...

UBS to offer BTC, ETH trading to select Swiss clients; Asia rollout eyed after Swiss pilot

UBS Group AG will allow select private banking clients to trade Bitcoin and Ethereum in Switzerland, a planned rollout that addresses demand from ultra-high-net-worth clients....

Most Popular

spot_img