HomeNewsDeFi urged to adopt invariant 'spec is law' checks to curb hacks...

DeFi urged to adopt invariant ‘spec is law’ checks to curb hacks as AI aids attackers now.

-

On January 11, Daejun Park of a16z Crypto argued that DeFi protocols must hard-code safety guarantees to reduce hacks. He said standardized specifications should automatically revert transactions that violate protocol assumptions.

Park wrote that many attacks would have been stopped by such checks. “Almost every exploit to date would have tripped one of these checks during execution, potentially halting the hack,” he added and argued that “So the once-popular idea of ‘code is law’ evolves into ‘spec is law.’” (See the full post here.)

Interest in runtime enforcement has risen as exploits continue. A report by Slowmist reported hackers swiped over $649 million through code exploits last year (Ed. note: the total highlights recurring security gaps).

Even established projects proved vulnerable. The protocol Balancer lost about $128 million in November despite code running on Ethereum since 2021.

Security experts note trade-offs. Gonçalo Magalhães of Immunefi said, “It’s not the silver bullet.” He warned that extra checks raise gas costs and may hurt competitiveness.

Researchers also stress limits to invariants. Felix Wilhelm of Asymmetric Research said, “For many vulnerabilities and real-life hacks, it is difficult or even impossible to write an invariant that detects the hack without also triggering under normal circumstances.”

Some projects already use invariant checks. Kamino began such checks with Certora Prover (details), and the XRP Ledger implemented invariant checking with safeguards described here.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST POSTS

Binance Finalizes $1B SAFU Fund Conversion to Bitcoin, Now Holds 15K BTC

Binance has completed converting its entire $1 billion user protection fund, the Secure Asset Fund for Users (SAFU), from stablecoins into Bitcoin. The exchange acquired...

Shopify Accepts Dogecoin, DOGE Historical Trends Show January and April Surges

Historical data reveals Dogecoin (DOGE) has demonstrated its strongest price surges during specific months. January holds the record for DOGE's biggest monthly gain, while April...

Robinhood Plunges After Q4 Crypto Miss; Shares Trade Near $71 Amid Split Analyst Calls Now

Robinhood shares fell sharply after the company released fourth-quarter results on February 10. It reported $1.3 billion in revenue and $221 million in crypto sales,...

US Prosecutors Warn Valentine’s Day Brings Surge in Crypto-Fueled Romance Scams

U.S. prosecutors are warning that romance scams increasingly involve cryptocurrency fraud, often orchestrated by organized crime networks. These "pig butchering" schemes involve scammers building trust...

Most Popular

spot_img