a16z crypto urges defi to adopt 'spec is law' for security

a16z Crypto has called for decentralized finance protocols to shift from 'code is law' to 'spec is law' to enhance security amid rising exploits. In a January 11 post, senior researcher Daejun Park advocated for standardised specifications and invariant checks to prevent hacks. This approach aims to mature the $168 billion sector by hard-coding safety guarantees.

Decentralized finance, or DeFi, faces ongoing threats from code exploits, with hackers stealing over $649 million last year, according to blockchain security firm Slowmist. Even established protocols like Balancer, operational on Ethereum since 2021, suffered a $128 million loss in November due to a code vulnerability. Developers are increasingly concerned about hackers leveraging artificial intelligence to identify weaknesses.

In response, a16z Crypto's Daejun Park proposed moving beyond reactive 'patch-after-the-hack' methods. He recommended embedding safety through standardised specifications that limit protocol actions and automatically reverse violating transactions. 'Almost every exploit to date would have tripped one of these checks during execution, potentially halting the hack,' Park wrote. 'So the once-popular idea of “code is law” evolves into “spec is law.”'

This concept, known as runtime enforcement or invariant checks, is gaining traction. Protocols such as Kamino, a Solana-based lending platform, integrated checks using Certora Prover in March 2023. The XRP Ledger, supporting the $120 billion XRP token, has also implemented them to safeguard against undetected bugs. 'Invariants should not trigger, but they ensure the XRP Ledger’s integrity from bugs yet to be discovered or even created,' its developers stated.

However, experts caution that invariant checks are not foolproof. Gonçalo Magalhães, head of security at Immunefi, noted they could raise transaction fees, deterring users in a cost-sensitive market. 'It’s not the silver bullet,' he said. Felix Wilhelm of Asymmetric Research added that crafting effective checks is challenging, as they may falsely trigger during normal operations or fail to stop sophisticated attacks outright. While useful for anomaly detection, such as unusual fund flows, they often mitigate rather than prevent damage.

Park's ideas underscore DeFi's push toward principled security to foster growth, though implementation hurdles remain.

Articoli correlati

U.S. Treasury report illustration showing holographic tech pillars for crypto compliance: AI monitoring, digital ID, blockchain analytics, and data APIs, with privacy mixer endorsement.
Immagine generata dall'IA

U.S. Treasury report proposes AI, digital ID pillars for crypto compliance; endorses lawful mixer privacy

Riportato dall'IA Immagine generata dall'IA

The U.S. Treasury Department submitted a report to Congress on March 9, 2026—commissioned under the GENIUS Act—outlining four technological pillars to enhance transparency in cryptocurrency transactions: artificial intelligence for monitoring, digital identity for onboarding, blockchain analytics for tracing, and interoperable data-sharing APIs. It describes digital assets as key to U.S. innovation leadership while acknowledging lawful users' need for privacy tools like mixers on public blockchains, amid risks from illicit exploitation.

Lawmakers in the US Congress introduced a new bill on Thursday aimed at shielding crypto software developers from criminal prosecution. The legislation focuses on decentralized finance (DeFi) and raises questions about the status of a broader crypto market structure bill. This development comes amid ongoing debates over cryptocurrency regulation.

Riportato dall'IA

Ethereum co-founder Vitalik Buterin has proposed a layered approach to cryptocurrency security that emphasizes redundancy and multi-angle verification to align systems with user intentions. Published on February 22, 2026, his framework acknowledges the impossibility of perfect security due to the complexity of human intent. The strategy aims to protect users from hacks and exploits while preserving usability.

The cryptocurrency industry faces a critical gap in secondary markets for locked and vested tokens, leading to opaque trading and distorted prices, according to industry expert Kanny Lee. In an opinion piece, Lee calls for a Nasdaq Private Markets-style infrastructure tailored for programmable assets to ensure fairer liquidity and support real-world asset adoption. This absence undermines the sustainability of token economies and hinders broader institutional participation.

Riportato dall'IA

Key Senate Democrats engaged in bipartisan cryptocurrency discussions are insisting on strict ethics measures. These rules would prevent public officials, including the president, from profiting from cryptocurrency business connections.

A Reddit trader known as Serenity has criticized the proposed Digital Asset Market Structure and Investor Protection Act, or CLARITY Act, as a measure that would benefit large banks at the expense of crypto-native firms and stablecoin issuers. The critique disputes claims by Patrick Witt that the bill could unlock trillions in institutional capital and drive Bitcoin to $250,000. Serenity argues the legislation would impose stricter rules that hinder innovation in decentralized finance.

Riportato dall'IA

Nearly a decade after a catastrophic hack nearly derailed Ethereum, TheDAO has reemerged to bolster the blockchain's security. Unclaimed Ether worth over $220 million will be staked to support ongoing initiatives. The move revives a long-forgotten commitment from the aftermath of the 2016 incident.

 

 

 

Questo sito web utilizza i cookie

Utilizziamo i cookie per l'analisi per migliorare il nostro sito. Leggi la nostra politica sulla privacy per ulteriori informazioni.
Rifiuta