Digital Assets
A New Framework Targets Hidden Risks in DeFi

Decentralized Finance, or DeFi, is an open financial system built on public blockchains that uses self-executing code instead of traditional financial institutions like banks and brokers. This can create major improvements in efficiency and independence from the traditional financial system, but also new risks.
The first type of risk is tied to the so-called “smart contracts” which form the backbone of DeFi. If poorly written or outright malicious, an individual bad smart contract can cause financial losses. And with little to no institutions or regulators protecting DeFi users, recovering lost or stolen funds can be difficult.
Luckily, as DeFi matured, standards for safe smart contract designs emerged and greatly improved safety from such risks.
However, as DeFi becomes more complex, a variety of smart contracts are used to build different DeFi protocols. This creates a new type of risk, where the interaction between newly deployed contracts and the existing blockchain is used to cause economic losses.
A new paper by Italians researchers at the University of Cagliari and the University of Trento proposes a new framework to address such risks. Their paper, accepted for publication in the Journal of Logical and Algebraic Methods in Programming, is titled “A formal framework for the economic security of DeFi compositions”.
DeFi & Maximal Extractable Value (MEV)
MEV Explained
To understand the situation with smart contracts and DeFi, investors must understand the concept of Maximal Extractable Value (MEV).
MEV is the maximum value that an adversary can extract by strategically interacting with a blockchain system. It is commonly associated with validators, miners, and sequencers reordering or selecting transactions, but it can also arise when ordinary users exploit smart-contract logic, protocol dependencies, price discrepancies, or temporary access to capital.
“While MEV introduces dynamics that can disadvantage users and distort incentives, it is also a transparent and observable phenomenon inherent to public blockchain infrastructure.”
Changing MEV With New Contracts
MEV is where the new vector of risks stemming from the integration of new smart contracts with old ones comes from.
“Adversaries can exploit unintended interactions among protocols to obtain an economic profit to the detriment of honest users.
This is a growing problem, as DeFi expands and new solutions create new risks.
“These risks are further exacerbated by emerging platforms that allow users to seamlessly create arbitrary compositions of DeFi protocols”
So this raises a fundamental question for DeFi that needs a solid answer: under which conditions is a DeFi composition secure?
For this reason, the researchers who wrote this study propose a new concept for DeFi composability, called “MEV non-interference”, which requires that interactions with the existing blockchain state do not increase the Maximal Extractable Value (MEV) obtainable from a set of newly deployed contracts.
They then applied this framework to representative DeFi compositions (exchanges, automated market makers, options, lending pools, routers, and arbitrage contracts), and showed that it distinguishes secure compositions from vulnerable ones.
From Blockchain- To Contract-Level Analysis
To determine MEV non-interference, it is not enough to just look at MEV at the blockchain level. Instead, checking for non-interference principles with existing contracts is needed.
This is why the researchers introduced the concept of local MEV. This is a new measure of economic attacks that quantifies the maximal loss that adversaries can inflict on a given set of victim contracts.
“In contrast to classical MEV which is defined for an entire blockchain state, local MEV focuses on the contracts whose security is under analysis. This shift from a global to a local perspective is the key ingredient of our approach.”
This framework helped them analyze representative DeFi compositions, as they used a collection of representative DeFi compositions, including exchanges, AMMs, binary options, lending pools, swap routers, and arbitrage protocols.
Toward Auditing Economic Interactions
The authors of the study provide many detailed examples of how this analysis framework can be used to detect vulnerabilities and risks from new contracts, like oracle manipulation, flash-loan attacks, or previously hidden dependencies.
This included a stronger adversarial model (wealthy adversaries), in which the adversary is assumed to always possess enough tokens to inflict the maximal possible loss on the victim contracts.
Overall, it gives developers a more practical foundation for testing whether new integrations expose user capital to indirect attacks leveraging the effect on existing smart contracts.
It should, however, be noted that this framework is not a production-ready security system, but just a formal foundation. It also excludes mempool activity, gas costs, token-freezing attacks, dynamic pricing, and some Ethereum (ETH ) behaviours such as reentrancy and cyclic dependencies.
So, as often in DeFi, improving security is not only stemming from perfect algorithms and mathematically secure composition, but also adaptation to real-world Ethereum deployment.
Investing In Decentralized Finance
Chainlink
LINK Price Chart
Chainlink (LINK ) is a decentralized network that connects blockchain smart contracts with real-world data, external APIs, and traditional payment systems. Chainlink is widely adopted by major market infrastructures, financial institutions, and DeFi protocols to unlock advanced use cases, including Swift, Euroclear, MasterCard, Fidelity International, UBS, ANZ, Aave, GMX, Lido, and many more.

Source: Chainlink
Chainlink solves a fundamental problem of blockchain DeFi protocols: blockchains are isolated environments; by default, they cannot access external information.
This makes them vulnerable to “price-oracle manipulation”, where smart contracts are executed according to false data, for example, the wrong price for a security. With Chainlink, such smart contracts have to execute automatically based on verified real-world events.
Therefore, Chainlink directly addresses this form of composability risk. This makes Chainlink useful for several use cases:
- Provide highly accurate, tamper-proof market prices for cryptocurrencies, commodities, and stocks.
- Provide cryptographically secure, random numbers directly on-chainfor blockchain gaming and NFT distributions.
- Cross-Chain Interoperability Protocol (CCIP)for communication between blockchain networks or with traditional banking infrastructure like SWIFT.
Investors in the LINK token should, however, be aware that developers use LINK tokens to pay Chainlink node operators for fetching, validating, and delivering data.
They should also be aware that LINK does not provide direct equity ownership, but participation in the related infrastructure.
Latest Chainlink (LINK) Stock News and Developments
Study Referenced
1. Massimo Bartoletti, Riccardo Marchesin, and Roberto Zunino. A formal framework for the economic security of DeFi compositions. Journal of Logical and Algebraic Methods in Programming. 23 September 2026. Article: 101171. 10.1016/j.jlamp.2026.101171











