Composability: Why DeFi Protocols Stack Like Money Lego
How smart contracts call other smart contracts to create complex financial operations. The risks and rewards of permissionless interoperability in decentralized systems.
Transcript
If you want to understand why DeFi went from zero to hundreds of billions in total value in just a few years, you need to understand composability.
Composability is the property that lets smart contracts call other smart contracts, letting developers build on top of existing protocols without asking permission. It's why people call DeFi protocols money legos. Each piece snaps together with the others, and what you can build is limited only by imagination and code quality.
Let me show you what this actually looks like in practice. Imagine you want to earn yield on your Ethereum, but you also want to borrow stablecoins against it without selling. In traditional finance, you'd need multiple intermediaries, multiple accounts, multiple approval processes. In DeFi, you can do this in a single transaction.
You deposit your ETH into a protocol like Lido, which stakes it and gives you stETH, a token representing your staked Ethereum that's earning staking rewards. Then you take that stETH and deposit it into Aave, a lending protocol, as collateral. Aave lets you borrow DAI, a stablecoin, against your stETH. Now you take that DAI and deposit it into Curve, a decentralized exchange optimized for stablecoins, where it earns trading fees. Curve gives you a liquidity provider token representing your position. You then deposit that LP token into Convex, which optimizes Curve rewards, giving you additional yield. And Convex gives you another token representing that position, which you could theoretically use somewhere else.
You've now interacted with five different protocols, each one building on the output of the previous one, creating a complex financial position that's earning yield in multiple ways simultaneously. Your original ETH is staking, your stETH is earning interest as collateral, your borrowed DAI is earning trading fees, and you're earning additional rewards from Convex. All of this is possible because each smart contract can read and interact with every other smart contract on Ethereum.
This is composability. Each protocol is a primitive, a basic building block. Lido gives you liquid staking. Aave gives you lending and borrowing. Curve gives you efficient stablecoin swaps. Convex optimizes Curve positions. Individually, each one is useful. Together, they create possibilities that none of their creators explicitly designed.
The key insight is that these protocols don't need to know about each other in advance. When Aave was built, Lido didn't exist yet. When Curve launched, nobody had thought of Convex. But because they're all open protocols running on the same blockchain, following the same token standards, they work together naturally. It's permissionless interoperability. You don't need anyone's approval to build on top of Aave or integrate with Curve. If you can write the code, you can do it.
This is fundamentally different from traditional finance, where integration requires partnerships, legal agreements, API access, and usually a revenue share. It's also different from traditional tech platforms. If you want to build on top of the Facebook or Google APIs, you need their permission, and they can change the rules or cut you off at any time. Smart contracts can't do that. Once deployed, they run according to their code, forever.
The economic implications are profound. In traditional markets, financial innovation is slow because it requires coordination between large institutions. In DeFi, innovation is fast because developers can combine existing primitives in new ways without asking permission. This is why you see so much experimentation, so many new protocols, so many weird and creative financial structures.
But composability creates risks as much as opportunities. When protocols stack on top of each other, vulnerabilities stack too. This is what people mean when they talk about composability risk or integration risk.
Think about that example I gave you earlier, with ETH flowing through five different protocols. At each step, you're trusting not just the code of that protocol, but how it interacts with all the others. If there's a bug in Lido, it might affect your Aave position. If Curve has an exploit, it could cascade to Convex. And if any of these protocols gets attacked or fails, your position across all of them could be at risk.
This actually happened in March 2023 with the Euler Finance hack. Euler was a lending protocol, similar to Aave. An attacker found a vulnerability that let them manipulate the protocol's internal accounting and drain nearly two hundred million dollars. But the damage didn't stop at Euler. Other protocols that had integrated with Euler, that were using Euler as a primitive in their own products, suddenly found themselves exposed. Yield aggregators that deposited user funds into Euler lost money. Other protocols that accepted Euler tokens as collateral had to freeze withdrawals. The failure of one protocol rippled through the ecosystem.
This is the dark side of money legos. The same property that makes them powerful makes them fragile. Every integration point is a potential failure point. And because everything is so interconnected, a problem in one place can cascade in unexpected ways.
There's also oracle risk. Most DeFi protocols need to know the prices of assets to function. Lending protocols need to know when to liquidate positions. Decentralized exchanges need to know if a trade is happening at fair value. But blockchains don't have built-in access to external data. They need oracles, services that feed external information into smart contracts.
Oracles are another point of composability, another place where protocols integrate. And they're a critical vulnerability. If you can manipulate the oracle, you can manipulate every protocol that depends on it. This has happened repeatedly. Flash loan attacks often work by manipulating price oracles, tricking protocols into thinking assets are worth more or less than they really are, then profiting from that confusion.
So how do you evaluate composability risk? You look at dependencies. Every protocol your money touches is a dependency. Every oracle it relies on is a dependency. Every token standard it assumes will work a certain way is a dependency. The more dependencies, the more surface area for failure.
You also look at how protocols handle failure. Do they have circuit breakers, automatic pauses if something looks wrong? Do they have timelocks on upgrades, giving users time to exit if they don't like a change? Do they have insurance funds or other mechanisms to make users whole if something goes wrong?
The most sophisticated DeFi users think in terms of dependency graphs. They map out how protocols connect to each other, where the critical nodes are, where failure could cascade. They limit their exposure to any single protocol or any single category of risk. They understand that higher composability often means higher risk, and they demand higher returns to compensate.
But despite the risks, composability remains DeFi's superpower. It's why DeFi can innovate faster than traditional finance. It's why a small team of developers can build a protocol that plugs into billions of dollars of existing infrastructure. It's why we see financial products in DeFi that don't exist anywhere else, because they're only possible when you can freely combine primitives.
The future of DeFi is more composability, not less. We're seeing protocols designed specifically to be composable, with clean interfaces and modular architecture. We're seeing better tools for managing composability risk, like protocol insurance and formal verification. We're seeing the emergence of composability standards, common patterns that make integration safer and easier.
See you Thursday.
Remember this: composability turns every protocol into public infrastructure, but infrastructure can be built on or it can collapse under weight.