Composability: the property that cuts both ways
Why protocols can build on each other — and why that is DeFi's most important source of risk.
This lesson has had no expert review. It was written for this platform and against the evidence it cites; nobody has gone through it independently.
Learning objectives
- You can write out a dependency chain for a position.
- You can explain why diversification across protocols is not diversification across dependencies.
Check your prior knowledge
Answer these for yourself before reading on. Wherever you hesitate is where this lesson pays off.
- What does it mean for one contract to call another?
- Where does a lending market get its prices?
- What happens to a product if one of its ingredients fails?
Core concept
Open interfaces instead of contracts between firms
One protocol can call another without anyone asking permission or signing a contract. That is why things appear in DeFi in weeks that take years of integration work in the traditional system. It is also why nobody holds a complete list of their own dependencies: none of them were ever negotiated.
Three kinds of exposure
Direct exposure is the protocol the position sits in. Indirect exposure is the protocols it uses itself. Dependency exposure is what they all share — a stablecoin, an oracle provider, a bridge, a chain. Only the first appears in a position listing; the third decides whether a failure hits one position or all of them at once.
Contagion needs no contract
If one link fails, everything built on it is affected — with no legal relationship between the parties involved. A faulty price in an oracle triggers liquidations in a lending market whose sales move the price in a DEX pool that a yield product depends on. The research literature describes exactly such dependencies and possible spillovers between protocols.
Definitions
- Composability
- The property that protocols can use one another without prior arrangement.
- Dependency exposure
- The risk from components several positions have in common.
- Contagion
- The transmission of a failure to parties with no direct contractual relationship.
Model
Yield product — what appears in the listing
Lending market — where the capital actually sits
Stablecoin as collateral — issuer risk
Oracle — determines when liquidation happens
Chain — carries everything above
Worked example
Three positions, how many risks?
- Position 1
- lending market, chain A, stablecoin X
- Position 2
- DEX pool, chain B, stablecoin X (bridged)
- Position 3
- yield product, chain A, deposits into position 1
Position 3 is not a separate risk beside position 1 but a second layer on top of it. Stablecoin X is common to all three. Chain A carries two of the three.
Three line items, but at core one stablecoin risk, one chain risk, one bridge risk and two protocol risks — one of them weighted twice.
Reading: A listing by protocol hides exactly this. A second listing by dependency exposes it.
Retrieval
Exercise on real data
Open two markets from different protocols and compare the dependency chains shown. Record which link they share — and that an unlisted dependency is an open question, not an absence.
Compare two markets' dependency chains →Application
Which listing would you keep alongside the position overview — and which row must it contain?
Related case studies
Institutional reading
- Insurance
- How many policies would a single failure at the shared level touch at once?
- Asset management
- Is the reported diversification a diversification of dependencies?
- Bank
- Do shared dependencies create a reportable concentration?
Key takeaways
- Composability is at once DeFi's strongest property and its most important source of risk.
- Diversification across protocols is not diversification across dependencies.
- An unlisted dependency is an open question, not an absence.
Evidence
- EVD-2026-0001
Electronic Markets (Springer) — A multivocal literature review of decentralized finance: Current knowledge and future research avenues