Why can DeFi protocols plug into each other like Lego bricks?
Composability is the property that makes DeFi genuinely different from a bank's API, and it is also the property that makes its risk so hard to measure. Both halves come from the same source.
Where it comes from
Three things make contracts snap together:
- Shared standards. Nearly every token implements the same small interface — the same function names for balance, transfer and approval. A contract that handles one standard-compliant token handles the others without being rewritten. The exceptions are where the losses live: tokens that take a fee on transfer, tokens whose balances rebase, and tokens whose transfer function returns nothing instead of a boolean all break code that assumed the interface was the whole contract.
- Public, callable code. A deployed contract's functions are open. Your contract calls mine directly, at the protocol level, with no key, no contract negotiation and no rate limit.
- Atomicity. Every step inside a single transaction either all succeeds or all reverts. You can chain six operations across four protocols and know that if step five fails, steps one to four never happened. Traditional finance has nothing equivalent at this granularity — and, as Unit 4 shows, this is precisely what makes flash loans possible.
The industry nickname is "money Legos." It is a good metaphor for building and a terrible one for risk, because Lego bricks do not fail each other.
What a stack actually looks like
A representative chain of five steps, described so you can recognise it — not as anything to construct:
- Deposit a volatile asset into a lending market as collateral.
- Borrow a stablecoin against it.
- Supply that stablecoin plus another token into an automated market maker pool.
- Receive an LP token — a receipt representing your share of the pool.
- Deposit that LP token into a fourth contract that issues its own receipt token, which some fifth protocol will accept as collateral.
Each step adds a return and a dependency. By the end, the position's value depends on five codebases, at least one price oracle, one stablecoin issuer, and the liquidity of a pool you no longer look at.
The arithmetic of stacked risk
Assume — generously — that each contract has a 99% chance of coming through a year without a failure, and that failures are independent:
0.99⁵ = 0.9510
So the stack survives with probability 95.1%, meaning a 4.9% chance that something breaks. Five "very safe" components produce a materially less safe whole, and that is the optimistic version. The assumption of independence is the weak link, and it fails in the direction people misread. If three of the five read the same price feed, or four are denominated in the same stablecoin, their failures move together — which makes the chance that something breaks slightly lower than 4.9%, and the chance that several break at once far higher. The figure worth fearing was never the probability that a failure arrives. It is how much of the stack goes with it when one does.
Two rules follow, and they are the reason this lesson exists:
- Your risk is not the risk of the protocol you chose. It is the union of the risks of everything it touches.
- Composability propagates exploits. A bug in one contract can drain positions in protocols whose own code is flawless, because they honoured a value the broken contract reported.
The loop that hides leverage
Composability also manufactures leverage from ordinary-looking steps. Deposit $10,000, borrow at a 75% collateral factor, redeposit the proceeds, borrow again, and repeat. The geometric series converges:
total deposits = initial ÷ (1 − collateral factor) = 10,000 ÷ 0.25 = $40,000
total borrowed = 40,000 − 10,000 = $30,000
That is 4× leverage on the original $10,000, assembled entirely from "deposit" and "borrow" — two words that sound conservative. Now price it for risk. With an 80% liquidation threshold, the position is liquidatable once collateral falls to 30,000 ÷ 0.80 = $37,500 — a drop of just:
(40,000 − 37,500) ÷ 40,000 = 6.25%
A 6.25% move against a position that began as $10,000 of unlevered collateral. Unit 3 does the liquidation mechanics properly. The point here is structural: leverage in DeFi is rarely labelled leverage. It is assembled from composable primitives, one innocuous step at a time.
Try it now
- On defillama.com, pick any yield listing and trace it backwards: which protocols does that single number depend on? Count the contracts. Most "one-click" yields are three or more.
- Apply the 0.99ⁿ arithmetic to the count you just made. What survival probability does the stack imply under the generous independence assumption?
- Recompute the loop above with a 50% collateral factor. What is the total leverage, and how far can the collateral fall before an 80% liquidation threshold is breached?