New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Oracles on EVMs: risks, misconceptions and tips 🔮 - Marcin Kazmierczak - RedStone & Warp.cc

ETH Belgrade CommunitySat, Oct 7, 2023, 12:00 AM

Transcript

foreign oh yeah I suppose now it works hi everyone my name is Marcin and I'm a co-founder of redstone and e4so I hope you still have some power and you know brain Consciousness in order to listen about oracles before I start I would like to warm you up a little bit with a small question who believes knows how the oracles operate raise your hand please okay okay let's say it's like 15 to 20 percent of the people over here so I will try to also run through the basics so to kick it off I'm going to tell you a bit more about Redstone so we are a company that started in early 2021 last year we raised seven million dollars from a prominent web free investors we are a team of 22 people from Poland mainly our Oracle specializes in price data as for now because that that's where the demand is but is also adjusted for other types of data for example over here you can see a prototype of lens score so calculating a score of a specific address based on the activity on lens and then delivering it to Smart contract that you can create for example anti-bought anti-spam or any reward system based on the score that lens gives you last year we've been to I don't know like 30 maybe 40 conferences because our approach is like developer first so we go we talk with people we try to interact get feedback understand what is cooking what is new so we always try to be up to speed with what's happening in the industry and as I said right now we are 22 people very dedicated to building the infrastructure therefore 75 of our team are engineers I'm the black sheep I'm not coding but believe me I do my best to understand uh like from time to time the PRS that go into our GitHub last week I actually announced couple of prominent Builders from the space like backing us as well for example stani Sandeep Alex gluhoski from ZK Singh Emin from Avalanche guys from Lido coin flip from GMX uh Richard founder of quan stamp and founder of quantum which shows that there is a need for diversification oracles and that our model can truly make a difference we also were featured at the defiant last week with Tegan Klein so if after this presentation you think what we build is fairly cool over there we go a bit more into how it all started and how we position ourselves in the Oracle space of course with chain link being a dominant player and a bit more like a deeper store over there so now as not everyone over here knows let me break down what an oracle is in simple terms so oracles deliver various types of data on chain for smart contracts and dapps that would be probably like a one sentence summary so you have various sources of data you have an Oracle and then you have various ecosystems towards which the data is transmitted so that adapts build their smart contracts can utilize that for any sort of application and now the title of the presentation is about misconceptions tips and tricks I'm going to talk about it during the presentation without mentioning which are them and at the end I'm going to summarize so in fact oracles right now specialize in price feed the reason for that is because there is a demand for that in D5 so if you're a new person coming into web free someone can tell you oh yeah Oracle delivers I don't know personal data results of elections any kind of data you want on chain yeah true actually like the reality is mainly price fit and many times it's like in minutes intervals or even like days intervals it's not too quick and therefore in our view how majority of oracles work right now is similar to moderns in the 80s so they create like a simple use cases but if you want to make something more sophisticated it's impossible so imagine a traffic guy coming to a free right now or D5 and hearing hey yeah so we update the prices of this asset every 24 hours he would be like what the heck I mean in fat fight like milliseconds like truly as quick as possible is necessary and important so on that kind of infrastructure we cannot build the future of financial system we need to like rethink the whole design that's our approach so how the flow of majority of oracle's work is that you have node operators that have data like from from virus sources they push it on chain to many ecosystems for example ethereum Avalanche layer twos and so on and then a smart contract of adapt let's say Ave on a specific chain communicates with the smart contract of the Oracle and the communication happens on chain and when the user makes a transaction it's settled right not much rocket science and you can easily understand that the same data has to be pushed to many ecosystems so if the future is going to be Omni chain or Omni layer 2 or whatever not just one ecosystem it creates friction and additional cost I guess simple as that so to what is the result of such a design is that oracles are non-scalable because you have cost that you face on many ecosystems so you cannot go abroad with assets that you provide because then the costs are going to eat you up um and the update interval is very long because every update you have to pay the gas so you try to make the interval uh short enough that it's usable and long as long as possible so that you don't pay that much in in the in the cost and they lack cross l1s and l2's interoperability because not only you occur like encounter the cost of updates on every chain also on every chain you have to build like a dedicated smart contract infrastructure and you know it's the block times differ like the um execution environment differ like the language differs so there are a lot of uh there's a lot of friction over there so right now D5 potential is limited by oracles especially on ltus like ZK sync arbitrum polygons AVM and speed oriented chains like Avalanche so now I'm going to give you some food for thoughts about this misconceptions three questions the first one is who requires data is it like the chain L1 or L2 or the DAP and the simple answer is it's the DAP that requires data for their smart contracts logic right so going a step forward if you push data on chain and no doubt uses that it's just waste it's nothing else than waste then the second question is can we deliver data to dapps or meeting on-chain storage because we already understood that dapps are the ones that require it and we can deliver data directly to dapp's omitting on this on chain storage this is possible however right now a lot of designs of the apps still require the on-chain delivery so if they require entry delivery can we change the variables like the conditions upon which the data is delivered because currently it's either a heartbeat so an interval or a deviation threshold so a specific deviation upon which the data is updated so can we make it more on demand so when it's needed or optimized that that part and actually yes so if if we cannot go directly to the app we have to still push it on chain we can still play with the conditions upon which the data is updated so now I'm going to talk a little bit about the cost of one gigabyte of storage on virus chains and as you know originally blockchains weren't created for for storage actually like storage was one of the actions that was heavily panelized usually when developers will be doing some stuff so one gigabyte of storage on in Bitcoin costs approximately 2.7 million dollars on ethereum is like 80 million dollars it's crazy much and then you have some other networks that specialize in storage probably you know a couple of them like filecoin and our weave and actually in our case we are very close with the Riff team and we utilize their infrastructure because it's truly optimized for the storage and tournament storage so that we don't have to worry that the data once transmitted is going to disappear in a short future so on r with it costs three dollars to start one gigabyte of data of course it's varies but it's just to show you the magnitude of difference and going even farther I'm going to tell you a bit about cold data on EVMS because we specialize on evm layer ones and layer twos and this is from ethereum white paper like ethereum and EVMS is basically the game between the states and then you have transactions in the middle and the really nice part that many developers forget about is that every transaction on evm has this field called call data which usually is used to transmit some arguments for the function but you can also add some other payloads over there so for example like small packages of data or other stuff usually like rollups use it also for transmitting like the proofs or any other stuff they want to transmit to the layer one why it's important because this piece of the transaction is cheap usually when people think about architecturing web free and D5 they're like oh this is cool this is nice this is sexy but they don't think about what's what's expensive what's not and then sometimes if you know if you are not a whale usually you don't want to pay let's say a hundred or two hundred dollars for a transaction in tune when the gas is high right so if you're a protocol designer you should also think about the cost that the end user is going to incur and here's like a simple price list you can see that the call data byte is fairly cheap in comparison to other actions so if you keep the bytes fairly small you can end up having a small bill on a gust when it comes to the transaction so now this is like the most important slide on the infrastructure of ours I suppose as Redstone because our original idea was to create the on-demand Oracle so we deliver price feeds only when it's needed so minimize the waste so follow me in our system we don't have node operators that blindlessly just take data from whatever and push it on chain we rather have data providers so these are like the entities that specialize in price Discovery so market makers specialized companies that uh like Source data and then they send in our model signed data packages to data delivery Network which is like an off-chain component so it's not a blockchain it's like an off-chain architecture you can think of it as like a decentralized cache layer that keeps data for a short period of time with design packages and then the first idea that we had how to deliver that data on chain is when a user of adopt for example Ave makes an interaction with a protocol with the interface he or she sends a transaction then the front end of other can fetch design data package quickly attach the data package to the transaction of the user and then send it to the destination chain so that is just used for the transaction it's needed and also on the ecosystem that it's needed so if the user uses it on Avalanche or arbitrum then it sends send only there because that's when it's necessary and it also out of the it works out of the box on all evm chains because every evm has this call data type like feature in the transaction but we also confirmed that it's possible to do outside of EVMS the first one was a starknet ecosystem that we made in integration for second the fuel and right now we are pretty excited because we go for the first time outside of the ethereum ecosystem and we are starting working on a toned connector for telegram open network if you want to play around like how it works on practice on various chains you can just go to showroom.redstone.finance and then there are many networks it usually works well on desktop on mobile there might be some problems and one narrative we also want to push towards the market is that in 2023 and forward there is no more narrative once solution fits it all like the Oracle as a concept came into existence when we still had just ethereum or ethereum Killers or whatever but rather like one network so it wasn't truly designed to be omnichine and also with new D5 more sophisticated Define web free applications therefore After figuring out in last year our core model like on demand model that I explained you we encountered that many developers have different needs so it's not like this is a solution to everything some daps really like it and can use it but some require still this on-chain data or have different requirements when it comes to the Oracle therefore we with this off chain component uh also created the Redstone classic Model which is like the model where you create a relayer like a bot that takes data signed data packages from this data delivery Network and then sends it again upon specific requirements on chain and the beauty of that is usually oracles have this specification of a heartbeat or heartbeat and deviation threshold per chain so if you build an arbitrum a perp Landing or any other use case they all use the same data on a specific chain and this approach is depth specific because we want to have dub first approach so we go to adapt we ask them what's what are the conditions upon which they want to update the prices on chain and then we deliver it as it's needed the third one that is so the one and two are production ready and are already used the third one is something new that we co-design with GMX in the very interesting model where you have a deferred settlement model so the transaction is recorded on Black Block n and then executed on the very next block why in order to Omit front running because on perpetuals actually the one of the biggest problem is the front running of the users so in order to omit it we execute the transaction slide with a slight delay um in comparison to other protocols so the last one is important because when the whole D5 space like crumbles rather that goes down the specific areas like derivatives purpose options lsts right now as well like grow in value I don't want to go into specifics into this Redstone X model but if that sounds interesting and you're building a perp I'm happy to explain it more in detail afterwards how it looks in metamask like this package so you as a user actually can see it like everything is transparent so if you go to your meta mask and you go to the hex section you're going to see that there is like a special payload and with the signature and this data package like was was going on you can basically figure it out but on the cost side you're going to pay like a very very small premium because we did a year of work like truly a year of heavy development to optimize the gas cost it's a very low level assembly script code in order to make this invisible from the ux perspective of a user so for example on ethereum you would pay something like I don't know two additional cents for having this payload so it doesn't matter if you pay twenty dollars for for a transaction right um so for many um price feeds we pull from multiple sources for example from for ethereum we have four resources that design also allows us as I said to have more horizontal spread when it comes to feeds that we deliver so it's not only anymore like ethereum Bitcoin and only Blue Chip tokens on very popular chains you can go crazy like for example on one of the hackathons a user like a developer created a feed for individual refugees from Ukraine recorded across Europe and this is like a data from couple of weeks ago I believe it's already like 8 million so you can create some more emotional let's say data on chain and let's say every I don't know thousand you you make a smart contract that donates some stuff right so you can go more creative not only like the heavy D5 that we've seen so far also we have like stake tokens um Commodities Forex and so on and so forth um one thing that is super important in oracles that I would like you to always verify when you're choosing yours is where the data comes from and if you can see which specific transaction like okay one is seeing the data sources in general and the other thing is seeing the who sent the price feed for a specific transaction so I can for example list all the data sources we have over here but then when you request a price feed I can only include let's say 10 of them so it's also important that you can see on on chain like who who are the final data providers so there are various sources like off-chain providers market makers centralized exchanges price aggregators but also on-chain sources like dexis LP tokens um liquid stake tokens nft data and much more benefits of such design already kind of covered but let me recap so it's scalable it covers a lot of data it has a very short update interval so right now we have like 10 seconds and we try to go sub second to finally meet the trotify guys like expectations to create even more like D5 Primitives and it's cross Chain by Design Within EVMS let me show you how it works in practice so Delta Prime is a protocol that allows you to okay let me call it gamble a build so you enter the protocol they create a specific smart contract for you and then this smart contract allows you to interact with many other protocols with under collateralized loans so for example you lock one avax and then you can borrow up to five avacs but you cannot run away because the smart contract holds the condition upon which you can cash out from the casino it's called so you have a Dap user with some collateral let's call it ether has you has you have one eater and then Delta Prime creates like a Prime account like a specific Prime account for you you can look up this one either you can borrow up to five then Redstone provides data for a solvency bot that checks dissolvency every 10 seconds so if you had updates like every 15 minutes within 15 minutes in D5 everything can just you know crumble down so you need something more accurate therefore 10 seconds is something that we can keep up with 5x loan and then we've read some price feeds with this smart contract you can interact for example on Avalanche with dexes like Trader Joe staking protocols like give the act or even have very interesting delta neutral strategies with liquidity mining with glp and GMX tokens so this is just one of the use case for this on-demand core model and the possibilities and now I'm going to recap through what I've said during the presentation what are the tips and misconceptions and tricks so the number one misconception is Oracle deliver all kinds of data I would like you to remember that right now it's not the case like we are not there yet maybe in the future but you have to remember that with delivering data on chain and to dapps there's always a cost and in order to justify this cost you have to create like a viable business model right like a viable use case and so far it's been mainly for Price feeds within D5 second misconception is on chain delivery is cheap as I said like you have multiple multiple networks usually storage is panelized so unless you have a very specific blockchain that is dedicated to storage then it's quite expensive um misconception number three is one Oracle fits it all so you create like something that is super standardized and you just try to push it to every client and it turns out you cannot make a lot of diversity with that in approach such an approach so perpetuos have different expectations Landing has different expectations lsts have different expectations so you just have to talk with developers and the clients to understand them all uh trick number one is you can add a payload to evm transactions and I will go right now even again step forward because right now these data packages are about price feeds but it can be anything else and we created a proof of concept of know your Degen Oracle so a soft version of kyc where the payload is not a price hit anymore it's rather the information whether your smart contract should accept a transaction from a given address or not so imagine you create a rule that every address that has ever interacted with tornado cache cannot interact with my smart contract you you implement this kyd Oracle within your smart contract and then before the transaction is executed it Dodges the transactions from the tornado cache users so then you can have like a soft version of kyc because you know right right now it's regulatory aspects a very heavy one especially in the United States trick number two is utilize storage networks to optimize costs and that's like in general like if you have a part of your flow or dap that is data heavy then think about offloading part of it outside and then making like for example async or any other rule to update tip number one is verify how adapt actually uses in Oracle and as I mentioned a Perpetual is going to use it differently than other types of protocols web free betting is going to use it differently last oh no tip number two is while defy sinks if if you're a developer or you're a builder and right now figure out what to build next there is a huge spring in my opinion when it comes to perpetuals lsts and Stables maybe cdps more specifically so I'm not encouraging you to build another one because it's it's going to be saturated soon but maybe you can think of any anything that you can build on top of them right because if it's a trend right now then in couple of months there are going to be other protocols that utilize already as stable ecosystem of these protocols last but not least always verify data sources and transparency so look if you integrate in an oracle you can check on every transaction who delivered the price so like the price feed or any other data type for you I'm going to give you a real case example do you remember this exchange like kind of a niche one FTX I suppose some of you do I hope none of you have lost huge fans over there so remind you of yourself yourself this um turmoil that happened over then and imagine your protocol takes data from an Oracle and now FDX was a data source for majority of oracles on the market it was a big player had a lot of liquidity so of course you pulled data from them and now if you couldn't see at that time that you were fetching data from FTX when FTX was stopping you wouldn't have been able to decide whether your app is malfunctioned because of the whole market crash or any other reason or because you consume data from FTX if you have this whole transparency you as a wise developer let's say when you see that FTX has problems and you remember that you consume data from FDX if your dap is upgradable and that's another whole another topic but usually they are you know how this you should usually you have a bug door to upgrade your contract you should quickly upgrade your contract and for example disregard that kind of a feed because you're aware so the more transparency and the more aware you are the more like capabilities you have to react to Market crashes or any Blackstone events so this is the last slide I would like to invite all of you to E4 so conference and hackathon that happens at the end of August it's happening in a beautiful 19th century building it's a Warsaw University of Technology and we are going to have great speakers like uh stani Alex a couple of others big names like ZK sync are we scroll like also joining so we'd like to uh invite you all also like if belgrad's organizers for sure thank you a lot you can catch me after the presentation if you have any follow-up questions and yeah thanks [Applause] any questions right now oh I didn't know there is a time for questions okay yeah we have time we have time so go wild okay so maybe anyone has a question right now okay foreign thanks for the nice presentation and good luck on your endeavors does this mean that the smart contracts that want to interact with this so to implement this solution we need to change for example can you use this on uniswap or anywhere else that wants to integrate this Oracle well this is it is it based on Smart contracts so if I want to make a smart contract I will need to integrate with this uh Oracle maybe with chain link Oracle and different kind of oracles is that right because the data is coming directly from metamask as I understand so the input data for the smart contract function needs to account for that and probably check for signature yeah so when the data comes to the smart contract of course like the signature is verified of the data package whether it comes from a verified data source and then to your question if adapt can create like a model where the on-chain storage is not necessary like this Delta Prime guys then you don't need like any secondary Oracle but in many cases for example right now the design of Ava or other big protocols like compound they are very robust have gone through multiple audits it's like fireproof at least all of us should hope that nothing will happens so of course for them implementing something Innovative like this would be a struggle so therefore we created this Redstone classic Model where you have a familiar interface and also like the smart contract of hours on chain that you can call so it's very as I said depends use case to use case but to sum it up also I heavily advise to try to implement more than one one Oracle in the design because then you always have more redundancy as long as the costs allow you because if you're talking on about let's say I don't know arbitrun where the storage is still affordable it maybe makes sense but on ethereum usually it doesn't because it's just too expensive thanks hey Martin um I was surprised to hear you say that you think sometimes it's necessary to have back doors in contracts and I wonder if you can just speak a little bit more about that are there like interesting ways of having safety guarantees in contracts that don't give unnecessarily privileges to certain groups of people so like the esm and maker or these kinds of examples of like security and safety modules that do shut things down but not in a way that can be easily manipulated like what are the examples of that in the industry that you're most interested in at the moment oh okay so that's as I said it's totally different topic and the title of the whole presentation could be like uh permissionless or unkillable smart contracts good or bad I'm not going to I'm going to talk about my personal belief my personal belief is unless you're super established and a long lasting project you should probably have maybe not you you should have a way to to react to Blackstone events especially when you are getting hacked everyone like look for the past couple of months you've seen so many hacks like even like okay on top of my head Euler two days ago and Steve uh and so on and so forth so as long as something is even like growing hot and super cool I I can give you another example like Libra Finance right now it's like the one that is rocking I mean the TV is growing everyone is looking at them and it might be a very good protocol but imagine like right now as far as I know they have like two million dollars in tvl and imagine Tuesday they have an attack and because they created it super permissionlessly they cannot react and they are super young so does it make sense I don't know like from my perspective if you do something Innovative in the very beginning especially in the early days you should be transparent that you leave the back door for yourself and then the users that are ex like Maxis will not interact with it but you should also be looking for a way to get rid of this of this back door as you progress when you learn when you have for example a couple of years already of experience you've seen you've seen like a market like turbulence and everything then you can at one point probably like decide okay this is a this is fine now I believe it's ready that I'm going to give away this uh this back there as is and again that's my personal take it's nothing that I prepared for the presentation I'm also not a subject matter expert but I've just seen a lot of I've seen people like truly crying because oh my God I have all my funds on this like this hacked protocol what can I do right yeah okay I think this is it nothing else thank you very much man one more Applause come on

Automatic transcript — names and jargon may be misspelled.