Resilient oracles: Enhancing economic security with multiple price feeds - Brad Harrison | Venus
ETH Belgrade Community·Mon, Oct 7, 2024, 12:00 AM
Transcript
[Applause] hey everybody good morning uh show of hands who's a defi engineer here defi engineer okay uh who uses defi okay good so everybody knows what a price feed Oracle is uh this this will be a compatible talk um full disclosure uh this talk is in beta uh but uh we're going to bring some interesting data for you uh about the PO potential problems and uh Solutions around the Achilles heel uh of defi uh which hopefully will become everybody's favorite topic here uh price feed oracles so uh let's begin uh first a little bit about me um or a little bit about Venus it was established four year almost four years ago it's the fourth largest lending dat by tvl uh the only one with real yield uh which means that the res the revenue is reinjected back into the LPS to uh incentivize more liquidity uh and it's the most audited uh lending protocol in defi a little bit more as the fourth largest lending protocol there's some interesting performance uh metrics here um for the last uh three months we've gone to 12 half 12 and a half million which uh it's a lot of money but when you compare this to some of the larger players it it's dwarfed in comparison right uh defi is going through an explosive boom uh lately and uh the volume is also impressive 95 96,000 uh average monthly transactions over the last 90 days so things have been busy in the lending sector um we at Venus have some impressive development velocity there's been a lot of commits uh over the uh over the recent uh past uh improving the protocol and the UI and uh as a function of capital efficiency uh we have some some multiples higher uh yearly Revenue per dollar of tvl to other lending protocols so uh if you haven't used Venus uh come check it out so price feed oracles uh if this is not an area that you've delved into before uh you should probably care about it because uh well there's been a number of price feed Oracle manipulation attacks uh that have resulted uh well in 2022 $43 million uh in what Elon Musk would call uh rapid unscheduled disassemblies right uh the protocols are getting wrecked uh this is catastrophic and uh it oftentimes boils down to uh these price feed oracles so uh for us we have to care about this because if you look at all of the exploits uh in defi a disproportionate number of them actually uh come from Price feed oracles and a disproportionate percentage of the exploits of in all of crypto come from defi uh so it's really up to all of us to put a magnifying glass to this and understand better uh how we can uh uh improve best practices and improve the overall uh situation so uh a lot of you said you use defi or defi Engineers you probably know how price feed oracles work right uh but for a a quick primer there's a few layers uh here that uh you may or may not be aware of so first you have a network of private offchain reporters uh that monitor uh undisclosed price sources so you know not everything here is completely transparent and uh known they periodically share their current price observations through uh a reporting Network that's governed by in this case uh chain link and whenever a reporting round has uh participating reporters agreeing that there's uh some observations that meet uh triggering criteria then that's relate to an aggregator contract and that goes as a transmit transaction then the aggregator checks the report for Val validity and the latest price variable in the aggregator contract is updated with an approximated median of the observations that are transmitted and from there you get a price point uh that's returned which is queried by a data feed that's consumed by protocols sounds simple right um of course these comes in come in a few different methods uh you have push and you have pool each with their own uh advantages and disadvantages so for example with push you can get some theoretical real-time updates uh but it's higher cost and with pool uh you get you request on an as-needed basis so it's more uh gas conservative which of course is probably uh still a concern for a lot of people if you're operating on Main net there's also a hybrid method uh which tries to take the Best of Both Worlds uh but you're still using one feed which we'll get into later um a little bit more about why we should care also if you break down all of the different types of exploits um you can see that uh the flash loan attacks are still a concern we we actually had one I think recently in uh if I don't remember the name but uh it's remarkable that these still come up um and uh security of course is uh a big theme here at eth B gry there's going to be a security panel later um actually the problem has gotten worse uh between 2022 and 2023 uh so so let's see what we can do about it uh if you break down Oracle manipulation attacks you can see that lending actually is the sector that's most vulnerable uh even though lending uh doesn't do the most Revenue compared uh to well uh lending does do the most Revenue so uh it does consume the most uh number of uh exploits uh but depending on where you are some dexes do more business and they uh they don't get exploited as much um uh but uh given that lending is such a big Revenue uh producer uh it's important for us of course to try and maintain the security of of the sector right um so let's get into some of the data here about six months ago there was a p interesting paper that came out uh and given that defi is so new or it's been scaling for only a couple years now right uh the proliferation of Defi and the proliferation of of empirical data uh is uh is only starting to emerge right so this is a paper from since six months ago uh that actually uh classified some of the many factors that are going into to the deviation of pricing accuracy so before we a few slides ago we got into all of the different components uh and factors that go into getting a price to the protocol right and each each one of these layers actually can contribute some uh uncertainty some variability uh and uh in this paper they uh tell you about the moderating effects uh of each of these so for example faster heartbeats reduce the uh price deviation uh which is why you have a negative sign there by fast heartbeat uh and uh they uh went through a painstaking process to map all these out using um uh using a lot of data which we'll get into next so they actually mapped out uh 150 million data points uh over 18 months from 5 40 feeds uh that's 150 million uh pricing events and it turns out uh 2.5% of those were over one standard deviation out of the range uh which is significant uh for an average of 57 bips uh 57 bips may or may not sound like a lot but when you're dealing with nine figures uh that adds up pretty quickly um and 2 and a half% of 150 million anybody want to do that math real quick it's uh 3.75 million times uh that a pricing event was pretty wrong 3. 3.75 million times over 18 months um it's not pretty so how does this kind of get into some concrete example uh well uh this is data from a chain from the chain link website that tells us about some skewing we have uh that resulted in the inappropriate liquidation of uh at least five positions uh this happened uh just 6 months ago um and so these six these five positions that were liquidated inappropriately these errant liquidations on Silo Finance these are just ones that uh somebody happened to look at and catch but over uh if you look across 3.
75 million pricing events uh there's likely more errant liquidations um and and I'm not sure anybody has looked at that empirically yet uh but that will be an interesting area of research to open up uh when it comes to lending specifically so we know that you can probably increase the pricing accuracy a little bit with gas cost right because um faster heartbeat more gas uh faster heartbeat a little more accuracy uh some of the other recommendations that came out of this paper uh deal with um other aspects to look at that are out of our control right we cannot control Market volatility we cannot uh control the reporting a reporter participation as the consumers meaning protocols uh so some things are in the control but a lot of things are out of our control um so where does that leave us well uh their kind of key takeaway was that if a specific Oracle is widely adopted dependency may become a source of systemic risk right um so the current state of defi is that we probably all widely depend on chain link we're taking this as a given uh but uh perhaps it's time to diversify and uh look elsewhere and include more sources right so what does the landscape of oracles look like uh some of you may have heard about some of these um some of them are less adopted in defi uh this is probably an incomplete list as I said this talk in beta uh but uh at Venus we're using chain link of course which is kind of mandatory now given that they're the early entrant and uh first mover uh to really get wide adoption but we've also added support for some others so uh we use uh Redstone Oracle as well uh which uh how many people have heard of redstone out of curiosity great yeah they're everywhere lately um we consume binance Oracle which uh would be the analog of coinbase or IAL which is also an offering uh so uh there's others that aren't in this list and I I think we should expect this list to grow as defi continues to proliferate of course more oracles are better we should have more competition in this field instead of all relying on one provider so this talk is a little bit about uh the some of the solutions we came up at Venus to address this big problem uh called the resilient Oracle uh you can read about it uh line by line in our V4 paper which was released last year we talk about a lot of the other improvements that we brought to Venus um and that include uh three specific uh improvements when it comes to the resilient Oracle so one is multi- Oracle support so the philosophy is that it's better to have more than one Oracle behind each price uh behind each asset on the lending protocol sense checking so a mechanism to understand is the price you're getting valid right uh probably a good thing to have if we know that uh 3.75 million times over 18 months it's probably not a valid price uh and a fallback so what do you do if that price is bad what what what happens next right because uh the the uh business has to continue in defi can't just stop uh so we created this we created this mechanism here uh which underlies the sense checking and uh it's basically a threshold so we set an upper and a lower bound uh for a ratio and the upper bound ratio represents the deviation between the reported price and some anchor price that price that is being validated against uh and uh a reported price which is which can be invalidated uh there's some logic to this that you can visualize then so with a second or Oracle in play because we're now uh using can use a total of three Oracles in this system uh you can validate with a third Oracle as a fallback if you have this threshold that's guiding the selection of pricing whenever a critical deviation is detected uh which as we've seen can happen pretty frequently so this can happen a lot in uh in the future maybe with liquid staking tokens because we just assume a one to one Price Right Now with uh correlated eth assets like staked eth right uh as we saw before there was a deviation in in the price that can result in errant liquidations uh so in some circumstances it's good to switch the pricing Oracle that you're deriving the quotes from rather than always assuming uh one: one uh and this is some of the flexibility that you can get from a res a resilient type setup uh lsts of course are one of the fastest growing uh narratives in crypto and uh represent like 70% of the revenue uh of lending protocols since we added support for Redstone we actually started to look at what's going on if we compare uh the coverage of the pricing block by block uh and it turns out that we found between four blocks uh chain link stop serving data but there was coverage from Redstone uh and binance Oracle so the the bottom line is that having multiple oracles uh improves your resilience and price delivery uh and if you have multiple oracles when things like this happen uh you'll continue to get uh uh price reliability uh block by Block it's also worth noting uh we probably don't have much monitoring in place for this across defi uh if you're a defi engineer if you work on a protocol uh it's uncertain if you're taking logs or looking at how many times you're missing uh a price block by block and when uh transaction volume is high as it seems to be in this cycle uh that that could be really important right so some key takeaways um we've had tremendous lossage from Oracle manipulation attacks and we need some robust Oracle systems uh having one Oracle is probably not adequate and we can we can probably address this problem in part by having some resiliency so um we identified that 2.5% of the time you're getting really invalid pricing uh and relying on one Oracle across all of defi could be a source of some systemic risk uh at Venus we figured out a way to introduce multiple oracles on uh every one of our our assets and we're hoping that over time this can diminish the likelihood of bad Li errant liquidations or inappropriate liquidations uh because right now if you're using a lending protocol uh it's really unclear uh if uh you fall victim to one of these uh errant liquidations right uh it could go unnoticed it's not uh an exploit even though we're you know we've seen that exploits are a tremendous problem and price feed manipulation is a big problem uh it remains to be seen how much bad liquidations are contributing to the overall problem so something that needs a lot more research and that uh we may want to unpack in future versions of this talk um if you want to talk more you can scan this QR code follow me on Twitter and happy to keep the conversation going hope you guys found this interesting thanks give it up for Brad we have time for one question so feel free if there's a question in the audience feel free to raise your hand don't be shy okay then oh there we go does this work oh yeah um so thanks for the great talk um I just have one quick question um so do you use um alternate oracles for just um in case one of the main ones fails or do you like aage them out uh and use them like all together even if um all three of them work um or again do you just um use what the second one or the third one as a backup if the first one fails that's the current iteration of this design so this design is in 1.0 as it were uh but the idea is that we can improve the overall reliability and pricing accuracy that users consume by using more oracles um there's other papers that I didn't include that are very new that speak about uh injecting uh volume weighted averaging uh on chain to do that um so I would say that's the direction we want to go we want to make it more sophisticated and we want to uh decrease we want to start making uh the rate of errant or inappropriate liquidations at kpi of enus and we want to start showing everybody what is the rate of bad inappropriate liquidations across all lending protocols and we want to make it uh as low as possible on Venus using uh future designs of the resilient Oracle that's a good question thanks thanks everybody once again give it for a bre
Automatic transcript — names and jargon may be misspelled.