Not Priced In: Security Footguns of Price Data - engn33r | yAudit
ETH Belgrade Community·Mon, Oct 7, 2024, 12:00 AM
Transcript
thank you I'll stand over here good morning everyone uh I know it's bright and early so thank you for coming out I actually recommend the talk happening in Hall one if you get bored halfway through uh but today we are talking about prices not priced in avoiding foot guns with price data I'm going to start with the world's fastest intro I'm engineer I do security at y audit y Academy next if you want the slides you can scan the QR code but if you scan the QR code I know you're not in security you should manually type the URL because that's what paranoid people do moving on we'll get back to this at the end everyone here knows what defi is decentralized finance the year is 2024 and defi deals with assets and asset prices everything needs asset price data and that's should be easy because it's 2024 right right no uh now for for normies for what we call normies which would be the people in this room very different than your average normies you might check price data on coin geeko on coin market cap and it looks straightforward you've got an asset a number and some other information about these asset prices it's easy right I'd like to remind everyone that not everyone puts all of their money on chain now I know you love your nft collection but uh I'm going to use a reference from outside the blockchain world just as a you know to ground everyone in reality a little bit here everyone's favorite stock coin for coinbase I just want to highlight the circles uh red circles showing the day range of the stock price we have a low price and high price and it might be hard to see because the font is a bit small on these slides but the numbers are the same on three different websites I forget which websites exactly but these are just three different financial data websites and they all match this makes sense doesn't it now let's return to our funny little blockchain world and let's look at Bitcoin if we open different websites we look at the same information of the 24-hour low and the 24-hour High they don't match this is different than what we just saw on the previous slide with the stock data and this is interesting right because when you think of a price of an asset you think of one price you don't think of multiple prices but what we're seeing here is that maybe there is no one price that everyone is agreeing on and this is strange everyone needs price data it's easy right you may know about Oracle services like chain link and if you open the chain link website you look at the Bitcoin price feed with USD or usdc you'll see something like this showing all these data sources and the prices of these data sources and there will also be a single number that's the final result that chain link provides Everyone likes the easy life of just seeing one result but if you look underneath and you use your telescop Vision to see the small font of all these numbers uh you will see these numbers do not match so once again we're not even talking about the 24-hour High and the low this is just a random time of day that I open the website and the numbers don't match it's interesting we don't have a single price here either but chain link provides one one of the reasons for this is simply that the liquidity is fractured in defi in traditional Finance if you are placing an order for a stock there's a more centralized order flow uh going through the stock market whereas in defi if you are placing your order on coinbase you're going to be interacting with the liquidity on coinbase if you go to ccken you'll be interacting with the liquidity there and all of these liquidity sources are fractured they're separated there's no single point at which you pass to access all of them this is decentralized finance after after all now I'd like to just say that this is an underexplored topic the differences between how the pricing Works in traditional finance and defi um the day I was making these slides there was some new research published from chaos Labs so I just want to do a quick shout out nice work guys um and this website with the link at the bottom which again you should type manually uh shows price differences PR charts between different uh centralized exchanges and I think even some decentralized exchanges so you can actually look at these price differences that I just described uh but again this is underexplored and this research was just published one or two weeks ago there's a few other differences between traditional finance and decentralized finance as you probably know but just to highlight quickly before we dive deeper into prices uh in defi the market Market are open all the time there is no Market close this does make things a little bit harder all the trading venues in defi have separated fractured liquidity as I mentioned uh the liquidity on Unis swap is totally separate from the liquidity on coinbase and the fractured liquidity means lower effective liquidity and what do I mean by this let's say the market cap of Bitcoin is I don't know $100 billion if you want to trade 10 billion of bitco coin there may be no single place where you can do this you may have to combine trades in multiple locations to access 10 billion dollars of Bitcoin so this fractured liquidity does make things harder uh in some cases and causes more variability in the prices uh lastly Arbitrage you'll find this everywhere in finance but in decentralized finance it's necessary for setting prices uh decentralized exchanges like Unis swap require Arbitrage to even set an accurate price because how else are you going to set the price you need to have people trading to determine it but this might all be a review to actually get price data in Def there are two main sources one is offchain price sources also known as oracles this has some difficulties you have to trust offchain sources with an intermediary and some governance and the uh offchain price updates are instant but they don't get onto the chain instantly there's a delay you have the block timing okay you don't want to deal with this stuff you decide to use onchain price data there's some difficulties there we have manipulation this can be Mev front running a trade that's too large and then uh your swap price comes in different than expected um if you're not using a limit order and and there can just be manipulation of the price data as well uh another problem with the onchain data sources if you hardcode your protocol to Unis swap 6 months later balancer has more liquidity you might decide you know what I want to change to use balancer price data to use a deeper liquidity pool so this can change and this makes life difficult I've given you a lot of difficult problems in this quick intro and developers face this very same challenge use an onchain oracle or use an offchain oracle now the moment you've all been waiting for how do we get good price data on chain I'd like to present my answer yeah uh that's not what this talk is about sorry that's uh maybe next year but even though I don't have a good answer for this question what I can provide is a quick lesson on how to play Mission Impossible with avoiding foot guns with price data now I'm going to go through the list of foot guns and hopefully by the end you guys will be masters of avoiding the common mistakes in this space now first let's say you're new to web 3 you're really excited you're going to make a protocol it's going to be the best going to have number one tvl numbers and you decide to use Unis swaps spot price no I love this website it has one single purpose the URL is should I use spot price as my Oracle and well I won't elaborate on this but excellent website highly recommend reading it okay you get a little smarter you decide spot price is not ideal let's use this twap what is this twap twap or twap I don't even know how it's said I only read this stuff online it's the time weighted average price and so instead of using a single price at a single point in time which could be manipulated very easily uh the twap is using average price so you don't have to rely on a single point in time you rely on a longer period of time which which uh Smooths the data and this looks great I mean it's decentralized it's on chain it's a trusted protocol it's Unis swap I mean what can go wrong I only showed half of the picture because on the other half anyone can manipulate this data the price is delayed because we're using an average price not the current price so if there's very high volatility the average price not might may not be ideal to use uh and ethereum switching from proof of work to proof of stake this also caused let's say some difficulties around trusting this data but you decide ah before I proceed to the next one uh this website is also excellent to understanding the risks of using the twap price uh because there is actually a value with the amount of capital you can use to manipulate this price and this website is like a calculator to tell you how safe the price data is uh how hard it is to manipulate it but you decide I don't care I'm doing this anyway so you choose the Unis swap swap what can go wrong well I'm just going to use one example there are many things that could go wrong but let's say for whatever reason you're using the older Unis swap V2 twap and you get this data which is usdc to eth price and you might think okay if I want the price of eth in usdc I can just flip this price upside down and invert it this is how it works right right well you might think that a 0.4 inaccuracy is a minor detail but uh I would like to just point out that Unis swap V2 actually has two tws in every single pool one of them for usdc to eth and one for the inverse and these are tracked differently in different state variables and you might wonder why this is and why this graph has two lines that are not overlapping and in brief without getting into too much detail average can mean many things there's geometric mean there's arithmetic mean and basically the way Unis swap V2 tracks this is with the arithmetic mean um whereas Unis swap V3 uses a geometric mean I hope I got the ordering of those right uh but yeah you can see from this equation basically uh inverting the data of an average doesn't always work out exactly so this is perhaps a more minor foot gun than other sources but uh it's something to keep in mind and there is a blog post for more info but let's say this is all review and you've decided to skip Unis swap entirely because you know what's happening in Defi and you choose chain link it's safer it's safer for manipulation you have no issues you're going to have a happy life your protocol is going to flourish but that was only half the picture because there is governance risk there's limited assets supported and you also need to actually check the data you cannot merely trust that the data you receive is good so what do I mean by this uh you might think this example would never happen in the real world but chain link has BTC to USD which is the actual US dollar currency as well as wbtc to USD uh sorry uh Bitcoin versus rap Bitcoin basically and you might think okay what's a big deal if uh if I can use one I can use the other now unfortunately these uh these assets are a bit different wrapped Bitcoin is not always equal to one Bitcoin so choosing the right feed for your purposes is important on the right half of the screen we have another example of eth to USD and usdc to eth and usdc is not always equal to one USD so what do I mean by this uh anyone here in def5 since 2013 raise of hands okay we have a few survivors well done uh glad you made it this far but there was this massive dpeg in usdc back in March and this is a very clear example of when one usdc did not equal one USD so again using the right price feed is important and even if you think this foot gun would never affect you uh it's happened is all I will say okay you decide you've got the right price feed you know which asset you're dealing with you go to chain link you find the Oracle and wait a minute what's this High Market risk medium Market risk new token what are these values to be honest I don't know exactly how these are calculated but this is merely a demonstration that you cannot say the oracles on chain link and I'm safe there are different risks associated with these price sources and uh to be honest I don't know who's even heard of the asset on the leftmost example um I don't want to even try to pronounce it but uh some of these these assets may not be as liquid they might not have as much liquidity and so just saying you're using chain chain link is not always the uh end of the story shall we say there is more analysis needed chain link even says what I have just said which is ultimately you are responsible so saying that you are using chain link and trusting chain link well chain link is just going to bounce the blame back on you for choosing the Oracle that you ended up choosing so this is again a reminder that you can use Unis swap you have to be satisfied with the pros and cons or you can use chain link or a similar Oracle provider and you have to be familiar with those pros and cons and the risks associated chain link is not like Unis swap in the sense that Unis swap is decentralized and not likely to change on chain they have designed the system this way chain link has a lot of offchain components and it can change and this slide demonstrates that uh you may be using a certain function in your contract and chain link may decide later to deprecate that function this is is not your fault but it is your fault for not factoring in that one of your dependencies could change later on so understanding what assumptions you make when you are integrating with price data is crucial to the success of your protocol so immutability of Unis swap is a pro in that case but uh anyway this is all about pros and cons there is no perfect answer yeah this can happen to you uh it doesn't even matter which Oracle provider you're using at the end of the day they are a business and if there is insufficient demand for certain old data feeds the price feed may disappear so keep this in mind and Factor this in when you're writing code make sure that you're compensating for potential changes in the Oracle provider if I may use an example from web 2 this is from an amazing website that has Silly comics about Google and uh as you can see Google is not exactly known for having the longest lifespan of products with all of their deprecated and killed off projects but don't mind that just stare at the unicorn and things are good okay quick quick intermission here I do want to clarify that when I use a word chain link I'm not only talking about chain link there are many other Oracle providers I won't even name names but this list on defi Lama actually has a list of 50 I didn't even realize there were that many options in the space so I am merely saying chain link as an abbreviation for listing all 50 options that apparently exist um so the problems here are not specific to chain link it's it's the class of solutions that are offchain oracles so anyway intermission is now over let's resume let's say you choose chain link the problem here is when you receive the data the data is not always good data you have to verify the data and if you have no idea what the code here means that's perfectly all right those of you in security this may look extremely familiar but when you get data from chain link you have to perform certain checks because some of these checks are helping you check if the price Oracle is deprecated if the price Oracle is even functioning correctly and if the price has exceeded the max price or the Min price so all of these things you might think that chain link is handling it but no the Assumption from chain link is that you are handling it so you need to make sure that you read the docs you integrate properly with any dependencies you have and getting price data is not the end of the story let's say you choose chain link can you call call the Oracle Outside of a TR catch who thinks yes who thinks no okay you're all asleep anyway uh moving on why use a TR catch which is the recommended approach uh because price data is received from a proxy and this is just how chain link is designed you are querying a proxy contract for the price and the price is coming from the implementation contract behind the proxy uh the Imp mation logic behind the proxy can change that is a typo should say can not and um and to prevent a denial of service in your protocol you need to prepare for an unexpected change of the implementation contract uh this can also happen on let's say uh one of the price feeds where it does get deprecated there may be some big changes to the implementation logic you're not prepared for it and the price Oracle merely is not working at all so that is that and you might think I'm finally done but there is one more let's say you choose chain link but you're on an L2 an L2 functions differently than an L1 if we take ethereum for example there has not been any downtime on ethereum for quite some time but l2s unfortunately will sometimes have this experience chain link documentation has a solution if you are on an L2 and you are using chain link you can use the sequenc or uptime feeds but uh this is very hard to test if you have ever thought of testing whether your protocol is working right if the sequencer goes down I honestly don't even know how you'd go about doing it so at the end of the day you are just trusting that the explanation here is working and the code that you copy from the docs is good this could be dangerous uh the part I highlighted at the end of this slide just saying the L2 has not stopped but it would be unfair to continue providing service on your applications when only a few users can use them this is a very interesting uh a very interesting comment for a space that's supposed to be immutable and always functioning uh without any road blocks shall we say um so anyway when you're on an L2 considering sequence or downtime is actually a factor when you choose price data now we've covered a lot of foot guns and hopefully on time so just going to run through these very quick first of all don't use a spot price from Unis swap use a twap only when the average price is okay and it's up to you to determine what okay means and when the pool has high enough liquidity if the pool doesn't have high liquidity that's another issue thirdly don't invert the twap at least for UNIS swap V2 um if you're using an arithmetic mean and there are likely there are likely other protocols using arithmetic mean I just haven't gotten around to checking them all so when you hear average price you should have a little alarm Bell going off in your head fourth use decentralized Oracle feeds with the correct assets because stable coins are not stable pegged assets are not always pegged depending on the pegged asset fifth use safe feeds Oracle feeds existing is not enough you have to check the risks Associated sixth Dodge deprecations this will just always happen with decentralized oracles uh sorry offchain oracles uh seventh add proper checks on the data eighth use TR catch and finally if you're on an L2 consider sequencer downtime well done you've made it your training is now complet complete and you can succeed in Mission Impossible with price data that is all thank you [Applause] I was crystal clear yeah thank you for a great talk uh can you tell about your experience uh did you try different kind of oracles you say there is a more than 50 uh in your experience or like chain link is like monopol for now that everyone using I think chain link is the most used or has been but there are certainly competitors catching up quickly and there are different models for pulling the data you can use a push model a pull data a pull model um personally I think you should ask someone from an oracle company because they will show you on all the little pros and cons uh to be honest when I am looking at code and I see chain link is used usually this is a positive sign merely because the signal from Big protocols like a and compound they are using chain link so you can go with the Assumption if if the big tvl Protocols are using it then it's okay but this is highly asset dependent because some of the less common assets uh will potentially have very large differences uh depending which Oracle provider you use I think if you are doing uh the price of eth and usdc then maybe there's less of a difference but uh yes I think that uh the exact differences I have not seen any good research analysis on the pros and cons of different uh offchain Oracle providers so this is open research anyone here can take that idea thank you um so I'm sorry I only caught the last bit I came late but I don't know if you mentioned I've seen people use um simulator swap to actually get a price and as a way as a way of of getting a price I don't know if you've mentioned it in your presentation is this a good practice uh yes I think this is perfectly fine um let's say the focus here was more on how to integrate a protocol with a good price data source um I think on the user side there are many good practices you can do you can basically just uh compare different price data sources and uh different aggregators to see that the price that you are getting from one aggregator is better than another um but this is all dependent on how much time you want to spend as a user actually verifying this if you're dealing with very large swaps I don't know seven figure swaps and above it probably pays to spend a lot of time figuring out the ideal process uh for the shrimps here like me uh maybe it doesn't take as much time to figure out if you'll lose one cent here or there so yes it is a good practice to do that so one more question about uh your experience do you know some kind good kind of framework so you uh show just great things like to check like minimum maximum price and all the the rest but maybe there's some Frameworks how you can integrate chain link like easier to don't think about this like manually or probably you know some other protocols that already implemented we can see their code if it's open source yes I will go back to that code you're referencing um this can get a little tricky because although most of these checks are straightforward and most likely everyone will Implement them the second to last line dealing with the Oracle staleness threshold this one potentially could be a a variable that you want to configure yourself so if you are highly sensitive to price changes you may want to set this threshold to a lower number um but at the end of the day yes I think you are perfectly right that chain link or or some other integration should be handling round ID price and Max answer Min answer checks so uh yes if anyone knows of a solution please do share I don't know of one at the moment but it's a great idea [Applause]
Automatic transcript — names and jargon may be misspelled.