ETHWarsaw 2023: Kuba Wojciechowski, Redstone - Pragmatic privacy with Liminal
ETH Warsaw·Mon, Oct 7, 2024, 12:00 AM
Pragmatic privacy with Liminal - An insightful presentation by Kuba Wojciechowski from Redstone examining privacy and its pragmatic applications within the blockchain space. Follow us for more updates: https://twitter.com/ETHWarsaw
Transcript
hi guys thanks for coming welcome everyone to to waro this is a very special place both for me because I based in waro permanently and also for the company which was incorporated created in waro and we got a headquarters like 10 minutes walking away from this place and most of the team is also based in waro so I'm going to tell you a bit more about oracles like what is an oracle what's our take on Oracle how we want to innovate this space is there a clicker this is not the easiest team for the uh Tech infrastructure and we also an infrastructure company which means that there are a lot of challenges building uh service so for those of you who do not know what uh Oracle is or just want to properly wake up after the the yesterday party I'm going to set up the scene and describe that an Oracle is basically a service that helps blockchain apps to receive data from the external world but also to receive any arbitrary piece of information that is necessary to properly function so the still the biggest use case is for landing protocols so if you are allowing people to take out loan against your collateral it's important to properly price the collateral to vate a situation that any one runs out with more money that was deposited to a protocol and Oracle usually takes data from multiple sources like the offchain API for exchanges obviously that's impossible to be done fully in the onchain environment so we need this intermediary getting that directly from IPS it will be just a disaster for the blockchains that needs to synchronize across the node and they need deterministic execution environment but also if the data is already available on chain for example if you want to directly query a x that's often super risky and we've seen like tons of hacks when the developers thought the data is already there we just need to call a contract take a price and we're ready to go but this this price could be manipulated it could be manipulated through a flash loan we've seen it many times hundred of millions dollars was extracted from protocols but it could be even manipulated in a more sophisticated way like a multi-block attack Etc so this little piece in the middle help us to protect all of the precious value locked in D5 protocols but there are some limitations that we notice in Oracle that we try to to solve like the most common model for an oracle is to periodically update price prices on chain so regardless if the price is used or not there is a service that constantly push the information on chain and if it need to do it constantly then it's expensive so the current way to reduce the cost was to limit the number of assets that we can provide price for so then on the ethereum mainnet currently we got something like between like 100 to 200 assets that we provide prices for and as you probably know that like tons of interesting things on the main net that we can have data about so there are like a derivatives LP tokens there are thousand of tokens Etc so limiting access to that information prohibits the growth of the whole space Also if you are constantly pushing data on chain the intervals or the frequency at which we can push the information is limited by the high cost so usual and optimistic update for the most frequent assets is around 10 minutes and also there's an issue with the extending to other chains so if there's a new chain the whole infrastructure will need to be redeployed the extra gas costs will need to be paid Etc so it makes the expansion to a newly created chains which are popping up like crazy recently it's really tough so we wanted to innovate the space offering a very modular design for our oracles so first on the left hand side you may see our data sources and currently most of the oracles use the one that is presented on the bottom which are the the Enterprise level aggregators or trading houses so they already take the data they certify the quality and this data is been pushed on chain but we also expanded on that allowing direct connection to all of the dexes and it's like really crucial if a token is not yet accepted by these Enterprise level aggregators or Traders it's just up recently it's a very common case for all of the recently laed LST tokens but is traded on chain with a decent liquidity we can take data directly from there and deliver to customers also we are directly connected to most of the centralized exchanges and it cuts the the middl man in the form of aggregators so we can deliver the data faster and also we got them much better Overlook what's happening there whether there's like a spread with between bid and ask or whether the the volume of some of the exchanges drops and all of these sources could be connected to our data provider notes which take the role of taking the information from multiple sources and applying different aggregation logic it could be simple median it could be twap it could be vwap or waiting based on liquidity and also applies uh sanity checks so we can verify if the price hasn't deviated too much in a short time span so it's probably manipulated so data providers are independent nodes currently we got more than 30 of them that are responsible for taking the data sanitizing them and certifying quality with a signature and the same data packages are then broadcasted in our data distribution layer which is a combination of a few Technologies for for the security stability and redundancy so it range from a say web to like model when the data is distributed really fast to a more decentralized approach with our open source lightweight nodes responsible for taking data package and broadcasting it to the nail boards and we also utilize streamer Network a distributed popup Network consistent of a few thousand nodes so the data packages are highly available for anyone to grasp and consume in a Target protocol and there are also like three ways how you can consume the data I am going to display that in details later but what's crucial also in this slide is the connection between data cons consumers protocols or DBS and the data providers so we do not enforce this connection we allow a protocol to select a set of trusted data providers and only accept the information coming from them and it's really important in a trend that we are seeing eify it's sometimes called like a bring your own Oracle or it gives freedom for Doos to quickly spin off a a new Landing pool or let's say a new product when either da or even a creator of this new pool can decide which providers they're going to use and therefore it offers that much larger scalability for the whole ecosystem so basically it's like with uni swap when you can anyone can create a pool and then the liquidity may come and we are seeing that in the future with the landing protocols anyone will be able to spin off a landing pool select a trusted data providers and then this pool may exist so we are seeing that in for example working with Venus on B&B working with silo or even Moro recently announc there will be decentralizing day Landing protocol to follow that path so as I was explaining in the middle there is this Cloud called Data distribution layer which is a place when the packages are broadcasted and it's not tied to any existing L1 or L2 Network it's a very abstract layer and that's like super handy if you want to expand to new networks So currently we are active on more than 30 networks this is a screenshot of our page which we call like a showroom. redstone. finance and you can go there we deployed a really tiny contract that takes the packages extract the price so we can test if it works on your network by basically adding a new network that is EVN compatible is something like a 15 minutes of work just to test if everything is properly verified and then you are ready to go so that's really powerful if you ask seeing especially recently like solutions that I call like L2 on demand or like with the optimis stack and maybe with a z sync stack when anyone can deploy their own L2 Network and we can be there in a matter of let's say minutes to deploy the necessary infrastructure and apart from the EVMS recently we also connected to a few known evm chains changing as the small part responsible for data verification so we are active on Stark net on fuel and recently we be working with ton which are super excited because it's a network based on Telegram and they are trying to bootst up the dii also there so going back to these three models of data consumption the base one that is also utilized in the all of the other models it's something we call a core model and in that case so that's the flow of a transaction starting from user to a protocol a user initiate a transaction and then we bring from this data distribution layer assign data packages that are automatically injected to a transaction so it happens behind the scenes from a user perspective is looks exactly the same as interacting with any other protocol or in a way that he is used to interact is just a single Mouse click single signature Etc but there is like a more information attached to a call data and this extra information the price data is then intercepted by our library that is connected to a protocol verified so we verify the signatures of data providers if these providers are the ones that were trusted by a protocol and we obviously verify time stamp if the data is not too old and then the information could be consumed directly from the call data and use in a protocol for example to accurately value the collateral and it's also a very efficient process because we inject the information the call data and we take it directly from call data for verification having an additional single price Fit cost an extra 15,000 gas so it's like almost minimal for User it's less than a transfer it's I think like a half of cost of transferring a token so that's how it works in practice as you may see in metamask a user sending a transaction it's important that it's still a single transaction can see this extra fancy hashes at the end of their message that after decryption are the information about prices and the core model was an innovation in the ecosystem and when we deployed that in in January this year we're like Curious whether we will adapt or maybe it's like will be tough for the protocols to integrate Etc and we are super happy to see that it works quite well in production so there's like almost 60,000 transaction facilitated with the data being injected as we detected on three chains that we currently are using the model which is Avalanche mainnet arbit room and more than 600 millions of dollars were secured in transaction in the core model but also when we started talking to to let's say larger more established protocols they are very used to the way how the oracles work before so they were expecting the information to be already present in the storage and that's fine you got a well audited code you've been working for a few years and you are not so willing to take a new approach to risk a new model until is proven successful and for that use case we took a step back and we offer a solution that is called classic Model so basically we're like 100% compatible with chain link with a small addition of a relayer that is capable of taking all of the sign data packages and pushing in a chain but also what's interesting this model is not like mirroring what was existing in oracles it as much more flexibility so anyone can spin off their own relayer and you can decide on the terms like what whether that should be like a deviation thres short hard bit recently got a really interesting conversation with options protocol that we able to push price directly of the specific time stamp which is not always easy knowing how the blocks are mined but they wanted that and also what's even more important this three layer is something that could be easily replaced by anyone so we got a trustless setup if the relay is down it haven't happened but it may happen I know if we got some real issues any of the users of the protocol can take the same data packages and act as a relayer anyone can can be his own relayer which is super important for the stability of oracles infrastructure so really it's a passive system take sign packages deliver the own chain following the same checks and verification as with our core model we also got a third model and this use case is really great for services that are extremely worried about front running so with a traditional setup there is a delay a between price is being pushed on chain even with the core model when we update price fits every 10 seconds you still got a few seconds when a sophisticated user or hacker may know that the market move within these few seconds and the protocol has got stale data so the X model was designed to Target this risk and it works as follows so when a user wants to make a trade or open a position I think is probably the best use case for Perpetual protocols so when a user want to execute an action this information like the intention to execute an action is started on train so let's imagine I want to open a long position on BTC but the price at which this position should be settled is going to be delivered in the very next block and it's going to be sourced exactly at the moment when the user intention was mined on chain so there is no way to front run the price as the price is been discovered and delivered after the intention is recorded on chain so that's the model that is was used in the GMX V1 we we are now engaged in the discussion with GMX V2 as they want to decentralize the Oracle service and it works quite well in practice it protects uh per Petras against front running vulnerability also what is interesting in let's say the stuff that we are working on and trying to improve in the Oracle space is the notion of the multi-dimensional price let's imagine there is a protocol Landing protocol and it's got something like a 20 million of of a token that they're trying to have like a fair valuation of this collateral to allow other users to take loans but it's a different use case if I'm going to sell on the open market let's say like a $1 value of a given token and if I'm going to sell like 20 millions dollar value of a given token there is a slipage and for protocols to protect against that there is usually a margin like a 20% that is allowed for a price to deviate or for Liquidators to exit a position but is a a huge gap that when you are let's say like a wind in comp position that actually quite quickly make composition of defi not very efficient so what we are proposing is to provide in the real time a fair market valuation on a specific amount of tokens so that's the value that you are going to get if you are at this point of time liquidating a given amount of tokens on the open market so So currently we integrate it with most of the dexes and we are combining the slipage across them and we can draw a slipage profile for every asset so a protocol can have a very accurate valuation of what's the value of the health assets so Al working practice many protocols we learn that Oracle self is not just taking a data and delivering that to the Target there's a lot of stuff to be done in the middle to assure how quality of data so first obviously we are detecting any outliers so if one of the sources significantly diverge from the others we are automatically excluding that on the data providers level also we are checking the volatility so we got the data of the all of the historical volatility of all of the assets and if you detect that let's say in a 5 minutes in diverge more than in an hour take into account that the full history for the last year then we see that something suspicious happening and for the safety case we can disconnect given Source recently we also introduce a slipage checks so as we got the data about the slipage profile all over the assets we can automatically disconnect aex when the slipage is increasing which means that the liquidity probably moved to another Dex and it's been down in the real time so that's the protection against a situation when someone just moved the slipage the liquidity and want to manipulate the price to extract value from protocol and that's not a theorical case if you look to what's happened recently in many protocols there have been this kind of hacks and often when hacker not no that the price Discovery mechan is pointing to one of the dexas most likely like to to in swap but also recently there was a lot of cases with the Curve PS and when the slipage was diminishing then obviously it's a really easy to manipulate the price and then exploit protocols that relies on that price also what we are doing is taking the referential price and that's very important for all the liquid stake tokens so we know what should be the fundamental price of an asset and if it diver diverge a lot we can disconnect a source that is providing us with an incorrect value I've been focusing mostly on the defi data because that's still let's say the majority of use cases for oracles but we also open a service that will allows anyone to create their lightweight oracles for any kind of data and we got it out for public and from time to time I'm looking like what's what's going to be built there so yesterday for example I discovered that someone connected the data about the the altitude of the International Space Station I got absolutely no idea where the data is been used but in our system you can simply point to a given API and there are like multiple nodes fetching information from that and making it available on chain so if you are hacking or if you want to build your custom Oracle for the data sources that are available in the web to but you do not know how to plug in this infrastructure to web Tre we offer this service we call it custom oracles it's like offered for free for experimentation as I mentioned we're based in waro and last eth waro we've spoken with a lot of people in we got these three amazing FS brilliant guys that actually met us during the last E4 so so if you're looking for a new opportunity in your life if you want to start a new journey in web tree come to our booth talk to us and I think that there's really amazing people great crowd in here and we'd love to to meet you and maybe possibly probably work together because we serve interesting task and it's just fun to work with us as we got a really cool team of 20 people here in warso so just to recap why should you use Redstone if there are so many different Oracle providers so our first reason that we often hear from the customers is the fact that we offer fits for asset that are not available anywhere else so there are like a newly created tokens these are the lsts we recently are integrating with a few of them there are LP tokens that are going that are used right now about this protocols that are making investment into LPS especially for UNIS swap V3 much easier and they need proper pricing for the lp tokens they're the real world assets and we started providing prices for T bills obviously but apart from that also for European bills and ETFs and there are derivatives of different kinds like uh stake tokens or protocol tokens that are available on chain so thanks to the fact that we can connect Direct direct ly to Dees we can provide prices for all of them we also offer this information at very low latency so at default we work at 10sec latency but if necessary and if we are considering like a really widely traded assets we can get down to less than 1 second of the uh latency and the update interval also as I mentioned we got a lot of Security checks so oracles are quite easy to be built if everything is stable if everything works fine but during last year we got a few scenarios with the depex of usdc with the Curve drama Etc and as all of the data is being available on chain you can detect and check that we work really stable and there were no issues with our infrastructure as I mentioned also the fact that we abstracted the data broadcasting and publication our decentralized data distribution layer makes it super easy to deploy the service to a newly created chain so if there is a new chain that you would like to expand and there are a lot of super interesting ideas like Bas mantle uh linear when we are already present and working with protocols and if there's a just a chain that was created a few days ago you can get to us and you can start providing the information as fast as possible and we are very flexible so we own not only the data Discovery process but also we are very engaged in the data aggregation methodology and we got multiple ways to push the data to the onine world so if there's like a very specific use case that you want to work with we are a small nimal team and we can accommodate to your needs with a tailored solution so that's it was about Redstone if you got more questions we are available downstairs when you get a boot and I'm also going to be available after this presentation hope you enjoy it and have a great Louch [Applause] [Music] and
Automatic transcript — names and jargon may be misspelled.