# Oracles for number values by William George | Devcon SEA

- Speakers: [William George](https://streameth.org/speakers/william-george)
- Channel: [Devcon](https://streameth.org/devcon)
- Date: 2025-10-07
- Duration: 25:39
- Watch: https://streameth.org/watch/yt-qd8mYNBx3-k
- YouTube: https://www.youtube.com/watch?v=qd8mYNBx3-k

## Description

We will overview the history and state of research on how to design a cryptoeconomic oracle that outputs a number value. One wants such tools for price oracles, but also for bringing other information on-chain, e.g. the damages to award from an on-chain insurance contract. We will look at approaches ranging from Vitalik's 2014 SchellingCoin proposal to ideas drawing from social choice theory, including based on recent research. We will explore tradeoffs including resistance to several attacks.

Speaker(s): William George
Skill level: Intermediate
Track: Cryptoeconomics
Keywords: Mechanism design, oracle, Mechanism, design

Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon
Learn more about devcon: https://www.devcon.org/
Learn more about ethereum: https://ethereum.org/ 

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more.

Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. 
Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024.
Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

## Transcript

[Music] okay hey everybody uh so I'm going to talk about oracles for number values uh my name is William George I work for the claros Cooperative uh so what do I what what's like what are we gonna what's the goal here like the district called the basic blockchain Oracle problem you probably all heard about many times uh blockchains don't have access to information about the offchain world if you want them to know something about the you have to tell them that information uh a classic example is you might want an oracle for for prices of Def of of like assets for defi contracts uh you might want other kinds of uh mechanisms to bring offchain information onto the chain maybe the amount of rainfall on some given location for some Farm insurance contract the mechanism used to do this is called an oracle uh and uh sometimes the thing you want the Oracle to Output is a number often in the case of price oracles uh just to give a bit of my motivation like sort of how and why I'm thinking about this problem so for those of you who aren't familiar claros is a blockchainbased dispute resolution platform imagine Alice the small business owner hires Bob as the freelancer uh to provide her some service build her website whatever she puts Bob's payment in some smart contract escrow and if Alice is happy with Bob's work she just clicks a button and it's released if Alice is unhappy uh then she raises a dispute that means that there's like some crowd of users of the Claris platform a few of whom are drawn and they decide who is right uh and the right answer to this dispute the correct resolution uh may be a number uh it may be some kind of partial settlement how much should Bob be paid uh if you have some kind of decentralized insurance contract you might have disputes about how much of a compensation someone should get uh and then basically you have this offchain question you know like like the answer to this offchain dispute and you want this like Oracle that's specialized in dispute resolution and notice that these questions can be you know more subjective more maybe individual than the kind of price Oracle question uh and as a result maybe your like Oracle design might be slightly different for these slightly different questions okay so now like digging really deep uh how how should we design an oracle what are like the basic ingredients go to an oracle uh well on just like a fundamental level you would ask who is participating in the Oracle uh obviously you're bringing information from the offchain world onto the chain somebody's got to be uploading that information who what is the format of the information they provide and assuming you have more than one person who's providing information how do you aggregate their information if they don't provide exactly the same thing how do you put it together into some kind of collective uh value that you use as the number in your in your system uh and people probably aren't doing this altruistically they're so are they what's what's in it for them like are they being rewarded or penalized somehow uh and as one makes these choices what are you trying to optimize you for well obviously you want the Oracle to produce good information fast cheap uh you want it to be attack resistant uh to whatever attacks are sort of relevant for your system I'm going to talk about different choices people have made on these in these design choices uh over times where some of the open like ideas are and like the attacks can vary from one idea to the other I hit on a few uh and so far all of this is relevant like everything I've said could be true for oracles whether they're outputting number values or not uh I could have some discret information uh that all everything I've said so far would be relevant for and where you really get into the number question what the specifics of the number question uh is this question of how precise you want your information to be uh how many decimals um and this is very relevant for incentive functions if you have people rewarding people to participate in your Oracle uh say you want a price Oracle and the you know you you say tell me the price and of like Ethan USD uh and I say you know the price is like $3,200 more or less and I say 3201 am I right should I rewarded should I be penalized uh so this question of like you know for for a number you can always have a more precise closer answer and there's this question of how close you need to be uh and over the course of the talk we'll hit on a few different Notions of close uh that you can build into different kinds of incentive functions like maybe the most basic one would be to say okay you need to be within x% of the of the output value 1% you're rewarded Beyond 1% you're you're penalized uh and that's that's a simple thing you could do there will be other ideas that people have done okay uh now to hit on you know the sort of next ingredient that goes into the Oracle this question of vote information and aggregation uh so again I I think a lot spent a lot of time thinking about dispute resolution for the claros platform sometimes the disputes have binary answers uh or discret answers that are non-binary uh and as a result I spent a lot of time in research thinking about how you aggregate kind of discreet non-numeric answers together uh and this draws from the field of social Choice Theory frequently this like academic field of how to design good voting systems uh voting systems that handle vote splitting well that don't have too much tactical voting uh there's all kinds of complicated questions when when you're trying to Define find a voting system and I bring this up because in the number case you have similar problems uh that are you know they have their own spin on on these kind of vote aggregation questions uh in some sense the questions get easier of how to aggregate people's slightly different information together because now if your participants are submitting numbers again you know maybe the question is what is the price of Ethan USD and everybody submits a number now you can do number operations on those numbers you can take the average uh or better yet you could take the median uh so if you think of like the numbers people provide to you like lining them up from highest to lowest you take them take the middle value that that's the median and that's a particularly popular choice for people that have done number of oracles because it's resistant to outlier effects uh if somebody could put some like crazy extreme value that's not going to affect the median too much so in some sense this question of like vote aggregation is easier than in the discreet case but also there are specific challenges like that that sort of precision question I had from a slot two ago okay uh and now hitting back the sort of last ingredient uh before I get into the choices different projects have made uh this question of who is participating uh and I would argue that there's like two basic models you could have here maybe you can do some some combination of the two uh but you can have either a crowd model or a delegate model uh with the idea and I would say that there are like parallels here to uh kind of different proof of stake systems uh delegated proof of stake versus something that's more like ethereum style proof of stake uh so the question is who is doing the thing who is providing the information uh in in the proof of in the proof of stake systems and the consensus algorithms who is producing blocks uh in an oracle question who's producing like Oracle values uh with the delegated model sort of taking the point of view that like you know these tasks are hard uh maybe you want an oracle that produces like Fast values very frequently you never you want like zero down time uh and to have that kind of reliability you want like a beefy institutional actor uh that has uh you know like really high performance Hardware somewhere in some data center uh and thus you know maybe it's not like appropriate for like random people to be doing the task of providing the Oracle information or producing the blocks in the consensus algorithm uh so instead you have them vote on who you like on delegates who then do the task for you uh and um you know then the crowd model is the opposite of that you know everybody's doing the task I can get 32 E I can spin up a validator I can I can be part of proof of stake or in an oracle I can be the P person that's providing values for the for the Oracle uh and there are of course pluses and minuses uh and the crowd model uh you know if you have like lots of people that are doing like a task constantly that takes gas uh maybe you know like normal Hardware they're not like super fast as fast as institutional actor in the delegated model you know there's some risk that the delegates could use their role sure they can be voted out uh but you know in any given question they're they're they're delegated and you can mitigate that somewhat by aggregating like a bunch of delegates together uh so that you know you'd have to have like some collusion or something for them to crop an answer uh and now to sort of summarize some of the different choices people have made over time uh I'm going to start with like the beginning of the history of this problem uh which is a blog post by vitalic back in 2014 called he called shelling coin so this is the dawn of ethereum this post was actually a lot of the like one of the big Inspirations for what became claros ultimately uh and he was thinking about this sort of like price Oracle question again uh where his proposal is okay I have people that each submit a number value uh you output the median so far that's kind of normal uh and then his uh incentive function was that you reward people in the 25 to 75% range so people who have middle values are rewarded and people who have extreme values are are not rewarded maybe they're penalized uh he didn't explicitly say who the participant should be uh he assumed that you had some kind of Cil resistance tool so this could be either delegated or crowd depending on exactly what that resistance tool looks like but you can certainly imagine like a crowd version of this uh and now here note that this like 25 70% rule uh now the notion of being close to the answer of being rewarded uh close enough to be rewarded is being closer than other people not just close to the value but like I have to beat out somebody else everybody can be within 1% not everybody can be within the middle 50 50 percentile uh so moving on in history uh like the big Oracle provider at least for Price oracles now is chain link so I'll I'll summarize what they do and how that's kind of you know there's choices evolved from from what shelling coin proposed uh so here they have like a Marketplace of nodes that provide Oracle information those nodes are supposed to take information from reliable sources coin gecko kico whatever uh and then a given price feed has a bunch of nodes that are sort of delegated into it uh and you output the median of the different nodes and those nodes are rewarded for their payment for services uh so in some sense this is crowd is uh because there's this Marketplace everybody can participate I to can spin up a chain chain Lan uh node uh but in practice uh it winds up being more like a delegated system uh because any given price feed has some some nodes selected uh and then if you want to get rid of them that that goes back to this question of like voting them out through a governance process uh if I have like a price feed that's used by a big defi application like compound or something like if one of the nodes does a bad job then you correct that by going on the compound forum and having a proposal that looks kind of like this where you're like please change the price feed update and get rid of that note um so now to like to like just wrap up this question of like delegated versus crowd uh here's a sort of partial list of different projects over time and there's kind of a spectrum you can be sort of in the middle but like more or less clustered into the two sides uh Acer had an internal price Oracle for their their die stable coin uh and it's older than anything else on this table so like they had more of a delegated model uh really all the price Oracle things have this have this delegated model which is probably the only like practical choice you could make at least historically uh because if you want a price Oracle that updates you know in real time for defi applications you know you can't have huge crowds of people voting constantly the gas would be crazy people aren't performant enough to do that uh the stuff on the other side that's more crowd uh claros Uma you know have more like individual one-off cases involving human effort so it's not super important that people are up to you know voting in real time uh Nest has a sort of an interesting thing where um they are specific to price oracles uh because they use like an arbitration an Arbitrage game uh to uh as part of their mechanism so it depends on being a price Oracle okay now getting back to the other questions aggregation functions incentive functions uh which ultimately comes down to what are the attacks if I'm trying to manipulate the system like what can I do and which systems are more robust uh so an attack that was already highlighted by vitalic in uh in his shelling coin article is what he called micro cheating there's this long quote I'm not going to read the whole thing uh but basically the idea is that you can just nudge the value provide just a little bit like you you know what the true honor answer is but you as an attacker you uh provide a value this is slightly to one side whatever side you want to nudge the Oracle uh and if you're sophisticated maybe you say within the 25 to 75% range so not even penalized uh and maybe you can move the the output a bit uh to give a bit of a more visual to this uh there's some distribution of how honest people people who are really trying will provide answers some people are better at this task than others uh so uh in the absence of attackers it all kind of average out uh here the the median answer is the the spoton people uh but if I have an attacker that has a few votes not even like a majority the votes only three out of I think 12 or nine or something here uh then by sort of going to one side you know if they're like a sophisticated actor that can anticipate the distribution of the honest people's votes uh they can kind of unwittingly wrap the people that are confused and off to one side into an attack Coalition against their will uh they uh they can take the like confused people join them together with the actual attack votes uh and collectively they have a majority that moves the uh the answer from spoton to okay um and then as the attacker gets more and more votes you can drag the the like answer that much more uh and if you think like you know like algebraically how much can attacker with K votes move the answer like this well if your aggregation function is taking the median uh then an attacker with K votes can drag the result to the point5 minus K Over 1us K percentile of the distribution of honest participants so this gives us a like a measure that to judge okay this is the resistance of median as an aggregation tool against this kind of attack and then we can compare that to like other attacks and see which ones are more or less resistant uh and a natural question is it ever make sense to do anything other than check the median uh like the Medan seems like a really bust robust mechanism like lots of projects have used this uh and uh I would say probably not if your voters only give you a single number uh but if they give you multiple numbers you can do something that's more interesting uh and now uh getting to kind of like research that I have done uh I've thought a lot about uh how to uh have voters provide intervals of precision uh or now they provide you some like lower and upper range where they think the True Value lies uh and if everybody sort of intervals overlap well the answer should be somewhere in the overlap uh if there's some point of conflict uh where there's one interval that's like the upper bound is strictly less than the lower bound of some other interval uh then they're like they disagree uh and you can essentially have the users vote on whether you're higher or lower than a point of disagreement I will sort of quickly go through this because I don't have tons of time uh but um you know you can think of if my upper bound is less than the point of conflict I vote less if it's my lower bound is higher than the point of conflict I vote higher uh and if my my interval disc contains the point of conflict well then I didn't vote at all I gave you less precise information everybody can vote like this you can kind of resolve the points of conflict and you can come up with a collective answer so this is an aggregation mechanism that isn't just taking the median uh this is based on an academic article I wrote with a co-author clange several years ago at this point uh that was based on a version of this that was slightly different because at the time we wrote this with um basically trying to be compatible with claros V1 as it existed at the time uh as of a few days ago claros 2.0 has been launched uh which has much more flexible mechanisms for being able to encode things like this as modules so now we have you know more flexibility to do things like this in the future um uh so how does that aggregation mechanism I just proposed how does it compare to taking the meeting is it better or less attack resistant uh without going too much into the details I will just say that it kind of depends on whether on your distribution of the honest participants uh like how they how they act uh B particularly if people who are confused know they're confused uh if people who are like out on the edges of the distribution or providing impr information if they give you long intervals because they they realized oh I I'm I don't really know the answer to this question uh then they uh then the this sort of voting by intervals performance is better than just taking the median uh if you have like a um like if people that are wrong are really convinced that they're like super confident of being wrong uh then uh it performs not as well there's slight effects either way but you know like this is the sort of analysis you can do of attack resistance for these different systems um now that was all about the aggregation rule you know even even before you think about is the attacker going to be penalized or rewarded uh for doing an attack or like how much are they going to be penalized you know like this the sort of basic question of how much can an attacker that's willing to sacrifice some amount of money drag the answer uh with some kind of minority attack Coalition uh when you get back to the incentive function there are all kinds of interesting questions uh and getting getting back to this question of how close you need to be rewarded uh ultimately every sort of incentive role that you come up with encodes a notion of distance to say whether like a given participant is close or not uh and uh for the voting by intervals thing I have this really complicated form formula that I use as an incentive rule uh at least like tentatively uh that tries to balance the fact that you want to encourage people to submit really small intervals uh which is the first term and at the same time you want to encourage people to be you want to like really reward people if they vote on the right sight side of the points of conflict uh so that if there's like like a point where the system could go a different way and choose a different answer uh you want to like raise the six on people so that an attacker that winds up losing like loses a lot of you know that much more um so if anybody's interested in that formula feel free to talk to me we can we can dig into it uh and then like the different metrics that people have used uh just to summarize the three that we've looked at so there's this notion of being close if you're close to like as a percentage of the output uh there's a notion of being close if you're closer than other people uh these are different things and then there's that crazy formula from different page which is about being on the right side of points of conflict uh so sort of being close when it matters and if like everybody kind agreed it doesn't matter so much and the formula doesn't care as much about whether you know how you voted uh summarizing how different projects have taken the different things they've done on on on these choices uh so shelling coin and chain link like the format of the vot is a number as such the only real reasonable aggregation mechanism is just to take the median uh for the interval approach I have more complicated information that means I can take more complicated aggregation rules um some projects I didn't talk very much about uh projects also have you know that have vote vote formats of numbers also take the median py which is an interesting example they also have something where you have submit something that's kind of like something like an interval uh they have a different aggregation mechanism uh and um you know I just want to say there's a lot of sort of room for experiments here uh so concluding uh historically on this like delegated to crowd model most people have been interested in price oracles if you want a price Oracle that updates like really fast you probably needed a price like a delegated model particularly in like a high gas environment maybe even in a low gas environment just because you want people to be able to provide information with like very low life time uh but if you consider more bespoke questions subjective questions that you might have in a claros select platform that you know now you open up this design space and you get back to this question of like digging in like what kind of oracles can we design and it does it make sense to go back to a crowd model uh we've come up with measures to talk about how microcheating varies from one sort of approach to another uh the delegated approach it leaves its incentives to just like the threat of being thrown out of the platform so they don't really have explicit incentive rules uh but if you want a crowd model you really have to think like what are my what's my incentive rule uh and I there's a lot of open interesting research there so if you're interested in that you know reach out uh and I'm happy to take questions [Applause] so we've got quite a few questions streaming in um as a wider variety of RWS get tokenized How concerned are you that oracles become a point of failure yeah so like the more things you have that like that are integrated in like important ways in your system the more Tax Service you have uh you know if you have real world assets that people are really engaged with and they're providing information you have lot of lots of Watchers uh you know a priori it shouldn't be so bad but we definitely want to like think about how rigorous our oracles are uh how do crowd oracles typically Implement Cil resistance yeah so I mean it depends uh for claros in in claros 1.0 uh there is a token weighted drawing so there's a token that participants have to have and you can't take over the system unless you have you know a large percentage of the tokens uh in claros 2.0 we've considered additional like social mechanisms that like that token mechanism is still there but also uh you can use sort of proof of person tools layered on top of that so and we've we've had sort of interesting results that I can point you to if you're interested uh such that you can design a system that where you both have to like break the proof of personhood and break the the token way to draw to like aot mount a large scale Cil attack um is there an actual objectively right answer or truth for numbers or is it something that's always subjective like I would argue on some level uh if you have like a discret question uh you know you can you can talk like truly about having a right answer uh that like an answer that's better than any of the other answers if you have a number question uh you know people if you zoom in enough can always disagree people might say okay yeah we agre up to like the you know thousandth decimal place but like in the 10,000 decimal place you know I'm you know I'm right and you're wrong uh so on some sense there's always some amount of subjectivity in any kind of nor number question um how do Oracle implementations typically check that they have a sufficient chorum of answers yeah so uh for the delegate systems I mean like they have like some some number of delegates that they think is appropriate uh an individual system might have a quorum if case there's like some like big outage uh where like okay I have nine delegates at least four of them have to be online or something so for you know when you have like a small number of delegates it's straightforward uh in a crowd system you could build something like that in uh in claros we don't have a quorum system because there's an appeal process so if for some reason like everybody was like censored you know there was like an outage it was like bad network connectivity and nobody voted you can just appeal and try again uh but but certainly something to think about in some systems yeah and it's and the last one is a great question uh if I'm a participant in the voting crowd what's stopping me from just copying another answer as my vote and essentially free riding yeah so again this will depend on on the system uh so in claros um like there again there's this appeal mechanism which gives people uh extra rewards if they were on the right side of of an answer that is like where they lost their voting round and ultimately like appealed and they were proven right by them by the appeal round uh so that you know gives an incentive to people to be contrarian if they think that they're right uh other approaches can be taken uh there are like you you can use committ reveal systems uh there's still questions if you do that about like what happen happens if someone pays you to reveal your vote even if you know like the commit and real system allows you to technically hide your vote you reveal anyway uh there are lots of interesting sort of properly cryptographic questions there uh but it's that's a that's like a subject of research uh but there are approaches so I might require a fact check on this last question that poly Market has a highly centralized Oracle and seems to be the largest do you think sentiment will drive crypto crypto products to this model instead of algorithmic is it a centralized Oracle first I think they use z uh so like like that's I think I I you know like people can can fact check me I but uh I I believe they use a like a crowd model uh so you know if people are interested in that product uh then um you know like there could be demand for you know that much more decentralization um you know it's you know if some if something is takes off people will have greater scrw toty for but in general what do you think about centralized oracles versus algorithmic or decentralized ones yeah so I mean it sort of depends on what you mean by centralized uh do you consider like a delegated model like centralized I mean it kind of depends you know it's it's it's not a question of like absolute centralization is about who has the power to do what uh if you have just like a pure one actor responsible for providing you like the truth uh you know you don't have a bunch of delegates and you don't take the media of their answers uh you don't have a Marketplace to join or be dropped kicked out as a delegate uh then yeah obviously if you just have like one absolute source of truth that's not necessarily in the spirit of the ethos that we have thanks yeah that was really good and quick rapid
