New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Future-block MEV in Proof of Stake by Torgin Mackinga | Devcon Bogotá

DevconSat, Oct 7, 2023, 12:00 AM

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. https://archive.devcon.org/archive/watch/6/future-block-mev-in-proof-of-stake/ In PoS Ethereum, block proposers are known ahead of time. This allows for new types of MEV, which leverage the ownership of future block space. Using this, some attacks that were expensive due to arbitrage competition, such as oracle manipulations, become very cheap. There could also be opportunities for incentivizing high-MEV transactions in a future block that you know you will control. Speaker(s): Torgin Mackinga Track: Security Keywords: MEV,PoS,security Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon 6 was held in Bogotá, Colombia on Oct 11 - 14, 2022. Devcon is organized and presented by the Ethereum Foundation, with the support of our sponsors. To find out more, please visit https://ethereum.foundation/

Transcript

Hello everyone. Uh my name is Torgan. I also work at Chain Security. Um and today I'm going to be talking about what I call future block MEV uh in proof of stake. So, what the hell is future block MEV supposed to be?

Um to understand that, first we have to talk about block production and how it changed um with the merge that happened a couple weeks ago. So, in proof of work, every miner tries to mine every single block. And what that means is at no point can you know who the next block producer is going to be. But in proof of stake, that's a little bit different. Um and there we actually decide ahead of time who the proposer for which block is going to be.

Um and in particular for Ethereum, uh we use the Randall value together with the current validator set to do this. And that means that um you can always know all the block proposers for the current epoch and for the next epoch. And since two epochs in Ethereum take about 12 minutes, uh that means that if you are a uh validator on Ethereum, you will know up to 12 minutes ahead of time when you will actually be the one that is able to produce a block. Um so now, what do you do with this information? Uh this is what I call future block MEV.

Um so, if you are the block producer for a block, you can control the transactions that are included and the ordering of the transactions. Um so, if you know that in some block n plus one, you are going to be um controlling that block. You can do some weird stuff in the block before that in block N, which you wouldn't do usually. Um so, one example of that would be that if you want to do an Oracle manipulation on Uniswap, um the way that you do that is you buy some asset, like here we have some asset that is worth one, and then you buy enough of that to, let's say, move it to six. And then the Uniswap Oracle will always uh record the price in between two blocks.

So, it will record this price of six at the end and will take that into its uh average that it reports. And now, usually, this would be very expensive to do because everyone would see that this price is incorrect. So, there's obviously a really big arbitrage opportunity that somebody could take um to, like, sell this asset at a higher price than what it is actually at. Um and that means that for the attacker, this would be really expensive. But, because now we're assuming that the attacker is actually the block producer for block N plus one, they can just put their own transaction at the very beginning of the block N plus one.

And they can guarantee that they themselves are going to be the one that takes this arbitrage instead of anybody else. So, essentially, they are able to hide the MEV um from the other searchers. Um and here we're assuming that there is some mechanism in which they can make that first transaction in block N uh without going through the public mempool. So, maybe they put it like through flashbots or something. And that means that people will only see the transaction on chain at the point where it's already too late because the next block is going to be produced by the attacker, and nobody is going to have any time to to react before that happens.

Um and so, one example of what you could do is if there was a lending protocol that used such a Uniswap Oracle, um you might be able to manipulate it enough to uh get some uh to get something into the liquidation level where it can get liquidated, but it wasn't able to before. Um and then it that liquidation will be available in block n plus one, and again because you control it, no other searcher is going to be able to compete with you for it because you can just put your transaction uh like in second position, for example, in that block. So, then you can trigger a liquidation uh without having to compete with all the other uh searchers out there. So, what are the main takeaways? First of all, the block proposers in proof of stake are known in advance, and that is different than it was uh in proof of work.

And second of all, this information is valuable. So, for example, you can use it through um doing manipulations or creating MEV and hiding it, uh like I said here, but you could also imagine that you could maybe sell future um block space and guarantee that to people, or you could even incentivize people to um create a lot of MEV in a block that you will control. Like you can imagine if there's some NFT project, they might not care exactly in which block they're going to be launching. So, you could just tell them to launch in the block that you create, and then all of the um gas that is going to be spent on minting those NFTs early is going to be in your block instead of somebody else's. So, I wrote a paper on Oracle manipulation and a blog post on how that changes uh after the merge.

So, if you guys are interested in learning more about the Oracle manipulation side of it, I highly recommend uh checking it out. Mhm.

Automatic transcript — names and jargon may be misspelled.