Original Title: "New Narrative of DeFi? A New Secure Model for Smart Contracts without Oracle Protocols"
Original Author: @Ac-Core, YBB Capital Researcher
Oracle is an important factor in the DeFi world. Although the security of different protocols is usually inherited from the underlying smart contract network, its normal operation still depends on the oracle. If an oracle of a protocol is attacked or destroyed, the entire protocol will be manipulated. Recently, new DeFi creators are creating new narratives by conceiving new lending and derivative architectures, and the common point of these protocol changes is no longer relying on the oracle. The biggest appeal of DeFi comes from its decentralization. In a broad sense, it is an open financial system with permissionless payment protocols. Compared to traditional finance, its rules, profits, and even risks are disclosed in a more "obscure" way, but it still has a very strong degree of openness. However, after several years of development, the DeFi field has also accumulated billions of dollars in theft [1], and even the most fervent believers will constantly question whether it can become the mainstream of future finance. In 2022 alone, hackers stole more than $3.8 billion through DeFi protocols and cross-chain bridges, making it the year with the highest amount of theft in crypto history. If we want to bring a larger group of people into the crypto world and rely on DeFi in the future, security is the primary factor that needs to be addressed. The organization Nascent, composed of builders, believes that the concept of "no Oracle agreement" will provide a more robust and secure technical architecture for DeFi from the ground up. Today, DeFi hopes to define itself as "primitives" and hopes that more teams will build products or combination protocols on their basis. Once the contract is mixed with any external dependencies, they will inherit all relevant risks. At the same time, in order to carry a larger system ecology, the contract will be upgraded, and this management-style upgrade variable will involve the current and future changeable environment, bringing more risk factors. As the name suggests, the introduction of Oracle creates a dependency relationship with external data, which can bring potential risks. Therefore, Dan Elitzer, a member of Nascent, proposed a brand new definition: to meet the conditions of primitives, in addition to contracts deployed on the blockchain, it cannot rely on any external factors, such as governance, contract upgradability, and oracles. However, this narrow governance function has not caused systemic risks due to the large-scale upgrades in other protocols, so the reason why Uniswap has achieved great success in all versions so far is the absence of Oracle and full-chain, two key factors. Undoubtedly, Uniswap is the leader in decentralized trading, achieving tremendous success and spawning many experiments in decentralized exchanges. For example, Uniswap V3 introduced the concept of non-fungible liquidity positions, allowing liquidity providers (LPs) to concentrate their liquidity within a specific range. This enables LPs to capture a larger share of trading fees generated within that range and profit from it, but there may also be uncompensated losses due to price fluctuations. This has led to more efficient use of capital and specialization of the LP portion in the market, resulting in a series of position management tools such as Arrakis, Gamma, and Sommelier. Although this is very friendly to DEXs, lending protocols still require oracles. In March of this year, Euler Finance's lending protocol was hacked, resulting in a loss of up to $200 million. The protocol allows users to decide on collateral and borrow funds. In short, the issue occurred in a specific function that was not properly secured, allowing users to disrupt the fundamental invariant of the lending market. For more information on the details of this attack, please refer to [2]. For loan agreements, qualified collateral is limited to assets with reliable price feedback from an oracle. Loan parameters (such as loan-to-value ratio [3]) are governed by their agreements, so any bad debts are the responsibility of the agreement rather than individual borrowers. Similarly, derivative agreements that rely on oracles for pricing, lacking internal price discovery mechanisms, are susceptible to price lag and lack of updates, severely limiting their scale and user experience. As mentioned in the preface, this also explains why trader Avraham Eisenberg was able to successfully attack Mango Markets and withdraw $116 million from the cryptocurrency trading platform. AMM can have the simplest basic invariant in any DeFi source code (Primitives): tokenBalanceX * tokenBalanceY = k (such as constant product). For example, the Pair interface in Uniswap V2 is implemented based on the following four function invariants: Mint: Add to k; Burn: Subtract from k; Swap: Move x and y while keeping k constant; Skim: readjust tokenBalanceX * tokenBalanceY to equal k. The Security of Uniswap V2: a simple core invariant that all functions serve. The only controversial aspect is its governance mode, which can switch the fee switch, but this does not touch the core invariant, only affects the distribution of token balance ownership. It is precisely because of their simplicity in security (non-upgradable smart contracts and basic invariants) that Uniswap itself has never been hacked. Recently, we have noticed many projects that involve lending agreements without oracles, such as Ajna, Ethereum Credit Guild, the Automated Tranche Maker protocol by MetaStreet, and the Blend hybrid protocol launched in collaboration with Blur and Paradig [4]. Unlike traditional DeFi lending markets, Gauntlet does not have collateral or a single universal oracle like Chainlink to provide "real" asset price sources for all users and protocol functions. Instead, borrowers need to assess risks to determine the collateral they require from borrowers, and must update their borrowing standards when asset prices change. The way it works is that borrowers choose the specified collateral they are willing to accept, such as BAYC Token and individual Bored Ape NFTs, the reference assets (such as USDC) they are willing to provide as collateral for borrowers, and the ratio of reference assets to collateral assets that they will require borrowers to be liquidated. Finally, borrowers can post collateral and borrow reference assets at the current market rate. Please note that, since both the borrower and the lender have agreed that the settlement of the loan is determined by the ratio of the unit quantity of each asset rather than the US dollar price, no oracle is required. However, if the relative US dollar value of any asset changes, the lender will adjust the terms of the current or future loan to achieve the collateral ratio they deem safe. The Blend protocol of Blur assumes "the existence of more complex lenders who can participate in complex on-chain and off-chain protocols, evaluate risks, and use their own funds." This makes sense in the context of Blur being a primary trading venue for professional NFT traders, but it seems much more complex for ordinary users to borrow on Aave or Compound. Point-to-Point The user bears the loan parameters and the risk of bad debts (no longer the contract's risk), and the borrower no longer defines the interest rate and LTV parameters, but decides the value comparison by themselves. Removing the oracle from the protocol mechanism means that these loans can be created by any on-chain collateral. Active management of positions is required to ensure that the provided liquidity is effectively utilized. Users must actively manage their positions in a manner similar to centralized liquidity positions such as Uniswap V3. Based on AMM, hybrid types (lending/derivatives-LPs liquidity providers) The underlying LP position provides pricing data for settlement and derivative contracts, and is also the main market for liquidation. This allows the protocol to calculate the results of settlement and derivative contracts from its underlying liquidity pool, essentially making the LP position itself like an oracle. In addition, these LP positions provide a primary market for unloading protocol inventory during liquidation or contract expiration, without the need to settle collateral on external platforms. Example: (1) Asset pricing provided by the lender: When the borrower uses the Ajna protocol, they will inform the contract of their willingness to pledge assets at a certain price. This effectively allows them to input their own lifecycle value and transform it from governance parameters to market parameters. (2) Automatic interest rate discovery: In each Ajna market, there is an equilibrium state determined by internal indicators. If the market is out of balance, anyone can change the exchange rate by 10% every 12 hours. If not, no changes will be made. (3) Clearing margin: As Ajna does not have an oracle, it relies on users to tell it when to liquidate loans. This is achieved by having a clearing agent post margin to trigger the liquidation. If they are honest, they will be rewarded. If not, they will be punished. So what's the point? These innovations allow Ajna to provide services for the "entire" ecosystem. Anyone can create a lending market with any asset (even NFTs). Governance processes are no longer laborious and there is no longer any concern about liquidity, secondary markets, and oracles. Blend is a peer-to-peer permanent lending protocol that supports any collateral, including NFTs. It matches users who intend to borrow with lenders who are willing to provide competitive interest rates through a complex off-chain quoting protocol. By default, the interest rate of Blend loans is fixed and never expires. Borrowers can repay at any time, while lenders can exit their positions by triggering a Dutch auction to find new lenders at a new interest rate. If the auction fails, the borrower will be liquidated and the lender will take possession of the collateral. Overall, it has four characteristics: independent of oracles, unlimited, liquid, and peer-to-peer. 无预言机 -> Non-interactive Zero Knowledge Many DeFi protocols require oracles to determine liquidation positions or the timing of interest rates. Taking NFTs as an example, their prices are difficult to objectively measure, and timely updates to the floor price on the chain are also difficult to observe. This solution usually involves a trusted party or transaction manipulation. However, hybrid protocols avoid any oracle dependencies in the core protocol, allowing interest rates and loan-to-value ratios to be determined by the borrower's willingness, and liquidation is triggered by the failure of a Dutch auction. 无期限 -> 无期限 (no time limit) Some DeFi protocols only support debt positions with a fixed term. This is inconvenient for borrowers, who need to remember to close or adjust their positions before they expire (otherwise they may face penalties, such as confiscation of NFTs). The process of manually adjusting positions also consumes gas, which reduces the profits generated by borrowing and lending. As long as there are lenders willing to lend this amount based on collateral, Blend will automatically adjust the loan position, and only on-chain transactions are required when the interest rate changes or one party wants to exit the position. 可流动 -> 可流动 (no translation needed) Some protocols do not support liquidation before expiration, which is more convenient for borrowers and reasonable in many use cases. However, this actually gives borrowers a put option, and lenders need to make choices from high interest rates/low loans in a short expiration time to avoid the risk of position liquidation. In Blend, as long as the borrower triggers the refinancing auction and no one is willing to take over the debt at any interest rate, the NFT can be liquidated; Point-to-Point Some protocols concentrate the funds of the lenders and attempt to manage their assets. This means that they heavily rely on centralized management or management on the chain to set parameters. Blend adopts a peer-to-peer model, and each loan is individually matched. It does not optimize the simplicity of the loan method, but assumes that there is more complex borrower ability involved in completing complex on-chain and off-chain protocols, thus having greater authority to control their own assets. According to Brock Elmore, a member of Nascent, the FREI-PI pattern stands for "Function Requirements-Effects-Interactions + Protocol Invariants pattern". Here, we take the SoloMargin contract (source code) of dYdX as an example, which is a contract for lending markets and leveraged trading, and is an excellent example of the FREI-PI pattern. This is the only lending market in the early lending market that has no market-related vulnerabilities. When viewing the code below, please pay attention to the following abstract concepts: Input requirements (_verifyInputs) Operation ( data transformation, state manipulation ) State requirement (_verifyFinalState) Here, the commonly used Checks-Effects-Interactions (CEI) are still being executed. However, it should be noted that CEI with additional Checks is not equivalent to FREI-PI. Although they are similar, they serve different goals. Therefore, developers should understand their differences: FREI-PI is a high-level abstraction for protocol security, while CEI is a high-level abstraction for functional safety. The interesting thing about this contract structure is that users can perform multiple operations in succession according to their own wishes, including: deposit, borrowing, trading, transfer, settlement, etc. We assume that three different tokens are deposited and the fourth token is withdrawn and the account is settled, and this series of operations can be completed with just one click. This is the power of FREI-PI: as long as the core lending market invariant holds true at the end of the call, users can do whatever they want within the protocol. For this contract, this will be executed in _verifyFinalState, checking the collateral status of each affected account to ensure that the protocol is better off than when the transaction started. This function also includes some additional invariants, which are supplements to the core invariants and help to implement auxiliary functions such as closing the market. However, the core check is what truly ensures protocol security. The concept centered around entities is another challenge for FREI-PI. Taking the lending market and assumed core invariants as an example: users cannot take any action that would put any account in an insecure collateral state. Technically speaking, this is not the only invariant, but it is the only invariant for users (which can be understood as the core protocol invariant, as the user invariant is the core protocol invariant). In the lending market, there are usually two additional invariants: 1. Oracle Generally speaking, Chainlink is a good choice. Its main function is to provide accurate and relatively accurate real-time information, which can meet the requirements of most invariants. In rare cases of manipulation or unexpected situations, it may be beneficial to reduce real-time security measures to ensure accuracy (such as checking whether the last known value is hundreds of percentage points higher than the current value). However, Cream Finance still suffered a $130 million attack. For more information on oracles, please refer to "Manipulating Uniswap V3 TWAP Oracle [5]". 2. Governance Governance is the most thorny invariance, because it is difficult to be constrained by conditions and most of its effects are to change other invariances, and some governance cannot be verified by FREI-PI during operation. Taking the governance operation that caused damage to the cETH market by Compound in August 2022 as an example, this upgrade violated the invariance of the oracle. For more details, please refer to [6]. In practice, every additional invariant makes the protocol more difficult to protect, so fewer is better. Therefore, complexity is dangerous, and the most important invariant is the invariant at the core of the protocol. However, as mentioned above, there may also be entity-centric invariants that must satisfy the requirements of the core invariant. The simplest/minimal set of invariants may be secure. Is building DeFi on un-upgradable source code (Primitives) and without oracles the best solution? After all, the flexibility and usability brought by governance, upgradability, and oracles have also led to a market size of billions of dollars for DeFi protocols. According to Dan Elitzer's point mentioned above, governance, upgradability, and oracles are not inherently bad, on the contrary, these elements have great practical value in a broader context, but they also increase the probability of protocol attacks. Primitives themselves can also be occasionally replaced when updating functionality or improving efficiency based on demand. When choosing how to create a DeFi protocol, there are two important choices to consider: entrusting all user data and external dependencies to a more centralized single protocol and delegating to a small group of token holders willing to participate in governance, or valuing the ownership of each participant in the market and allowing users to decide on the protocol and service provider themselves. The participants and developers of the entire industry are committed to building a more decentralized, permissionless, and highly compositional DeFi to enhance the security and resilience of the entire industry. Regarding the future development direction of DeFi, we hope that it can continuously occupy the market share of traditional finance in a more secure and efficient manner. Explanation and References: Welcome to join the official BlockBeats community: Telegram Subscription Group: https://t.me/theblockbeats Telegram Discussion Group: https://t.me/BlockBeats_App Official Twitter Account: https://twitter.com/BlockBeatsAsia
I am a practitioner in the encryption industry. Please translate the following Chinese text into English without considering the context, industry-specific terms or names. Do not omit any English words or phrases, including capitalized ones such as ZKS, STARK, and SCROLL. If there are English characters in an tag, do not translate them and return the tag as is. If the content only consists of punctuation marks, return them as is. Do not translate HTML tags such as , , , and
. If an HTML tag contains English characters, omit the translation and return it as is. Please preserve the content within tags. Do not translate any Chinese characters.
The text to be translated is:
Foreword
DeFi Risk and Remediation

Source: Chainalysis
Risks and "Source Code" of Oracle
But the reality is that DeFi protocols that meet this basic definition are very rare today, with the most representative being Uniswap V1. However, even Uniswap V2 and V3, which are consistent with the definition proposed above, do not qualify from a security perspective because they allow governance over certain functions, such as closing protocol fees and introducing fee tiers for pools.Why Uniswap is currently secure
Reconstruction Loan Agreement

Source: Author Balakov
These methods' greatest advantage is that the protocol is essentially immune to bankruptcy. This is because each lender is ultimately responsible for their own ability to repay the loan, so there is no concept of "bad debt", which may be borne by DAO treasury/insurance funds or handled among lenders.无 Oracle 的新面孔
Translation: A New Face Without Oracle
According to Chase Devens, a researcher at Messari, the definition architecture of non-oracle can be divided into two categories: peer-to-peer and hybrid types based on AMM. The main characteristics of these two types are as follows:
Supports any type of on-chain collateral.
Supports any type of on-chain collateral.Ajna.finance
Ajna is a lending protocol designed specifically for EVM, without governance, permissions, or external price supply (oracle). It can be used to borrow and lend our entire investment portfolio (including NFTs). Two core issues of other lending projects that have reached critical mass are: (1) token governance systems are insufficient to analyze complex risks, and (2) using external price feedback (oracle) limits asset scope to "blue chip" with liquidity in secondary markets. These flaws have caused catastrophic losses in the DeFi lending market and limited the ability to support new assets. Ajna solves these problems through some key innovations.Blend

Source: Achal Srinivasan, Kirby
What is FREI-PI mode?

Source: Brock Elmore
Summary: The Future of DeFi
[1] https://rekt.news/leaderboard/
[2] https://medium.com/@omniscia.io/euler-finance-incident-post-mortem-1ce077c28454
[3] https://www.investopedia.com/terms/l/loantovalue.asp
[4] htts://www.paradigm.xyz/2023/05/blend
[5] https://github.com/euler-xyz/uni-v3-twap-manipulation/blob/master/cost-of-attack.pdf
[6] https://medium.com/chainlight/the-suspension-of-compound-finances-ceth-market-causes-and-solutions-b106c2e1c922
http://www.nascent.xyz/idea/youre-writing-require-statements-wrong
https://www.nascent.xyz/idea/why-defi-is-broken-and-how-to-fix-it-pt-1-oracle-free-protocols
This article is from a submission and does not represent the views of BlockBeats.