5 risks that DeFi must know
DeFi governance and risk structure
More people began to pay attention to the topic of DeFi governance. And the memory of "Black Thursday" during the crypto market plunge in March this year has also exacerbated people's concerns about DeFi. There are concerns that the risk structure of DeFi is not well understood.
We believe that,
We believe that,In some DeFi systems designed with broad governance power and no social recourse, the participation of rational agents may be zero. That's because the cost of aligning incentives in these systems can be prohibitively high (it's like requiring a bank to trade at 1,000 times long-term earnings to keep depositors from stealing their money).
Our framework provides a way to model these systems and generates a set of unanswered research questions that will be key to DeFi moving forward.
Compound
One of the recent hot news in the DeFi field is the issuance of Compound’s COMP token, which has become a leveraged risk circus. Driven by the reward mechanism, users have played a crazy game of leverage.
You can see this happening on the Ethereum network. Traders carry out COMP liquidity mining (Yield Farming) by maintaining complex multiple positions: for example, deposit ETH and USDC, lend a large amount of BAT tokens; and then re-deposit BAT to a new Compound account to borrow Send out ZRX tokens, deposit ZRX to previous accounts, lend more BAT tokens, etc. (Translator's Note: Yield Farming, which means that token holders deposit funds into the platform to provide liquidity for the platform, and obtain token incentives provided by the platform, which is for liquidity mining)
You may not have thought of this kind of operation before, but don’t think about it because of this article: God’s operation, I will try it too! We are obliged to emphasize: this kind of operation has accumulated the risks of layers of leverage, especially in low-liquidity markets like BAT and ZRX. The risks are worth writing an article for your own analysis. Just think about the multiple liquidation on Black Thursday! This illiquid market is easily manipulated and easily attacked, and others may use it to trigger the liquidation process and profit from your losses.
use high-risk assets"Yield farming"Extremely dangerous and easy to hang up. Don't use users' funds to join BAT liquidity mining with high leverage. Everyone, let's have some snacks!
If its goal was to increase audience reach, COMP's release has certainly accomplished a lot. More obviously, Compound has temporarily increased liquidity yields, solving the “chicken or the egg” problem of platform usage. Ironically, it provides the platform for large-scale stress testing.
Among the many reports, Compond's initial goal is less talked about: to foster "an increasingly large ecosystem […] that will have the incentive to co-manage the future of the protocol with good governance".The COMP token distribution essentially seeks to achieve a broader distribution of governance rights among platform users, allowing users to manage their own security.
How to design the incentive mechanism so that the interests of the participants are aligned is a broader issue in the entire encrypted economic system. Taking stablecoins as an analysis background, we have created a framework to quantify the incentive problem. This framework can be widely applied to encrypted economic systems.
We pose a fundamental question of incentivized security in a system: [Incentive-Security] After accounting for the attack scenario, is it still mutually beneficial for all parties involved to continue to participate?
If not, then the system cannot work because the equilibrium participation is zero. For example, if incentives make attacks profitable, then rational actors will price this risk when deciding how to engage. Only after answering this question can we understand the question of economic stability.
[Economic Stability] Are the incentives in the system producing stable outcomes?
Are the incentives sustainable?
From the model we built, how to provide continuous security incentives to resist governance attacks as the scale of the system expands? This question is critical. A governance attack is profitable if the attack reward is greater than the attack cost.
The reward is proportional to the locked asset value (AUM) in the system: if the governance power is strong, the collateral can be directly stolen (and the related liquidity pool on the DEX is emptied); even if the governance power is not so strong, the collateral assets can still be stolen indirectly, This can be achieved even with time delays in governance by manipulating parameters and preventing users from exiting.
honest"honest"For the governance, the basic value of the governance token value comes from the accrual of future governance fees, as well as institutional responsibilities (such as legal recourse).
Stablecoins, synthetic assets and cross-chain assets
For non-custodial stablecoins (and synthetic assets using similar mechanisms and cross-chain assets of BTC), the value of security governance needs to exceed the value of locked assets, which is a multiple of the latter. Scale issues arise when considering a long-run equilibrium with modest future growth expectations, where the present value of future fees (even with an unrealistically high percentage of AUM, the value of assets locked in the system) cannot Reach the level of AUM multiples.
In this case, the security of the decentralized governance system will depend on system participants holding governance tokens holding large numbers of governance tokens to increase their market value. This will feed back into the participation incentives of these other parties, and there is no guarantee that balanced participation will exist.
For example, stablecoin holders may need to hold a large number of risk management asset positions in order to ensure their stable positions, which may defeat their purpose of holding stablecoins. This leads us to an informal conjecture (and an important direction for future research!).
[Conjecture] In many DeFi systems designed with extensive governance rights and no social recourse rights, the participation of rational people may be zero under equilibrium conditions.
The point is that the cost to participants of aligning incentives in these regimes can be prohibitively high. Let's use the analogy of the bank situation: if the incentive mechanism to achieve safety requires that the bank's stock market value must be a multiple of total deposits, then it is simply not cost-effective for depositors to participate. In other words, the long-term P/E ratio of the bank needs to reach about 1000 (and supported by depositors) to ensure that the bank does not steal depositors' funds.
The currently implemented solution is basically centralized governance. This solution relies on a form of institutional accountability, which can be described in our model. This situation is not necessarily problematic. In fact, many traditional financial systems work this way. That's why banks don't need to be worth multiples of total deposits. Yet we should openly acknowledge that the existence of such trust may be crucial. Solving these problems in a fully decentralized manner remains an open problem.
Decentralized Exchange (DEX)
These incentive models also make sense for some DEXs.
For example, if a DEX runs its own independent blockchain (this chain is jointly controlled by the DEX's governor), when an attack occurs, the governor can restrict the users who have provided liquidity to the platform so that they cannot exit, even after the governance The same is true in the presence of time delays.
In a DEX, fee accruals ('honest' governance earnings) are proportional to a fraction of total volume over a period of time, which can be many times the exchange's instantaneous AUM value, while incentive security is still tied to AUM.
For Uniswap, the annualized transaction volume can be about 100 times the deposit. In contrast, the accrued fees incurred by a stablecoin system may be about 1/4 of the deposit supply. Governance accruals are likely to be much smaller for DEXs compared to stablecoins, but this ~400x factor makes the feasible region for incentive security against governance attacks in DEXs potentially larger. This leads us to the following informal conjecture comparing the viability of different types of DeFi applications.
[Conjecture] Compared with stablecoins, DEX is more economically immune to governance attacks.
loan agreement
loan agreement
With the above preliminary discussions, let's go back to mortgage lending agreements, such as Compound. These have a similar structure to non-custodial stablecoins. However, they are somewhat simpler because borrowed assets are largely exogenous. Due to this exogenous nature, it may be easier for participants to exit the system before a governance attack succeeds (i.e., during the governance time delay).
Consider, for example, that the asset being borrowed is USDC; in this case, the vault can deleverage and exit at any time by the issuer creating new stablecoins at par (specifically, when they want to exit, they does not depend on Dai holders selling Dai back to them). Governance delays are inherently a stronger prevention tool in this environment, though exceptions may be made if complex price feeds and/or miner-extractable attacks are involved.
text
Data from Compound on June 23, 2020
That leaves a question: Does the COMP token distribution process help incentivize user alignment in the long run? That is, does it reduce user costs while defending against governance attacks? At first glance, this looks promising. Users earn governance shares through participation, so they don't have to consciously inflate the governance market value in order to secure the system -- they just don't have to sell their earned COMP shares.
But once users are gifted shares, which become part of their portfolio, they will choose whether to maintain this risky position. While the distribution of COMP has undoubtedly attracted many new users to the Compound platform, it is still an open question whether the distribution mechanism of COMP (or any other distribution mechanism for that matter) will help bring the system to a more stable governance balance.
Stablecoins: Design, Model and Risks
Below we start with several typical types of stablecoins and describe the dimensions of risks and trade-offs of different functional components.The difference between custodial stablecoins and non-custodial stablecoins is obvious. The former relies on some kind of trust in a third party, while the latter aims to be trustless.
The figure summarizes and analyzes stablecoin design according to some of the most important risk dimensions
Managed Stablecoins
In terms of custodial stablecoins, there are three different types of stablecoins, all of which maintain the peg through the work of arbitrageurs, who can create/redeem stablecoins for the underlying. The reserve fund of the stablecoin maintains a 100% reserve ratio, just like a dollar ETF on the blockchain. Examples include TUSD, USDC, and later iterations of Libra.
The second type, including Tether, is a fractional reserve mechanism similar to a bank or money market fund. Such stablecoins face the risk of de-anchoring similar to banking operations. This was the case with the Tether stablecoin (USDT) in October 2018. Tether’s crisis ensued when its partner exchange, Bitfinex, suspended the exchange of USDT for fiat currency. As funds flowed from Tether to assets with less credit risk, the currency’s anchor to the US dollar was broken, and arbitrage The latter was unable to re-peg Tether to the US dollar at the time.
bank"bank"May be less regulated and audited, and may not have a government guarantee to deal with a bank run.
In October 2018, Tether was de-pegged from the US dollar
The third type of stable currency is issued directly by the central bank. At present, the central bank only provides reserve deposits to commercial banks, while the goal of CBDC is for the central bank to provide consumer-oriented deposits, possibly in the form of tokens.
These custodial stablecoins face similar risks to the traditional financial system. These risks mainly come from counterparty risks, such as the risk of a custodian defaulting on its pegged value obligations. A related risk is the risk of scrutiny, whereby custodians selectively choose which claims to honor.
Non-custodial stablecoins
The characteristic of non-custodial stablecoins is that they no longer depend on specific custody institutions like managed stablecoins. Instead of these social institutions are economic structures, through smart contracts, an economic system is established among the participants.
Non-custodial stablecoins are structurally similar to dynamic versions of risk transfer instruments such as Collateralized Debt Obligations (CDOs). CDOs are backed by a pool of collateralized assets divided into different credit tranches (tranches). When a loss occurs, the lower credit tranche absorbs the loss first, and after all the lower credit tranches are liquidated, the higher tranche absorbs the loss.
In our research paper, we provide a general idea that can decompose the design of all non-custodial stablecoins into the following functional components. The diagram below draws several stablecoin designs and describes how they are related to each other in the form of some components.
main value. The economic structure of the stable currency value base mainly comes from market expectations under a certain system. Divided into three types. a) Exogenous collateral: In addition to the stable currency system, collateral has other uses, such as ETH in Maker.
b) Endogenous collateral: The goal of creating collateral is to act as a collateral for stablecoins.
c) Implicit collateral: In this case, instead of using explicit collateral, market mechanisms are used to dynamically adjust supply to stabilize prices. This is similar to endogenous collateral, but with an important difference in the obligation to absorb losses.
Risk Absorbers: At some level, some speculators absorb financial risk in search of profit (similar to junior tranches of CDOs). This could be an individual principal participating with collateral, a separate equity-like position in the network, or a participant acting as a miner (or validator) in the network.
Stablecoin holders: the main body that constitutes the demand side of the stablecoin market (similar to holders of CDO's senior credit tranche)
Issuance: The subject or algorithm that determines the issuance of stablecoins. It can be determined by multiple individuals in the system, or it can work through algorithms.
Governance: The body or algorithm that manages the parameters of the protocol, similar to a stock position when managing a CDO.
Data provider: Import the data of external assets to some functions of the blockchain.
Miner: Determines the individual who verifies and packs transaction operations in the basic blockchain layer.
The way different non-custodial stablecoins are designed shows how several components are interrelated.
Such non-custodial stablecoins introduce new risks, so existing financial models cannot"unpack"use. Here we discuss three of these new types of risks.
deleveraging risk
First, there is the risk of a downward deleveraging spiral, where the level of debt maintaining a stablecoin is reduced too quickly, causing the peg to be broken.
This risk is substantial. For example, during the 36-hour period ('Black Thursday') of March 12-13, 2020, coronavirus-related market turmoil saw crypto markets lose 50% of their value. On the ETH network, this leads to network congestion and high gas fees, which in turn slow down transactions and cause transactions to fail.
This poses serious problems for Maker's Dai. Collateralized position holders (Vaults) struggle to deleverage as they cannot increase collateral or repay their Dai debt. The Keeper either cannot obtain Dai liquidity quickly, or cannot participate in all debt auctions. Someone even started bidding on ETH for close to 0 DAI, getting about $8 million in ETH almost for free.
Impact on Maker Dai price when Black Thursday happened in March Source: OnChainFx
We summarize several noteworthy non-custodial stablecoin deleveraging events as shown in the table. These events deserve to serve as case studies for designers of stablecoin projects.
Risk of oracle failure
Secondly, the oracle service that provides data to the blockchain from the outside may also fail. This could be accidental or the result of an attack. Again this risk is significant and has occurred several times - we have summarized notable incidents in the table below.
For example, in June 2019, an error in the FX price feed caused the price of KRW (Korean Won) to skyrocket on Synthetix. At 3am Sydney time, one of the price feed APIs started intermittently failing, resulting in prices being offered that were 1,000 times higher than the current Korean Won exchange rate. Although there is a defense mechanism to discard outliers, but a series of misfortunes and coincidences, in the actual calculation, the oracle still uses this greatly inflated price. Several trades turned out to be 1,000x profitable, resulting in profits of over $1 billion in less than an hour.
Several incidents of price feed failure
Governance Attacks and Miner Attacks
Smart Contract Risk
Smart Contract Risk
Because of the way stablecoins are algorithmically enforced, errors in their specification or implementation can have serious repercussions without any specific institutional oversight. From a modeling perspective, smart contract risk is similar to counterparty risk (in this case, the risk of bugs in execution).
The diagram below shows what happens when this bug is exploited maliciously. Due to a re-entrancy bug, the locked assets in the lending protocol dForce were stolen, from $25 million to $19,000 in a few hours.
Build a risk-based economic foundation
We propose a series of models that can serve as the basis for risk analysis of these risks.
We propose an ensemble of models borrowed fromcapital structure model. Taking inspiration from models developed in the context of initial public offerings (IPOs), we adapt these models to capture the incentives of governance token holders, stablecoin holders, and risk absorbers.
The second type of model isbifurcation model. The capital structure model considers only a single time step: based on the agent's expectations, they will choose to perform certain actions in the next round. The bifurcation model is an extension that considers multiple rounds of agency decisions.
The third type of model isPrice Dynamics Model, which simulates the interaction of different individuals in a CDO-like structure, combined with the feedback effect in the stable currency system.
Disclaimer: This article is the author's independent opinion, and does not represent the position of the Blockchain Institute (public account), nor does it constitute any investment opinion or suggestion. This article has been deleted without changing the original intention.
original:https://medium.com/
-END-
Disclaimer: This article is the author's independent opinion, and does not represent the position of the Blockchain Institute (public account), nor does it constitute any investment opinion or suggestion. This article has been deleted without changing the original intention.


