Papers
Topics
Authors
Recent
Search
2000 character limit reached

Short Squeeze in DeFi Lending Market: Decentralization in Jeopardy?

Published 8 Feb 2023 in cs.CR and q-fin.RM | (2302.04068v2)

Abstract: Anxiety levels in the Aave community spiked in November 2022 as Avi Eisenberg performed an attack on Aave. Eisenberg attempted to short the CRV token by using funds borrowed on the protocol to artificially deflate the value of CRV. While the attack was ultimately unsuccessful, it left the Aave community scared and even raised question marks regarding the feasibility of large lending platforms under decentralized governance. In this work, we analyze Avi Eisenberg's actions and show how he was able to artificially lower the price of CRV by selling large quantities of borrowed CRV for stablecoins on both decentralized and centralized exchanges. Despite the failure of his attack, it still led to irretrievable debt worth more than 1.5 Mio USD at the time and, thereby, quadrupled the protocol's irretrievable debt. Furthermore, we highlight that his attack was enabled by the vast proportion of CRV available to borrow as well as Aave's lending protocol design hindering rapid intervention. We stress Eisenberg's attack exposes a predicament of large DeFi lending protocols: limit the scope or compromise on 'decentralization'.

Definition Search Book Streamline Icon: https://streamlinehq.com
References (17)
  1. Aave. https://aave.com/ (2022)
  2. Eisenberg Tweet from Nov-20. https://twitter.com/avi_eisen/status/1594293743 380615168?cxt=HHwWgMCinc7tiKAsAAAA (2022)
  3. Report on code at risk: An In-depth Analysis of How AAVE’s $1.6 Million Bad Debt Was Created. https://drive.google.com/file/d/1u3vtcsQ1qfclt6Od8aZx5DkvuQRE4GMH/view (2022)
  4. Risk Parameter Updates for Aave V2 ETH Market (2022-11-12). https://app.aave.com/governance/proposal/?proposalId=117 (2022)
  5. Risk Parameter Updates for Aave V2 Ethereum Liquidity Pool (2022-11-25). https://governance.aave.com/t/risk-parameter-updates-for-aave-v2-ethereum-liquidity-pool-2022-11-25/10824 (2022)
  6. 1inch. https://app.1inch.io (2023)
  7. Aave V3 Risk. https://docs.aave.com/risk/ (2023)
  8. Binance API. https://github.com/binance/binance-public-data (2023)
  9. Chainlink. https://chain.link/ (2023)
  10. Chainlink. https://twitter.com/avi_eisen/status/1582763707742183424 (2023)
  11. Curve. https://curve.fi/ (2023)
  12. Mango Markets. https://mango.markets/ (2023)
  13. Mango Markets Mangled by Oracle Manipulation for 112M. https://blockworks.co/news/mango-markets-mangled-by-oracle-manipulation-for-112m (2023)
  14. Wallet of Avi Eisenberg: 0x57e04786e231af3343562c062e0d058f25dace9e (2023)
  15. Wallet of Curve Founder: 0x7a16ff8270133f063aab6c9977183d9e72835428 (2023)
  16. Eigenphi: Cleaning Up of the Battlefield of Avi and Curve. https://eigenphi.substack.com/p/cleaning-up-of-the-battlefield-of (2022)
  17. ledgerwatch: Erigon. https://github.com/ledgerwatch/erigon (2023)
Citations (5)

Summary

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.

Collections

Sign up for free to add this paper to one or more collections.

Tweets

Sign up for free to view the 2 tweets with 1 like about this paper.