Hi!
I wanted to share my personal views and input here. By “network-level actors” in the text below, I’m referring to node operators but also other entities that affect on-chain operations, like bridge operators.
Future on-chain incidents and interventions
I believe Gnosis ecosystem participants should continue taking measures that prevent on-chain incidents from occurring in the first place. Protocols/DApps should not rely on network-level actors stepping in to save their users, and instead continue primarily relying on industry best practices.
In my opinion, the best possible outcome of this framework would be that network-level actors never need to step in again.
The simplest way to achieve said outcome would be to agree on a very simple framework - never to intervene on-chain. This is the easiest way to guarantee Gnosis Chain’s credible neutrality at the cost of not being able to rescue victim funds in case of incidents.
This is therefore the first question we should answer. There has been an intervention recently but that doesn’t mean there ever needs to be another one.
→ Do we want network-level actors to intervene in similar cases?
Therefore, on this point I strongly disagree with this statement from the “Legitimate Intervention Framework” that has been discussed in this thread:
The question is not whether to intervene, but how to do so legitimately.
Low-risk DeFi
I understand Gnosis wants to position itself as an ecosystem where low-risk DeFi thrives, and that is difficult to achieve when low-risk DeFi users risk losing all of their money through protocol exploits. This is the primary reason why the hardfork was likely even considered for the recent Balancer exploit – it affected a DeFi protocol that would, by many of its users, be considered low-risk DeFi.
If the Gnosis ecosystem indeed decides it is desirable to intervene when low-risk DeFi exploits occur, there should be a very strict and objective definition of that term (I am not currently aware of any such definition). Some of the conditions that DeFi protocols could need to fulfill to be considered low-risk:
- time test - the breached version of the DeFi protocol must have been live on-chain without a breach for at least X months before the incident
- security review test - the breached version of the DeFi protocol must have undergone security review(s) by X reputable independent firms
- TVL test - the breached version of the DeFi protocol must have maintained a TVL of at least $X for the last Y months
The point of these tests is to ensure the emergency intervention mechanism will not be abused for other purposes.
The bar should be as high as practically feasible – with DeFi protocols still taking every industry-accepted measure they can to avoid being breached in the first place. I think intervention should be considered a last resort if every other measure fails, and nothing could have reasonably prevented the incident from occurring.
Intervention mechanism
I may be stating the obvious but still, I want to make a note here that in blockchain land it is not always possible to rescue victim funds. Even if network-level actors were willing to intervene in a previously-agreed-upon scenario, this by no means guarantees they will be able to do so in time.
To stand a chance in situations where steps need to be taken quickly, some level of centralization seems inevitable. For instance, bridges need to be contacted quickly to ensure victim funds do not leave Gnosis Chain. There are many open questions here, like:
- Who is responsible for noticing a DeFi protocol was breached?
- Who should be contacted, how, and by whom?
- How should network-level actors verify a breach has occurred?
- What is the limit in terms of measures network-level actors may take during an intervention? (previous comments already alluded to this)
- What happens if the intervention fails?
- …
Non-retroactivity
There may be a desire to update this framework at some point in the future. This could be a minor parameter adjustment like an increase in the TVL test, or adding another security condition that DeFi protocols must fulfill to be considered low-risk. However, it could also be a larger change to the scope of this framework. In such cases it could be dangerous to allow a change to be retroactive - therefore I suggest any changes to the framework may only apply to future situations, not past.
Thank you to everyone who has joined this discussion so far.