New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Veiled Oracles: A fair, liveness-preserving method for enshrined information feeds

ETHBerlinThu, Jun 19, 2025, 09:39 AM · 21:40

Enshrined oracles have long been controversial, because in extreme conditions they put pressure on the protocol to either fork or gaslight some of its users. We present an "intents"-based method called Veiling, implemented in about 100 lines of code, that is a provably optimal way to address the classic concerns directly.

Transcript

Thanks everybody, thanks to the morning crew for coming out right as the door is open and hanging out in the theater with me. So yeah, talking about veiled oracles, weird tricks for preserving liveness and maybe having the protocol be honest about what it knows. This will be lightly mathy toward the end, but also probably approachable, we'll see, you tell me. Okay, so quick about me slide I just threw in because these are good ideas to do. I'm an econ game theory PhD, I feel like that's important to actually stress here so it sounds more credible what I'm presenting.

I've been doing crypto economics since 2018, I was head of research at Pantera Capital and then block science previously, maybe some of you know it. And then yeah, earlier this year I got nerd sniped to work on some fun, hard, weird problems like oracles. What I do doesn't really have much to do with what I'm presenting, this is kind of a like fun skunkworks weird thing that came out that seems very useful and interesting and deserves to be experimented with, so I'm excited to tell you about it. But I guess just to sort of like set the stage, you know, I think this thing is probably going to seem weird, but then you think about other things that might have seemed weird, maybe like XY equals K or fruit jerky and things like that that seemed weird at the time that turned out to work. Hopefully it's one of those, maybe it isn't, but maybe I can convince you that it's worth some experimentation.

So flashback here to how people used to like lose money back before, you know, meme coins started. In America we have a thing called the Super Bowl, everybody, a lot of people bet on it and there are these things called prop bets, these silly little bets. The most popular one by far going back 10 years is what color is the Gatorade that gets dumped on the winning coach, that's a weird Super Bowl tradition. And people bet millions on this every year. Here's the historical data on how many, on the colors, does anybody want to like, you all have funny money, you know, does anybody want to bet on a color here, given the historical data?

You can shout it out. Orange, good guess, right? The future resembles the past, so orange. Maybe somebody out there is thinking purple, that'll just help me with my example, okay? So we've got a bet for orange, we've got a bet for purple.

And look, we'll just say we have a trusted oracle that's going to report the exact color, right? So we can just run this all in a smart contract and whatever and you can bet it in like a prediction market, right? And then this happens. So this happened in 2015. Orange and then purple got dumped on the Super Bowl coach.

Or maybe it was purple then orange. It could have been the two colors at the same time, but the point is, we thought we were betting on something that made sense, right? Is it going to be orange? Is it going to be purple? And what did we get?

We got this thing that is two answers, right? And the value in the middle makes no sense, right? For orange or purple, I don't really know how to do that, right? There's no sense in which like the solution in the middle is the correct answer. It's just both or one or the other or something.

And if I pick purple, orange here is unhappy, right? And if I pick orange, then purple is unhappy. It seems unfair. I don't know what we do with this. We thought it was a sensible question.

It wasn't. But there's other problems that have these kind of hump shapes, right? This kind of convexity problem, right? You have latent information. One price that gets reported or one piece of information gets reported is stale.

The other one's fresh. The protocol doesn't know which is which. And it's not the truth that the value in the middle is better than either of the sides. It's that there's one of them and not the other, and we don't know which. And then there's another one, misinformation, right?

You get truth, you get lies. And it isn't that in between a truth and a lie is the truth. It's that one of them is the truth and you don't know which. So these problems, which are convex problems, right? You apply concave solutions to them, you don't always get what you want.

This is about how to handle this hump-shaped problem directly. So let's take a more specific applied example. On-chain lending protocol, like a compound or an Aave or something, right? You stake collateral to take out loans. The protocol is going to enforce margin positions on behalf of both the borrower and the lender, right?

So the protocol is trying to represent both sides of this market fairly in some sense or another. Well, there's just error modes in both directions. If an oracle price gets pushed that says the collateral is undervalued, right, then you can liquidate. And if the oracle update was a lie, then everybody's mad. It's a bad liquidation.

You're too trusting of this one oracle update. This happened in 2023 with Silo Finance. The stake in oracle value was pushed. I think something like $12 million in bad liquidations happened. Everybody's mad.

Okay, well, let's be cautious instead, okay? We shouldn't just believe every single oracle update that comes through. Let's look back at the prices, the way they changed over time. And we'll go, well, look, if a price seems too far away from the way prices have changed over time before, let's kind of throw that new price out. No, that can mess you up too, right?

This happened in 2024. I think it was Compound V2 did that exact thing, what I just described. And the UNI token happened to be so volatile that the new price looked wrong but was correct. That means you didn't liquidate in time, maybe, right? The price is now falling.

The lenders say, hey, liquidate, man. Liquidate before the price falls even further. And we're like, no, we don't believe it. We think the price is higher. Now the lenders are mad.

So in either case, the protocol is trying to serve both sides. When it just doesn't know the answer, you have a failure mode. So here's a juicy guy from Goodwill Hunting saying, look, man, you're just not doing anything with protocols. The problem you have is that you've got these lovely commitment devices. But the price you pay for these commitment devices is a latency penalty, right?

You have to have this redundancy of having everybody talk to each other or enough people talk to each other so you get the commitment. And that means whenever you have the commitment, by the time you have it, somebody else has more information than you. You're committing, but in game theory terms, you're committing in a game that has second-mover advantage. That's not a game where commitment helps. You don't want to be first-mover in a game with second-mover advantage, commitment or not.

Well, so, you know, and then instead of Will, we have the mid-curve guy going, but like, what if we just get fast enough? Like, what if we solve governance? What if we just hire the right mechanism designers and put in the right mechanism? Then maybe we can overcome this problem that can look a little fundamental, at least, you know, here in the Boston bar. And look, this is me most of the time.

I'm usually the crying mid-curve guy trying to, you know, speed things up and add new mechanisms that are going to make it better. Solve governance. I love all this stuff. It's important. I'm not nay-saying any of it.

But this is an alternative that looks very promising. It's not an alternative you do instead. It's just a complementary alternative, something else you can add. So what's the problem? Shout out to the act I'm opening for here, Barnaby, who has seemed like protocol, just slightly cribbed it.

But protocol here wants to be fair, live, truthful, right? In, let's say, the situations we described above. But we have multiple priors. We have the two-humped problem. We don't know which is which.

And we're ambiguous between the two. One might be the answer. The other might be the answer. There's no real sense to the value in the middle. But we do have some tools.

We do have encryption. And we do have this commitment. Turns out you can do something very, very cool with encryption and commitment that can solve that in the math. And will it solve it in real life? Maybe.

We'll talk about that. So one solution, though, of course, is you can just fork, right? When things go wrong, you just sort of say, well, look, I don't know. We picked one. And if you don't like it, start a new chain equivalently.

That is a careful and seriously reasoned-through solution. And it can work in some applications. This one's different. This one preserves liveness. So the idea here is the protocol represents the information it actually has, which is could be this, could be this, don't know.

And then it uses commitment so that if you're going to interact with me, the protocol, in this case, you're going to have to be as dumb as me, provably as dumb as me. Instead of trying to make the protocol smarter, you try to make the people who interact with it as dumb as the protocol is in some cases. So here's the mathy bit. I'm not going to go through it. You're welcome to click the picture here.

But basically, what you're producing is you're producing, and we have this hump shape, right? You're producing could be this, could be this. But there is no expected value at all in between. And what that looks like, basically, is that there is a thing called machine two. And it can generate sequences that stay as close to that one hump for as long as you like and then arbitrarily at any time switch to the other hump and stay there as long as you like.

Mathematically, what it does is it says there's no expected value between the two, but it does preserve the bounce. Could be this thing, could be this thing, period. There's some fun citations in this one. Welcome to go through it and encouraged to go through it and feel free to message me if you do. But here's what it looks like if you've ever seen the like, you know, Scouts 101.

Here's what a bias coin or here's what a coin flip looks like, right? You know that the first thing, right? Like column one, row one is what it usually looks like, a fair coin flip. It gets to be about 50-50 or something close. This is the world's craziest, most unfair coin flip.

You'll find no pattern up, down, sideways, across, or anything. It is a pathological RNG that has no pattern whatsoever but stays within bounds, does one or the other. This is currently running in a TEE. You can commit to resolve something with it. It's just a single TEE, so maybe don't yet, but it shows that you can do it.

So what does this do? This is going to be a little further than Scouts 101, but not too much further. How do you do this? How do you destroy learning between these two bounds? You have to do a couple of fancy fun things.

It's called a Cauchy oscillator from Scouts physics, but here's how it basically works. You start with a nightmare distribution called a Cauchy, already bad. And then you go, well, hey, you can still learn a few things from this. You can like give sample or something. And you say, no, I'm going to make it non-stationary.

I'm going to make it recursive, second-order recursive. So now you're feeding a Cauchy into a Cauchy. Now it gets even messier. And then you go, but what about the law of large numbers? Didn't I hear that that's a pretty robust thing?

Can't you always learn something a little bit over time? No, you randomize the sample size. Sorry, you can't use law of large numbers either. And then you're like, well, what about like time series analysis? I took an econ class and I learned about like autoregressive conditional heteroscedasticity or something you dimly recall.

Now you can't do that either, right? You resample and you index with a different non-stationary Cauchy. And this all sounds very complex. It's actually about 100 lines of Python. It's really quick.

It's really trivial. You can generate 500,000 of these runs in, I don't know, a second or two. Not too bad. So it's not that big a deal, but you really can't learn anything from it. You flatten it onto these bit intervals.

I said 4 and 17. You could do it orange and purple. You could do it whatever, right? Ultimately, you're flattening onto the interval of the two things you don't know. And then lastly, just for any real hardcore, like, you know, less wrong comment section folks in the audience, you might go, well, aren't these like there are these generalized learning things?

Couldn't I still learn something over time? Or isn't there like a theoretical thing called a Solomonov inductor or whatever? Yeah, but if we admit only a single value per run and charge you for it, we'll bleed you dry there too. So really, you just can't learn anything other than it's going to be this or this. That's what you get out of all this chaos and messiness.

And that's a cool property. Once you add commitment to it, you add encryption, because if you don't encrypt it, people know what it's going to do. It defeats the purpose. And then if you commit to resolve to it, you get something very powerful, which is that the other side of the trade can only know what you know. If you know it could be this, could be this.

The other side knows only could be this, could be this. Sounds interesting. This is novel. It's crypto specific. It is a generalized, what's called in the game theory literature, an ambiguous device.

But this is a generalized ambiguous device. So you can use it for anything, as far as we can tell. Has not been tried much. It is the correct way to represent the protocol's information in that two-hump case. If you don't know between the two, this is how you say, I don't know.

And here's the part that's mind-blowing for me anyway. It actually improves welfare in positive-sum games. So sometimes when you read the stats, people will go, but wait, it's weird that a thing doesn't have an expected value. But it's not that weird for distribution stats to have an expected value. There's, you don't usually cover them, but there's all kinds of distributions that don't have integrals that converge.

But it is weird to have a Nash equilibrium be Pareto-dominated by another equilibrium. Feels like, well, isn't that what a Nash equilibrium does? So I'm going to show you a little bit about why that to be. First, shout out to the guy who taught me game theory, Ben Moore, Ken Ben Moore, the great game theorist. He founded this in 2008 and kind of blew everybody's minds.

This is in a game called Battle of the Sexes. Maybe you've heard of this one. It's like, I'm going to go to opera, you're going to go to boxing, and so on, right? Well, the equilibrium of that game, if you use this ambiguous device, you can do better than the standard mixed-strategy Nash. I don't have permission to play the video, but all it's going to show you, just a permissioning thing, is that two-humps thing we were showing earlier.

You can kind of see how it resembles, if you turn it sideways, this payoff graph from Battle of the Sexes. So you're already getting maybe a little bit of a flavor of how you can take a sort of convex problem and improve welfare using this ambiguous device, this machine too. How does it work? Okay, so my clicker is not working. There we go.

Okay, so this one will take a second. Okay, okay, cool, cool. So this is showing you why it can work. Those red dots there are the Nash equilibrium payoffs. The graph is the lighter the color, the more each player gets.

The first player is on the left, the second player is on the right. You can think of them as purple or orange, borrower or lender, protocol versus arbitrager. Pick whatever you want in this game, right? And what we have is a Nash equilibrium where, on the first one, the guy on the left earns zero. It's that dark color below, that little bit of dark color.

And the person on the right earns something like 1.3, which is that dark color for them as well, the one that's meeting. And then the green part is what you get when you do the ambiguous draw, the veiling. When you commit to encryption. They're trading now, instead of those points, those little red points, they're trading those green boxes.

And so what you can get a sense for if you squint is why it's an equilibrium. So if you look at those bars and you think about sliding one to the left or sliding one down, right, you can see why they suddenly lose a little bit, right? If you slide it in, you make a little bit less. If you slide it out, you make a little bit less in every case. That's the equilibrium property you get.

But then what you can also see, and this is the part that, you know, even if you're not totally tracking what's going on in the graph, you'll definitely be able to see, is that on the left side, rather than having that bad dark color, that thing that's at the little sliver of the bottom of the left, you now have this whole big light looking space that you get to lay claim to, right? So this is just positive. Some games are weird. Sometimes you find a Nash equilibrium and there's a whole bunch of positive stuff that you can't get to because it's not an equilibrium, usually under convergence, but you can get it under non-convergence. And then what you're trading with on the right is something that's symmetric.

In this case, it actually keeps the person at their same payoff. There are other equilibria where both do better, but this is one where player one does a lot better. So this is sort of, it doesn't matter if you don't totally follow this, this is giving you a peek under the hood of how this can be welfare improving over a Nash. In positive-sum games, they have often these complex topologies where both players can kind of do better. You can find these topologies and trade them instead of trading these points, and it can make both players better off.

Very interesting property. And you can apply it, for instance, for AMF. So this is an application for making impermanent loss impermanent again. And this is actually very simple. It's kind of a simple demonstration.

In the left here, you have an excludability game. It's just one way of modeling the liquidity provider's problem. The liquidity provider's problem is, I'd like to be profitable. Like, I'd like to have fees that net more than my impermanent loss. And they're trying to get to this region over here, that beautiful green region where they can make some money.

And there are papers showing that maybe over time, under some adversarial arbitrage or conditions, right, maybe they just can't. Maybe, you know, impermanent loss is permanent. And in this game, we have the Nash converging right before they hit zero. So they can't be profitable. Take the same game.

Add Veiling. Add this machine to draw and commitment. How do you do it? Maybe you do it in, you know, certain large trades. We'd have to think through the exact way you apply it.

But what it shows in the math is that instead of getting that little red dot point, you can get that entire blue region, right? And if you, you know, the visual intuition is pretty good here, right? The blue region looks better than the red dot. You can see that the blue region peaks a little bit below the red dot. So maybe you lose in some states of the world a little more.

But you can also get all the way to your highest payoff. So very, very interesting. And I'm tempted to say you make more. But the problem is that sounds like I'm talking expected value again, and I'm not allowed to do that. We're just saying this is the region of possibility, right?

And the region of possibility looks better than that little point to most folks. But what does it actually look like? And in practice, what you do, what is the cost of this, right, is the trade resolution is very, very ambiguous. You might get this. You might get this.

That's what's going to happen. And so the question becomes, as you start to think about application, are users going to like it? I don't know if users are going to like it, right? The ask is, look, you are not going to know what price this trade resolves to under maybe these extreme conditions. But what do you get right now?

You know the trade, your trade, or you know the price your trade is going to resolve to. But you also know you're going to lose money. You also know that probably that trade is with somebody who knows more than you, with an arbitrager who's going to take the money from you. So we can eliminate the you're going to lose money on the trade, but we're going to replace it with you're not going to be totally sure what the price that your trade is going to resolve to. And you can check out the draft of this one if you want to read more.

So is veiling weird? It seems pretty weird, right? But I'm going to close by arguing that maybe it's not so weird. So if I got up here and I was just like, here's some standard game theory, and the mixed strategy equilibrium is great, and therefore we should be really, really happy, because I've shown in the math and standard game theory that we all know that this mechanism will improve things. Everybody goes, yeah.

But mixed strategies are actually super weird. That's one of the ways we find a Nash equilibrium. They're weird because they're originally concealment devices. The whole point of a mixed strategy, right? You're doing a penalty kick in soccer.

And when you do a penalty kick, you do a mixed strategy between kicking left, kicking right. I know this is overly simplistic, but I'm American and I did the Super Bowl earlier, right? So let's just say kicking left, kicking right. Which one do you do more often? You randomize 50-50, right?

Because otherwise the goalie knows your tendency. So it's a concealment device. There's a sense in which this offers better concealment, right? Seems to. You can't learn a tendency.

It never converges. And then you see some real world examples. For instance, you can find this in the literature, in the game theory lit. The contracts are frequently written ambiguously. When you look at your contracts for your job, you'll find that it does not detail all your particular roles.

That, in fact, some of the language is vague and you're not sure how a manager or anybody else would interpret it. And maybe that has some upside. There's the phenomenon of IPO book building, where people investing in IPOs are given a range beforehand. And then that range is resolved by a secret cabal of underwriters. So there's some ambiguity there and presumably trusted ambiguity.

And what we have in crypto is we have a very generalized version of that. We have generalized ambiguous device. And then is it weird? Yes. Is it weirder than, you know, like food trucky was or xy plus k?

Like I said, I'm not so sure. So I hope this gets experimented with and I'm interested in discussing it further. Unfortunately, I'm probably not doing much more with it, but I would love to in my spare time, just, you know, discuss it more and encourage any experimentation. So you want to check out the papers. They are here and appreciate your time.

Appreciate you joining me early. Any, do we have time for questions? All right. Cool. If we have any questions.

Thank you very much. Thank you. Thank you, Matthew. So I right now I don't see any questions, but if you guys have any questions, you can just scan the QR code here. And otherwise, we can just do a quick round of mics.

Yeah. If anybody wants to shout out a question, you're welcome to. So who wants to go back to any pretty slides? Any questions? All good.

Otherwise, you can. You did a good job. Yeah. Otherwise, you can catch Matthew after the talk. Thank.

Automatic transcript — names and jargon may be misspelled.