{"id":31911,"date":"2020-11-17T17:27:45","date_gmt":"2020-11-17T15:27:45","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=31911"},"modified":"2025-08-28T06:03:25","modified_gmt":"2025-08-28T03:03:25","slug":"analysts-uncover-a-loophole-in-makerdao-that-could-let-users-dodge-liquidations","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/analysts-uncover-a-loophole-in-makerdao-that-could-let-users-dodge-liquidations\/","title":{"rendered":"Analysts uncover a loophole in MakerDAO that could let users dodge liquidations"},"content":{"rendered":"<p>Users of the DeFi project MakerDAO can split CDPs (collateralized debt positions) into small tranches and evade forced liquidations if collateral falls below the 150% threshold. This vulnerability was discovered by Yaron Velner, head of B.Protocol.<!--more--><\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">B.Protocol backstop, having more tangible incentives, did liquidate such small Vaults.<\/p>\n<p>Takeaway: When the incentives are not clear, the liquidators\u2019 expected behavior is also not clear.<\/p>\n<p>The full report can be found here: <a href=\"https:\/\/t.co\/CpUzufdYSd\">https:\/\/t.co\/CpUzufdYSd<\/a><\/p>\n<p>\u2014 B.Protocol (@bprotocoleth) <a href=\"https:\/\/twitter.com\/bprotocoleth\/status\/1328338763639042048?ref_src=twsrc%5Etfw\">November 16, 2020<\/a><\/p>\n<\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Velner found that borrowers in MakerDAO can resort to a trick by splitting CDPs into components of around $100. In this case, the <a href=\"https:\/\/makerdao.com\/ru\/whitepaper\/#%D0%B0%D1%83%D0%BA%D1%86%D0%B8%D0%BE%D0%BD%D1%8B-%D0%B2-%D0%BF%D1%80%D0%BE%D1%82%D0%BE%D0%BA%D0%BE%D0%BB%D0%B5-maker\" target=\"_blank\" rel=\"noopener noreferrer\">auction keepers<\/a> would not liquidate these positions after collateral falls below 150%.<\/p>\n<p>The reason lies in the difficulty of calculating the profitability of such operations. It is likely related to the high fees in auctions. Typically, participants in such auctions are bots configured in a particular way.<\/p>\n<p>The expert explained that, via this ploy, users could theoretically close the position later and avoid a 13% liquidation penalty.<\/p>\n<p>Velner declined to specify how long this phenomenon may last, as the behavior of the keepers in such cases defies precise prediction.<\/p>\n<blockquote>\n<p>\u201cWith a $1 million vault, gas costs to split it into 7,800 vaults would amount to $5,000. In other words, protection against future liquidations would cost only 0.5% of the vault size,\u201d the expert calculated.<\/p>\n<\/blockquote>\n<p>The founder of B.Protocol ultimately questioned whether there really is a liquidation ceiling at 150% when keepers rely on such vague heuristics.<\/p>\n<p>In an interview with <a href=\"https:\/\/www.coindesk.com\/makerdao-loans-collateralized-debt-liquidation\" target=\"_blank\" rel=\"noopener noreferrer\">CoinDesk<\/a> some DeFi arbiters explained that lending protocols Aave and Compound are significantly simpler than Maker. When working with them, users do not have to think about anything other than having sufficient liquidity.<\/p>\n<p>MakerDAO currently leads DeFi Pulse&#8217;s ranking by value of assets locked.<\/p>\n<div id=\"attachment_116759\" style=\"width: 902px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-116759\" class=\"wp-image-116759 size-full\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/DeFi-Pulse-10.png\" alt=\"Analysts found loophole in MakerDAO allowing avoidance of liquidations\" width=\"892\" height=\"626\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/DeFi-Pulse-10.png 892w, https:\/\/u1f987.com\/wp-content\/uploads\/DeFi-Pulse-10-300x211.png 300w, https:\/\/u1f987.com\/wp-content\/uploads\/DeFi-Pulse-10-768x539.png 768w\" sizes=\"auto, (max-width: 892px) 100vw, 892px\" \/><\/p>\n<p id=\"caption-attachment-116759\" class=\"wp-caption-text\">The amount locked in MakerDAO stands at $2.37 billion. Data: <a href=\"https:\/\/defipulse.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">DeFi Pulse<\/a>.<\/p>\n<\/div>\n<p>In late September, the collective lawsuit against Maker <a href=\"https:\/\/u1f987.com\/en\/news\/class-action-against-maker-moved-to-arbitration\">was referred<\/a> to arbitration. In April, investors accused Maker Foundation, Maker Ecosystem Growth Foundation and Dai Foundation of deliberately misrepresenting the risks of owning a CDP.<\/p>\n<p>Also in September ForkLog <a href=\"https:\/\/u1f987.com\/en\/news\/opinion-dai-at-risk-from-centralised-stablecoins-as-collateral\">reported<\/a> that the stablecoin DAI is 40% backed by centralized assets. Recently, DAI&#8217;s market capitalization <a href=\"https:\/\/u1f987.com\/en\/news\/dai-market-capitalization-surpasses-1-billion\">surpassed<\/a> $1 billion.<\/p>\n<p>Subscribe to ForkLog news on <a href=\"https:\/\/twitter.com\/ForkLog\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Twitter<\/a>!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Users of the DeFi project MakerDAO can split CDPs (collateralized debt positions) into small tranches and evade forced liquidations if collateral falls below the 150% threshold. This vulnerability was discovered by Yaron Velner, head of B.Protocol.<\/p>\n","protected":false},"author":1,"featured_media":31912,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1093,1100],"class_list":["post-31911","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-defi","tag-makerdao"],"aioseo_notices":[],"amp_enabled":true,"views":"17","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/31911","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=31911"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/31911\/revisions"}],"predecessor-version":[{"id":31913,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/31911\/revisions\/31913"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/31912"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=31911"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=31911"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=31911"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}