Frequently Asked Questions
What is the difference between an AMM and an order book DEX?
An AMM (Automated Market Maker) uses a mathematical formula to price assets against a liquidity pool — trades always execute against the pool, LP capital provides continuous liquidity. An order book DEX matches buyer and seller orders at agreed prices — requires active market makers, offers better price discovery for large trades. AMMs are simpler to build and always have liquidity; order books are more capital-efficient for institutional trades but require market maker relationships to launch.
How do you prevent oracle manipulation?
Oracle manipulation prevention requires multiple layers: use time-weighted average prices (TWAP) rather than spot prices for any security-critical calculation, aggregate across multiple independent oracle sources, implement deviation thresholds that trigger circuit breakers when price moves abnormally fast, and never use an on-chain pool's spot price as its own oracle. Chainlink provides manipulation-resistant price feeds for major assets. For assets without Chainlink coverage, TWAP design requires careful analysis of the available liquidity depth.
What is a flash loan attack and how do you defend against it?
A flash loan allows an attacker to borrow an arbitrarily large amount of capital within a single transaction, as long as it is repaid before the transaction ends. Attackers use this borrowed capital to manipulate AMM prices, pass governance votes or exploit logic that assumes token holdings cannot change within a single transaction. Defences: use TWAP oracles rather than spot price, take governance voting snapshots at a past block, use reentrancy guards and never trust a price feed that can be manipulated with the capital available in a flash loan.
How should we design the governance system?
Governance design must balance decentralisation with responsiveness. Our standard recommendation: on-chain proposal voting with a 48–72h timelock before execution, quorum requirements that prevent minority capture, a guardian multi-sig for emergency pause only (not execution), and snapshot voting based on past block balances to prevent flash loan voting attacks. Token distribution must be broad enough to prevent a single actor from controlling proposals — concentration of >10% voting power in a single address creates governance attack risk.
What audit process do DeFi protocols need?
Internal review comes first: Slither static analysis on every commit, Foundry fuzz testing for all invariants, Echidna property-based testing for complex state machines, full test coverage and natspec documentation. Then third-party audit from a firm specialising in DeFi — Trail of Bits, OpenZeppelin, Spearbit or Code4rena depending on protocol complexity and budget. Audit is not a one-time gate: protocols with upgradeable contracts require re-audit after significant changes.
How do you model liquidity incentives?
Liquidity mining incentive models must answer: what token emission rate sustains LP profitability relative to impermanent loss? What happens when emissions reduce — do LPs leave? We model expected APY at different TVL levels, simulate LP exit scenarios as rewards decrease and design sink mechanics (governance staking, fee burns, protocol revenue sharing) to sustain token value without perpetual inflation. Protocols that launch without this model typically experience mercenary capital exits at emission reduction.
What is the risk of upgradeable contracts in DeFi?
Upgradeable DeFi contracts trade one risk for another. Immutable contracts cannot be patched if a vulnerability is found after deployment. Upgradeable contracts can be patched — but the upgrade key is itself an attack surface. A compromised upgrade key can drain all user funds by replacing the contract with a malicious implementation. Mitigations: timelock delays (48–72h minimum) on all upgrades, multi-sig governance with high threshold, emergency pause capability separate from upgrade capability, and governance-controlled upgrades for non-emergency changes.
How does collateral liquidation work?
When a borrowing position's collateral value falls below the required collateralisation ratio, it becomes eligible for liquidation. Liquidators repay a portion of the debt in exchange for the collateral at a discount (the liquidation bonus). The mechanics — partial vs full liquidation, liquidation bonus sizing, bad debt socialisation — significantly affect protocol solvency during market stress. Bonus too low: no liquidation incentive, bad debt accumulates. Bonus too high: aggressive liquidations push asset prices down further, causing cascades.
What chains are best for a new DeFi protocol?
For protocols that need deep liquidity and ecosystem integration: Ethereum mainnet or Arbitrum/Base/Optimism for EVM compatibility with lower fees. For protocols needing high throughput: Solana or Arbitrum. For protocols targeting specific ecosystems: deploy where your target liquidity already lives. Multi-chain deployment adds complexity — separate audit cycles, bridge risk if sharing liquidity, fragmented governance. We recommend launching on one chain with strong product-market fit before expanding.
What does a realistic DeFi protocol launch timeline look like?
Mechanism design and contract architecture: 2–4 weeks. Core protocol development: 6–10 weeks. Integration, frontend and subgraph: 4–6 weeks. Internal security review and test coverage: 2–3 weeks. Third-party audit: 4–6 weeks. Testnet and bug fix cycle: 2–4 weeks. Total: 20–33 weeks from design to mainnet for a production DeFi protocol with full audit. Protocols skipping audit or compressing testing to ship faster are the ones that get exploited.