Augur v2 Whitepaper Release v2.0.16 (69accf630d20af5aee5ff3d78fcf6560f069ccfd)

III. POTENTIAL ISSUES & RISKS

A. Parasitic Markets

Recall that a parasitic market is any market that does not pay reporting fees to Augur, but does resolve in accordance with the resolution of a native Augur market. Because parasitic markets do not have any reporters to pay, they can offer the same service as Augur with lower fees. This can have serious consequences for the integrity of Augur’s forking protocol. In particular, if parasitic markets attract trading interest away from Augur, then Augur’s reporters will receive less in reporting fees. This would put downward pressure on the market cap of REP. If the market cap of REP falls too low, the integrity of the forking protocol is put in jeopardy (Theorem 1). As a result, parasitic markets have the potential to threaten the long term viability of Augur, and should be vehemently opposed. The oracle parasite problem has not been solved – and may be provably unsolvable – even for centralized systems. That said, at the time of this writing, we have observed no significant parasitic interest leveraging Augur’s oracle.

B. Volatility of Open Interest

Large, sudden, unexpected, and short-lived increases in open interest – like those that may be seen during a popular sporting event – result in rapid increases in the market cap requirement for forking protocol integrity (Theorem 1). When the market cap requirement exceeds the market cap, there is a risk of economically rational attackers causing a fork to resolve incorrectly. While Augur does attempt to nudge the market cap and/or the open interest back into a safe ratio during such situations (see Section II.C), these nudges are reactionary and are adjusted only once per 7-day dispute window. It is worth noting, however, that speculators who witness the sudden increase in open interest may buy REP in anticipation of the reactionary market cap nudge, thus driving the market cap of REP up, perhaps to a point where the integrity of the forking protocol is no longer threatened. So the length of time during which the oracle is vulnerable may not be long enough for an attacker to successfully exploit the vulnerability. Additionally, we have increased the security multiplier from the theoretical minimum of 31, to a more comfortable value of 5. This means that the fee adjustment algorithm targets a market cap of 5 times the native open interest, rather than 3 times. This should help us absorb large (up to a 66.6% increase), sudden, unexpected, and short-lived increases in open interest without threatening oracle integrity.

C. Inconsistent or Malicious Resolution Sources

During market creation, market creators chose a resolution source that reporters should use to determine the outcome of the event in question. If the market creator chooses an inconsistent or malicious resolution source, honest reporters may lose money. For example, suppose the market in question has outcomes A and B, and the market creator, Serena, has chosen her own website, attacker.com, as the resolution source. After the market’s event end time, Serena – who is also the designated reporter for the market – reports outcome A, and updates attacker.com to indicate that outcome B is the correct outcome. Honest reporters who check attacker.com will see that the initial report is incorrect and, during the first dispute round, should successfully dispute the tentative outcome in favor of outcome B. Serena would update attacker.com to indicate that outcome A is the correct outcome, and the market would then enter its second dispute round. Again, reporters who check attacker.com will see that the tentative outcome (outcome B) is incorrect, and may successfully dispute it. Serena can repeat this behavior until the market resolves. No matter how the market resolves, some honest reporters will lose money. Several variations of this attack exist. Simply ignoring markets with dubious resolution sources is not sufficient, for in the event that such a market causes a fork, all REP holders will have to choose a child universe to which to migrate their REP. Reporters should remain vigilant against markets with dubious resolution sources. Such markets should be publicly identified so reporters can coordinate to make sure such markets finalize as invalid.

D. Self-Referential Oracle Queries

Markets that trade on the future behavior of Augur’s oracle may have undesirable effects on the behavior of the oracle itself [12]. For example, consider a market that trades on the question, “Will any designated reporter fail to submit a report during their three-day forking period before December 31, 2018?” Bets placed on the No outcome of this market may act as a perverse incentive for designated reporters to intentionally fail to report. If a designated reporter can buy up enough Yes shares at a low enough price to compensate for the loss of the creation bond, they may intentionally fail to report. If the market cap of REP is large enough (Theorem 1) then these self-referential oracle queries will not threaten the integrity of the forking protocol. However, they may negatively affect the performance of Augur by causing delays in market finalizations. While markets would still finalize correctly, this sort of behavior is disruptive and undesirable.

E. Uncertain Fork Participation

We cannot know in advance how much REP will be migrated to the True universe during the forking period of a fork, thus we cannot know in advance whether the market cap is large enough for the oracle to have integrity (Theorem 1). Our belief in the integrity of the forking protocol can be no stronger than our belief in our assumption that users will behave rationally and in their own economic self-interest. We assume that at least 50% (minus one attorep) of all theoretical REP will migrate to the True child universe during the forking period of a fork because that is consistent with self-interested, rational decision making on the behalf of the participants. However, we cannot guarantee this will happen.

F. Responsibility During a Fork

Augur forks differ from blockchain forks in one important respect: after a blockchain fork, a user who owned a coin on the parent chain will now own a coin on both forks. Ignoring replay attacks, blockchain forks pose little risk to users. During an Augur fork, however, a user who owns a REP token in the parent universe can migrate that coin to only one of the child universes. If the user migrates their token to any universe other than the consensus universe, their token may lose all value. Thus migrating REP during the forking period of a fork, before it is clear which child universe has achieved consensus, exposes the user to risk. This risk is an inherent part of REP ownership. Abstaining from migration during a fork will result in near-certain loss of value for the REP holder. This is a necessary design decision, as the integrity of the oracle relies upon REP holders reporting truthfully during the fork. REP holders cannot be absolved of this responsibility without greatly increasing the cost of system security.

G. Ambiguous or Subjective Markets

Only events that have objectively knowable outcomes are suitable for use in Augur markets. If reporters believe that a market is not suitable for resolution by the platform – for example, because it is ambiguous, subjective, or the outcome is not known by the event end date – they should report the market as Invalid. If a market resolves as Invalid, traders are paid out at equal values for all possible outcomes; for scalar markets, traders are paid out halfway between the market’s minimum price and maximum price. It is possible to imagine markets where some reporters are certain that the outcome is A and others are certain that the outcome is B. For example, in 2006, TradeSports allowed its users to speculate on whether North Korea would fire a ballistic missile that would land outside of its airspace before the end of July 2006. On July 5, 2006, North Korea successfully fired a ballistic missile that landed outside of its airspace, and the event was widely reported by the world media and confirmed by many U.S. government sources. However, the U.S. Department of Defense had not confirmed the event, as was required by TradeSports’ contract. TradeSports concluded that the contract’s conditions had not been met, and paid out accordingly.2 This is a case where the spirit of the market – to predict the missile launch – was clearly satisfied, but the letter of the market – to predict whether the U.S. Department of Defense would confirm the launch – was not. TradeSports, being a centralized website, was able to unilaterally declare the outcome of the market. If such a situation arises in an Augur market, REP holders may have differing opinions about how the market should resolve, and stake their REP accordingly. In the worst case, this could result in a fork where REP in more than one child universe maintains a non-zero market value.

Footnotes

  1. The theoretical minimum for the security multiplier is 2 when not accounting for any parasitic interest. When account for parasitic interest of up to 50% of the native open interest, the theoretical minimum for the security multiplier is 3.

  2. See https://en.wikipedia.org/wiki/Intrade#Disputes for details.