Anxiety levels in the AAVE community spiked in November 2022 as Avi Eisenberg performed an attack on AAVE. Eisenberg attempted to short the CRV token by using funds borrowed on the protocol to artificially deflate the value of CRV. While the attack was ultimately unsuccessful, it left the AAVE community scared and even raised question marks regarding the feasibility of large lending platforms under decentralized governance. In this work, we analyze Avi Eisenberg's actions and show how he was able to artificially lower the price of CRV by selling large quantities of borrowed CRV for stablecoins on both decentralized and centralized exchanges. Despite the failure of his attack, it still led to approximately 1.6 Mio USD of irretrievable debt and, thereby, quadrupled the protocol's irretrievable debt. Furthermore, we highlight that his attack was enabled by the vast proportion of CRV available to borrow as well as AAVE's lending protocol design hindering rapid intervention. We stress Eisenberg's attack exposes a predicament of large DeFi lending protocols: limit the scope or compromise on `decentralization'.
翻译:2022年11月,AAVE社区焦虑水平飙升,原因是Avi Eisenberg对AAVE发起了一次攻击。Eisenberg试图通过使用从该协议借来的资金人为压低CRV代币的价值,从而做空CRV代币。尽管这次攻击最终未能成功,但让AAVE社区感到恐慌,甚至对去中心化治理下大型借贷平台的可行性提出了质疑。在本研究中,我们分析了Avi Eisenberg的行动,并展示了他如何通过在去中心化和中心化交易所大量出售借来的CRV换取稳定币,从而人为压低CRV的价格。尽管他的攻击失败了,但仍然导致了约160万美元的不可追回债务,从而使该协议的不可追回债务增加了三倍。此外,我们强调,他的攻击之所以能够实施,是因为大部分CRV可供借入,以及AAVE借贷协议的设计阻碍了快速干预。我们强调,Eisenberg的攻击揭示了大型DeFi借贷协议的一个困境:要么限制规模,要么在“去中心化”上妥协。