Keepers: DeFi’s Blind Spot
Keepers are exterior bots or providers that monitor onchain exercise and provoke transactions when predefined circumstances are met. As a result of they will occupy privileged positions inside a protocol’s execution circulation, the dangers lengthen past downtime, congestion, or compromised non-public keys. The execution path itself can develop into an assault floor.
GMX V1 Keeper Execution-Movement Exploit — $42 Million
The attacker used GMX V1’s keeper execution circulation to entry a short lived window during which leverage was enabled, then re-entered the vault to create unusually giant brief positions. These positions manipulated the worldwide brief common value utilized in GMX’s AUM calculation, artificially inflated the worth of GLP, and enabled roughly $42 million to be extracted by means of redemptions.
GMX demonstrates how keeper execution can develop into a part of an exploit path. The keeper wasn’t compromised and didn’t execute an unauthorized transaction. The attacker exploited privileged protocol conduct that grew to become out there whereas the keeper was legitimately executing an order.
Extra generally, keepers carry out routine actions comparable to auto-compounding. In lots of liquidity and yield methods, they periodically declare amassed charges or rewards and submit transactions that reinvest them into the place.
Carbon DeFi offers native auto-compounding. Income are routinely added again to the place as trades execute, with out requiring an exterior bot to observe the place or submit a separate compounding transaction.
Automation isn’t an extra service layered on prime of Carbon DeFi. It’s a part of the protocol’s underlying execution logic. Eradicating keeper-based execution eliminates one other exterior dependency and the operational dangers that include it.
