Dai is a stablecoin created by the Maker protocol, designed to maintain a stable value by being pegged to the US Dollar. It achieves this stability by using a system of smart contracts on the Ethereum blockchain, which requires users to lock up collateral in excess of the value of the Dai they wish to generate. This means borrowers must deposit cryptocurrencies as collateral to create (or "mint") Dai tokens. The process of over-collateralization ensures that even if the value of the collateral drops, there is sufficient buffer to cover the value of the Dai. Additionally, Maker uses two tokens: Dai as the stablecoin and MKR as the governance token. MKR holders have the power to vote on changes to the system, such as which types of collateral can be deposited and what the risk parameters should be to maintain the stability of Dai. This decentralized governance allows the Maker community to maintain the robustness and security of the system.
The Dai project is a component of the Maker Protocol, which was founded by the Maker Foundation. The Maker Protocol was initially conceived in 2015 when Rune Christensen introduced the eDollar, which later evolved into Dai. The foundation began in 2014, and control was transferred to a decentralized autonomous organization, MakerDAO, on March 25, 2020 [source].
Rune Christensen, the founder, is a Danish entrepreneur who co-founded a recruitment company, Try China, before delving into cryptocurrency. He has been pivotal in establishing the architecture behind Dai, which began as Single-Collateral Dai (SAI) in 2017, before transitioning to Multi-Collateral Dai (DAI) in 2019 [source].
No, you cannot stake any tokens in this project.
There have been no notable hacks or exploits specifically targeting the native Dai protocol where a significant amount of money was lost. However, Dai has been involved indirectly in situations where stolen assets were converted into Dai due to its decentralized nature. For instance, hackers have preferred using Dai to launder funds in unrelated exploits, such as the Bybit hack. This behavior is due to Dai's resistance to being frozen by centralized authorities, unlike other stablecoins. Nonetheless, such risks are extraneous to the security of the Dai protocol itself.
The Dai project, operated under MakerDAO, employs multiple robust security measures tailored to its decentralized finance protocols, ensuring both stability and integrity of its collateral-backed stablecoin, DAI. Here’s a consolidated list of key security measures and vulnerabilities:
Formal Verification and Audits: MakerDAO uses formal system verification and regular third-party security audits. This includes contracted audits from top-tier blockchain security firms to ensure the integrity and robustness of its smart contracts.
Bug Bounty Programs: A proactive bug bounty program is set in place through platforms like Immunefi, offering rewards for finding vulnerabilities. This incentivizes community participation in identifying potential threats before they can be exploited.
Multi-collateral System: DAI's security benefits from being backed by a diverse set of collateral types, not just a single asset. This dilutes risk concentration that might be associated with a single collateral's volatility.
Emergency Shutdown Protocol: A unique feature of the Maker protocol is its Emergency Shutdown mechanism. This is designed as a last-resort measure to protect the system from threats like governance attacks or oracle failures. It allows Dai holders to claim a fixed basket of collateral.
Risk Parameters and Governance Modules: Through a decentralized governance framework, MKR holders vote on critical protocol adjustments, including risk parameters like Liquidation Ratios and Debt Ceilings. These dynamic parameters help manage volatility and safeguard the system's stability.
Oracle Security: The protocol utilizes a multi-oracle system to ensure accurate asset price feeds, reducing the chances of manipulation that can affect DAI's price stability.
Oracle Manipulation Risk: DAI relies heavily on oracles for accurate crypto price data, which if manipulated, can threaten DAI's peg to the US dollar. This was notably a weakness identified during past events.
Governance Risks: The governance model, albeit decentralized, means that MKR holders control protocol decisions. Collusion among a majority of these stakeholders can lead to detrimental changes or security breaches.
Black Swan Events: The potential for rare events like severe market crashes or systemic protocol failures could strain the system, leading to cascading liquidations or loss of peg stability.
Operational Breaches: There have been instances of operational vulnerabilities, such as issues with the multi-sig wallet in delegation events, that caused temporary system disruptions. These have been addressed with updates and improved monitoring practices.
Phishing Attacks: Despite the protocol's internal security measures, users of DAI have been victims of external phishing attacks, which highlight the need for endpoint security by individual holders.
Overall, the Dai project has layered security measures that are continually updated and tested to manage risks inherent in the DeFi space, with a focus on flexible, community-driven protocol management. However, like all DeFi projects, it remains subject to both market-based and systemic risks that require vigilant governance and continual technical improvements.
Here are the Dai project audits listed in chronological order, with the most recent first: