Finance · Fintech · Crypto — explained

Bitfolio

An independent explainer desk · No ads · No affiliate links

TechExplainer

What is a blockchain oracle, and why do smart contracts need one?

A smart contract can only see what is already on its blockchain. Oracles are the bridge to everything else, and they are often the weakest link in the chain.

A white lighthouse on a grassy headland under a bright sky
Photo: “DGJ_4831 - Louisbourg Lighthouse” by archer10 (Dennis), CC BY-SA 2.0, via flickr.com · Edited: duotone, cropped.

The short answer

A blockchain oracle is a service that brings off-chain information, such as an asset price or a sports result, onto a blockchain so smart contracts can use it. Contracts cannot fetch outside data themselves, so whoever runs the oracle shapes what the contract believes.

Key takeaways

  1. Smart contracts cannot read data outside their blockchain, so they rely on oracles to supply prices, events and random numbers.
  2. The oracle problem is about trust: the data must be correct, available when needed and reported by parties with a reason to be honest.
  3. Decentralised oracles combine reports from many independent nodes to reduce the risk that one faulty or dishonest source corrupts the data.
  4. If an oracle reports a wrong or manipulated price, contracts that depend on it can lend, liquidate or pay out on false information.

What is a blockchain oracle?

An oracle is an application that produces a data feed, making information from outside a blockchain available to smart contracts on it1. The U.S. Treasury describes oracles in the same way: they connect a smart contract to off-chain data, such as stock prices or the value of collateral, that the contract needs in order to work2.

Despite the mystical name, an oracle does not predict anything. It is closer to a courier. It collects a fact from the outside world, writes it into a transaction and leaves it on the chain where contracts can read it. A typical setup has three parts: an on-chain contract that receives and stores the data, off-chain nodes that fetch it, and the original data sources, such as APIs or databases1.

Figure · How a price reaches a smart contract

How a price reaches a smart contract01Data sourcesexchanges, APIs,databases02Oracle nodesfetch and sign thedata03Oracle contractstores the valueon-chain04Your smartcontractreads it and acts
  1. 01Data sourcesexchanges, APIs, databases
  2. 02Oracle nodesfetch and sign the data
  3. 03Oracle contractstores the value on-chain
  4. 04Your smart contractreads it and acts
Every arrow is a point where data can be delayed, corrupted or manipulated. Source: [1]

Why can't a smart contract just look up the price itself?

A blockchain only works if every node that re-runs a transaction reaches exactly the same result. That property is called determinism. If a contract could call a website directly, different nodes might get different answers at different moments, and they could no longer agree on the state of the chain1. So Ethereum contracts, by default, cannot access information stored outside the network1.

The workaround is to put outside data on the chain as an ordinary transaction. Once recorded, every node sees the same value. But this creates what developers call the oracle problem: the chain can prove that a value was recorded, not that it was true.

The three parts of the oracle problem Source: [1]

RequirementThe question it asksWhat failure looks like
CorrectnessIs the data authentic and unaltered?A wrong price is recorded and contracts act on it
AvailabilityIs the data delivered when it is needed?The feed stops or lags, and contracts use stale values
Incentive compatibilityAre reporters rewarded for honesty and penalised for lying?Reporters gain more by cheating than by being accurate

How do oracles deliver data?

Oracles follow two broad patterns1. In publish-subscribe, the oracle keeps updating a feed, such as a price, and contracts read the latest value whenever they need it. In request-response, a contract asks a specific question and the oracle answers it once, which suits rarer data like the result of an event.

The bigger design choice is who reports the data. A centralised oracle has a single provider. It is simple and fast, but the provider can switch off the service, be hacked or supply bad data, and there is no on-chain way to confirm the information is correct1. A decentralised oracle network queries many independent nodes and compares their answers1. Some require nodes to post a financial stake that they can lose for submitting incorrect data, and some take the median of all reported values so one outlier cannot move the result1.

Figure · Centralised and decentralised oracles

Centralised and decentralised oraclesCentralised oracleOne provider supplies the dataFast and simple to buildSingle point of failureNo on-chain check on accuracyDecentralised oracleMany nodes report independentlyAnswers compared or aggregatedStakes can penalise bad reportsSlower and costlier to run

Centralised oracle

  • One provider supplies the data
  • Fast and simple to build
  • Single point of failure
  • No on-chain check on accuracy

Decentralised oracle

  • Many nodes report independently
  • Answers compared or aggregated
  • Stakes can penalise bad reports
  • Slower and costlier to run
Source: [1]

What are oracles used for?

Ethereum's developer documentation lists four common jobs1:

  • Price feeds for lending and trading apps in decentralised finance. The documentation's own code example reads an ETH price from a Chainlink feed1; our Chainlink profile explains that project.
  • Verifiable randomness for games and lotteries, where a contract needs a random number nobody could have predicted or rigged.
  • Event outcomes for prediction markets, such as election or sports results.
  • Automation, where outside networks trigger contract functions at set times or conditions.

Worked example

Why one number matters so much (illustrative)

Imagine a lending app with a rule that collateral must be worth at least 150% of the loan. You borrow 1,000 dollars of stablecoins against 10 tokens. At an oracle price of 200 dollars, your collateral is worth 2,000 dollars, or 200% of the loan. The rule is breached once the reported price falls below 150 dollars.

If the oracle wrongly reports 140 dollars, the contract sees collateral of 1,400 dollars, or 140%, and may treat your loan as undercollateralised even though nothing changed in the real market. The contract has no way to know the price is wrong.

What can go wrong with an oracle?

Securities regulators take oracle risk seriously. In its 2023 policy recommendations on decentralised finance, the International Organization of Securities Commissions (IOSCO) listed oracles among the places vulnerabilities can sit, and said that DeFi's reliance on off-chain data through oracles continues to present considerable risks3. Problems usually fall into three groups.

  • Outages and lag. A centralised feed that stops leaves contracts exposed, which ethereum.org describes as a denial-of-service risk1.
  • Bad or hacked data. Even reputable providers can go rogue or be compromised1.
  • Manipulated inputs. If an oracle copies prices from thin markets, someone with enough money can move those markets. The Treasury warns that flash loans, which let a user borrow large sums inside a single transaction, can be used to manipulate asset prices across DeFi services2.

A U.S. case shows the third risk. In January 2023 the Commodity Futures Trading Commission (CFTC) alleged that a trader on the Mango Markets platform bought large amounts of the MNGO token on the three exchanges that fed the platform's oracle4. According to the complaint, the oracle's MNGO price jumped more than 13-fold in about 30 minutes, inflating the trader's positions, and over 110 million dollars in digital assets were taken from the platform4. These are allegations in a civil complaint, not findings by a court4.

Risk warning

Your funds depend on someone else's data

When you use a lending or trading app built on smart contracts, the oracle's accuracy can decide whether you are liquidated or paid. Crypto-assets are volatile and these services may lack the protections of regulated finance. See our risk disclosure.

What mistakes do beginners make about oracles?

Common beginner mistakes

  1. Thinking the blockchain verifies the data

    The chain proves a value was recorded and by whom, not that it matches reality. Accuracy depends on the oracle design.

  2. Ignoring where the price comes from

    A feed built from a few small exchanges is easier to push around than one drawn from many deep markets.

  3. Assuming "decentralised" means many independent parties

    Check how many nodes report, who runs them and who can change the feed's settings. IOSCO notes that DeFi arrangements often still have people in control3.

  4. Forgetting about stale prices

    In fast markets a feed that updates slowly can be minutes behind, and contracts act on the old number.

Frequently asked questions

Why is it called an oracle?

The name is a metaphor for a trusted source of answers. Technically it is just software that writes outside data onto a blockchain1; it does not forecast anything.

Is an oracle the same as an API?

No. An API is a data source on the ordinary internet. An oracle fetches data from sources like APIs and records it on-chain so smart contracts can use it1.

Do oracles only deliver prices?

No. Besides price feeds, oracle networks supply verifiable random numbers, event results for prediction markets and automation that triggers contract functions when set conditions are met1.

Do all DeFi apps use the same oracle?

No. Each app chooses its own data feeds and settings, so two lending apps can see slightly different prices for the same token at the same moment.

Who regulates oracles?

There is no single oracle regulator. Authorities look at the activity: the Treasury says a DeFi service that functions as a financial institution must meet anti-money-laundering rules whatever its structure2.

The bottom line

Oracles are how blockchains learn about the outside world, and that makes them a point of trust in systems that claim to remove trust. Before relying on any app that uses price data, it is worth asking where its numbers come from, how many parties report them and what happens if they are wrong or late.

Sources

  1. Oracles — ethereum.org developer documentation Primary source
  2. Illicit Finance Risk Assessment of Decentralized Finance — U.S. Department of the Treasury, 2023 Primary source
  3. Final Report with Policy Recommendations for Decentralized Finance (DeFi) — International Organization of Securities Commissions (IOSCO), 2023 Primary source
  4. CFTC Charges Avraham Eisenberg with Manipulative and Deceptive Scheme to Misappropriate Over $110 million from Mango Markets (Release 8647-23) — U.S. Commodity Futures Trading Commission, 2023 Primary source

How we checked this page: every figure above links to the numbered source it came from. Spotted an error? Tell the desk — see our editorial policy.

Read next