# Glossary

Learn more about metrics you see in the Apostro dashboard.

#### TVL (Total Value Locked)

TVL is a crucial metric used to gauge the overall size and activity of a DeFi platform or protocol. It represents the aggregate amount of assets, typically denominated in USD or a stablecoin, currently locked within a platform or protocol as collateral, staking, or liquidity provision. A higher TVL indicates increased usage and trust in the platform, making it a valuable indicator of a project's growth and adoption.

#### Borrows

Borrows refer to the borrowed assets obtained by users by taking a loan from the lending protocol. Users deposit collateral (typically in the form of cryptocurrencies or stablecoins) to secure a loan, and they can then borrow funds based on the value of their deposited collateral. The total value of assets borrowed by all users on a platform constitutes the platform's borrows. The interest rates on these loans are determined by factors like supply, demand, and the platform's utilization rate.

#### Collateral

Collateral is an asset deposited by a borrower in a DeFi lending platform to secure a loan. It serves as a form of insurance, ensuring that the borrower will repay the loan or face the liquidation of their collateral. The collateral value typically must exceed the value of the borrowed funds to account for market fluctuations and maintain the platform's solvency. Collateral can be in the form of cryptocurrencies, stablecoins, or tokenized assets, depending on the platform.

#### Supply

Supply refers to the total amount of an asset available for borrowing within a DeFi lending platform. Lenders deposit their assets to earn interest, which increases the supply pool. The more significant the supply, the more liquidity is available for borrowers, typically resulting in lower borrowing rates. Conversely, a lower supply may lead to higher interest rates to attract more lenders.

#### Utilization

Utilization is a metric that measures the proportion of borrowed assets to the total supply available in a DeFi lending platform. It is usually expressed as a percentage and represents the efficiency with which assets are being utilized within the platform. A higher utilization rate indicates that a more significant portion of the supplied assets is being borrowed, which may lead to higher interest rates for both lenders and borrowers.

#### Impact Cost&#x20;

Impact Cost shows the minimum price the attacker would pay for oracle manipulation by influencing the market. This figure depends on the amount of available liquidity, its distribution and TWAP set in the oracle. Lower impact costs indicate less liquid markets or less efficient platforms, leading to potential price slippage or difficulty in executing large trades without affecting the market or oracle price.

#### **Risk Factor**

Risk Factor is a metric that quantifies the potential risk of position liquidation and helps users assess the safety and stability of their positions. This metric operates on a scale ranging from 0 to 1, where a value of 0 signifies no risk and a value of 1 indicates imminent liquidation.&#x20;

A lower Risk Factor suggests that the user's position is relatively secure and is not in immediate danger of being liquidated. In contrast, a higher Risk Factor, nearing 1, warns the user that their position is at significant risk of liquidation due to factors such as market volatility, collateral value fluctuations, or changing borrowing conditions.&#x20;

#### **Liquidation Threshold (LT)**

The maximal borrow-to-collateral ratio reachable when creating a new position with token T as collateral. This number does not exceed 1.

#### **Manipulated Token (MToken)**

The token, which price is being manipulated in the considered scenario.

#### **Total Supply**

Value (in USD) supplied (as collateral or in any other form) in asset T across all positions in a specific pool.

#### **Total Borrow**

Value (in USD) borrowed in asset T across all positions in a specific pool.

#### **Borrow Cap**

Maximal value (in USD) that can be borrowed in asset T across all positions in a specific pool.

#### **Supply Cap**

Maximal value (in USD) that can be supplied (as collateral or in any other form) in asset T across all positions in a specific pool.

#### Bad debt

Value (in USD) of the loan exceeding collateral in a position. This value indicates a loss for liquidity miners. For example, a position with $1M collateral and a $1.1M loan will have $100K Bad Debt.


# Rating definitions

Learn more about ratings for pools and PnD attacks

Based on the rules described further, every isolated pool is assigned one of five ratings:

* &#x20;Rating A: Excellent (5)
* Rating B: Good (4)
* Rating C: Moderate (3)
* Rating D: High-risk (2)
* Rating E: Critical (1)

Numbers in brackets are assigned to each rank and are used for numerical operations with ranks (e.g., averaging).

The ratings are given for 2 factors:

* Manipulation Complexity
* Bad Debt

Minimal of two ratings is assigned to the pool. Total protocol rank is calculated by weighted average of pool ranks for each factor, rounded to the nearest value. Pool weights are set proportionally to their TVL for Manipulation Complexity ratings and proportionally to their Total Borrows for Bad Debt ratings.

## Manipulation complexity

Our metrics in this category are based on the Manipulation Cost (MC). We define MC differently for pump attacks and dump attacks:

* For pump attacks, MC is defined as capital required for **increasing** the price of the MToken from the current price CurPrice to CurPrice / LT(T).&#x20;
* For dump attacks, MC is defined as capital required for **decreasing** the price of the MToken from the current price CurPrice to CurPrice \* LT(T) (where T is a token with maximal Liquidation Threshold other than [MToken](https://docs.apostro.xyz/resources/glossary#manipulated-token-mtoken)).

The logic behind this threshold is simple. The attacker is required to push the MToken price at least to the thresholds above to not take any loss in case they do not return the loan, without considering the manipulation cost.

The manipulation cost rating of a pool is set to the lowest of its Pump rating and Dump rating. For both Pump and Dump ratings, each asset in the pool which price oracle allows it to be manipulated (i.e. it is not set to a fixed value) will be considered as MToken, and the minimal resulting rating (over all pool tokens) is considered, respectively, as a Pump or Dump rating of the pool. Calculation rules in the next section are provided for a fixed MToken.

#### Dump attack ratings

We define the **Value at Risk (VaR)** of a pool as the USD value which could be seized in case of an attack if the protocol is functioning correctly. For Dump attacks, it is expressed as:

<figure><img src="/files/6ms3V4nFYesS7gvHgXFP" alt=""><figcaption></figcaption></figure>

Limiting the supply with Supply Cap is not necessary when calculating risk for the current market state but comes to use when Additional Liquidity is introduced.

Rating rules are provided in Table 2:

**Dump Attack: Rating Rules**

<table><thead><tr><th width="126">Rating</th><th>Condition</th></tr></thead><tbody><tr><td>A</td><td>MC ≥ 10 VaR</td></tr><tr><td>B</td><td>10 VaR > MC ≥ 5 VaR</td></tr><tr><td>C</td><td>5 VaR > MC ≥ 2 VaR</td></tr><tr><td>D</td><td>2 VaR > MC ≥ VaR</td></tr><tr><td>E</td><td>MC &#x3C; VaR</td></tr></tbody></table>

Rating E is assigned in the case where Manipulation Cost is so small that it does not exceed VaR, therefore there is a possibility of profitable attacks. It is important to note that the assignment of this rating to a pool does not imply that there necessarily exists a profitable attack strategy (otherwise, this indicator would be exploited by malicious agents), but it indicates very high risk.

Other tiers express levels of confidence in the protocol's security. They are calibrated so that rating A is assigned to pools with high-liquidity assets and reasonable risk isolation.

#### Pump attack ratings

For pump attacks, we define Value at Risk (VaR) in several steps. First, for each token T, we define MaxBorrowable\_T as:

<figure><img src="/files/pflZgQIC4BbKhav3aWyU" alt=""><figcaption></figcaption></figure>

Then we calculate this value for the entire pool:

<figure><img src="/files/FOikpicVpHaV7RawGXx8" alt=""><figcaption></figcaption></figure>

The value of assets that can be borrowed against [MToken](https://docs.apostro.xyz/resources/glossary#manipulated-token-mtoken) as collateral is also limited by Supply Cap\_(MToken) and LT\_(MToken), which we denote with MaxBorrowingPower\_(MToken):

<figure><img src="/files/VNUA0nuIj4SOg2tcg8j8" alt=""><figcaption></figcaption></figure>

Finally, the Value at Risk for pump attacks is calculated as:

<figure><img src="/files/x9SJktBJZnOmXpuQEoHv" alt=""><figcaption></figcaption></figure>

Rating rules are more complex in the case of pump attacks. They reflect the notion of capital-intensive attacks and their effect on risk. In the first step, base ratings are assigned based solely on the Manipulation Cost indicator:

**Pump Attack: Base Rating Rules**

<table><thead><tr><th width="126">Rating</th><th>Condition</th></tr></thead><tbody><tr><td></td><td></td></tr><tr><td>B</td><td>MC ≥ $10M</td></tr><tr><td>C</td><td>$10M > MC ≥ $3M</td></tr><tr><td>D</td><td>$3M > MC ≥ $1M</td></tr><tr><td>E</td><td>MC &#x3C; $1M</td></tr></tbody></table>

Rating A is absent in this table due to the fact that those ratings are assigned to pools that may be vulnerable to manipulation (which is demonstrated further). The higher the Manipulation Cost, the riskier the attack for the attacker and fewer actors possess such capital combined with malicious intents. Based on observed attacks, the required starting capital exceeds MC as per our definition by 5+ times. This maps rating B to the possibility of a profitable attack with very high capital requirements ($50M+), while rating E depicts vulnerabilities to low-capital attacks (<$5M).

Once the base ratings are calculated, we move them up or down based on this set of rules:

**Pump Attack: Rating Adjustments**

<table><thead><tr><th width="233">Adjustment</th><th>Condition</th></tr></thead><tbody><tr><td>+4</td><td>MC ≥ 10 VaR</td></tr><tr><td>+3</td><td>10 VaR > MC ≥ 5 VaR</td></tr><tr><td>+2</td><td>5 VaR > MC ≥ 2 VaR</td></tr><tr><td>+1</td><td>2 VaR > MC ≥ VaR</td></tr><tr><td>+0</td><td>MC &#x3C; VaR</td></tr><tr><td>-1</td><td>MC &#x3C; 0.1 VaR and LT_(MToken) ≥ 0.5</td></tr></tbody></table>

If the Manipulation Cost exceeds the Value at Risk, we adjust the base rating by moving it up (e.g., B+1 = A) the number of ratings proportional to the level of confidence. There is a special case where we reduce the base rating.

The rating rules are calibrated so that rating A is assigned to pools with high-liquidity assets and reasonable risk isolation, and rating E signals the urgent need to change the protocol's risk parameters or even halt the pool.

## Bad debt

Bad debt is defined as a loan which is not backed by any collateral. It naturally occurs in correctly functioning lending protocols due to liquidations being unprofitable for low-value positions in condition of high network commissions. However, large amounts of bad debt are indicating sub-optimal risk parameters such as liquidation incentive and/or price manipulation or other attacks.

* **Max Bad Debt** is defined as the maximal amount of debt not backed by collateral. For example, Max Bad Debt for two undercollateralized positions with \[$1.1M, $1.05M] and \[$300K, $100K] of loan and collateral respectively will be equal to $200K (and not $50K, despite the first position having a higher total loan value).
* **Debt Percentage** is defined as the ratio of bad debt to Total Supply. For example, Debt Percentage for two positions with \[$1.1M, $1.05M] and \[$300K, $500K] of loan and collateral respectively and additional $1.4M supplied liquidity will be equal to ±1.78% (see formula below).

<figure><img src="/files/06qrT2diYX3ILqiqBDv4" alt=""><figcaption></figcaption></figure>

In order to correctly support 1-to-1 stablecoin lending pools (such as Maker's [DAI/USDP](https://explorer.apostro.xyz/protocols/maker/mainnet/markets/PSM-PAX-A)), we tolerate up to 1% price fluctuations before assigning bad debt status for a position. For example, $199M DAI backed by $198M USDC would not be considered as $1M of bad debt, as this difference is most likely based on the market price of both assets deviating insignificantly from $1.

**Rating rules are provided in the following table:**

<figure><img src="/files/0z37ysKn98AOrptXJ96a" alt=""><figcaption><p>Table 1</p></figcaption></figure>

The table is calibrated so that rating A is assigned to protocols that have been adequately operating under extreme market conditions, which inevitably leads to the accumulation of bad debt. The Debt Percentage threshold is also low enough, in this case, to not have a significant influence on liquidity providers' PnL, and bigger undercollateralized positions are tolerated, given they do not make up for a large share of the protocol's TVL.

Ratings B and C reflect degrees of concern on the protocol's liquidation mechanics or/and loss reimbursement. Generally, those protocols are safe to deposit liquid tokens into

Ratings D and E are assigned to pools with large (5% to 20%) and very large (>20%) shares of bad debt, indicating severe exploits and loss for liquidity providers. Those pools are typically frozen for deposits and borrows.


# Apostro algorithms

Or how it works behind the scenes

## **Market impact**

Market impact cost calculation algorithms are designed to estimate the minimum capital required to change the price on a target exchange through market orders. Target prices for manipulation are calculated based on protocols' risk parameters.

### **Uniswap V3**

Our methodology involves the use of Time-Weighted Average Prices (TWAPs) within oracle settings to ensure precise price estimations. The impact cost algorithm calculates the cost of short-term (5-10 minute timeframe) TWAP manipulation on Uniswap V3 using a single market order. We assume that there is sufficient liquidity available on other decentralized markets, allowing the token to be sold at a price close to the current market rate.&#x20;

If the token has low liquidity, long-term attacks may be more profitable, while the actual impact costs could be lower than estimated (described in the next section).

Actual short-term TWAP manipulation costs may be higher or lower than reported depending on the manipulation mechanics used.

### Upper Bound

In cases where Chainlink-like oracles are used, or short-term (1-5 minutes) manipulation estimated by the Uniswap model isn't feasible, we have developed an upper-bound formula for manipulation costs. The predicted market impact is proportional to the order size and inversely proportional to the token's market capitalization.&#x20;

This model has been tested extensively and is expected to provide a confident upper bound for manipulation costs; however, real costs may be many times lower than those produced using this approach.

Here are several examples that illustrate use cases for both methods.

#### Example 1

\- Suppose we have a pool consisting of $WETH, $USDC and $SHI, the latter one being a low-cap ($2M) token;\
\- WETH and USDC price manipulation is basically impossible due to the huge liquidity, therefore, manipulation costs only make sense for $SHI. Let's also assume that the target price increase for a manipulation is 40% for $SHI.\
\- Uniswap V3 TWAP is used as the price feed for $SHI;\
\- The liquidity for $SHI is placed in such a way that a short-term TWAP manipulation requires $10B+;\
\- Meanwhile, according to even general economic knowledge, buying 10% of the market capitalization increases the price by at least 10% with a longer-lasting impact. Therefore, pumping up $SHI by the aforementioned 40% requires no more than 40% \* $2M = $800K; our Upper Bound algorithm will show \~200K;\
\- This number will be displayed in the dashboard as Impact Cost for $SHI instead of $10B.

#### Example 2

\- Assume the same setup, but now $SHI liquidity on Uniswap is placed on a narrow range, making short-term TWAP manipulation relatively cheap (\~$50K);\
\- This number will be displayed in the dashboard, and the Upper Bound result will be neglected.

#### Example 3

\- Assume the same setup, but now $SHI is mostly traded on small centralized exchanges and Chainlink price is used, with no TWAP constructed on top.\
\- Market conditions are such that most of $SHI supply is locked in reward farming or inactive in other ways, and the liquidity available on exchanges is only a fraction of the value expected for a token with such capitalization.\
\- In this case, pushing the price up for several minutes by 40% can in fact cost $20K, while the cost predicted by the Upper Bound algorithm is \~$200K. For now, while we are developing a universally accurate market impact model, Upper Bound results will be displayed in the dashboard.


