A solid oracle is critical for Colada.
It’s not only about getting a price, but knowing where it comes from, how it was calculated, how hard it is to manipulate and how much that manipulation could cost.
With Mimir, we can use that information directly in Colada to adapt risk limits and exposure to the actual strength of each market.
That level of transparency and control is exactly what we wanted.
Reading a pool price is easy. Making it expensive to manipulate is way harder.
It has been the biggest challenge in building Mimir, and where much of our development time went.
That work led to several safeguards built directly into how Mimir reads pools.
An attacker cannot change a pool’s price and have Mimir read that pool in the same transaction. Mimir also checks its liquidity and the amount needed to move its price by 0.5%, rejecting sources below the feed’s requirements.
Prices are combined using a weighted median: an attacker needs to influence sources carrying at least 50% of the total weight. Pools sharing the same liquidity route count once, not as separate confirmations.
More independent sources can mean more markets to manipulate. Deeper liquidity means more money needed to move them. Prices too far from the median are excluded, and if too few sources remain, Mimir refuses the update.
Mimir also estimates how much capital an attacker would need and how much they could lose attacking enough sources to move the price. From the capital estimate, it recommends a limit on the value an app should expose to that feed.
Every check, limit and risk calculation is enforced onchain.