← All episodes

Why DeFi's Biggest Risk Isn't Smart Contracts

EP 07Jun 202648 min

Lee argues that operational security, not smart contract bugs, is now the leading cause of loss in DeFi lending.

Lee McClellandNexus Mutual
Watch on YouTube

Transcript

auto-generated

It's easier for North Korean state actors to compromise a dev or compromise somebody on a multi-sig than it is for them to actually hack a protocol. We launched kidnap and ransom cover uh here at the beginning of the year that's seen a lot of interest from people as well. The people that bear these risks are the people that are the least sophisticated. You know, your peer-to-pool market uh is as strong as the weakest collateral in it. Like in times like this where market yields compress, you actually see people move up the risk curve to get higher yields to be competitive.

And so sometimes that risk is actually higher than the available yield. >> Okay, excellent. Hello everybody. Welcome to another episode of Beyond Yield. This one featuring Nexus Mutual.

Uh Nexus Mutual, of course, is one of the earliest and the leading on-chain cover products and insurance providers in the Web3 space. And today, we're here with Lee McClelland, uh who leads product and risk at Nexus Mutual. So, Lee, thank you firstly in advance for taking the time today to go deeper with us and uh and welcome. >> Yeah, thanks for having me. I look forward to chatting about Nexus and, you know, what risk is, you know, done in the space, where it's gone, and where it's heading next, and how we're looking to cover more people against risk.

>> Excellent. Likewise, I also think it's a super timely topic in the space given the events of probably the last 8 months or so. So, let's kick it off. Um I think it's always helpful just to get a background context on who we're chatting with. I love to hear about your journey in Web3 or even beforehand.

Um you know, kind of like how you came upon the Nexus Mutual team, what drove you, what what got you interested to join the team, and kind of, you know, a bit more about your role on the team today. >> Yeah, I first got involved uh like looking at blockchain and in DeFi in 2020. I had a friend who was talking to me about Bitcoin like most people. Um so, I started looking at that and then I stumbled across Ethereum, you know, in the uh EVM computer. And I started looking to DeFi and I just thought this is kind of this level of efficiency is something that I think is going to take off and be very interesting.

So I just went into uh a deep dive, you know, went into the rabbit hole on DeFi and started doing research in all of these different sectors. You know, what did lending look like? What were um DEXs looking like? Where were these different industries going and where were the gaps? So one of the gaps I found was actually insurance or coverage in the space.

There weren't really any providers and for the ones that were kind of fledgling, their solution was more like insurance is easy, just build a Uniswap pool and people can trade. Right? And like that approach hasn't really scaled. But when I came across Nexus, the one big differentiator was Hugh and Ray both came from traditional insurance. They'd worked in mutuals before and they brought that expertise um and then worked with a really solid engineering team to build Nexus Mutual.

A lot of other protocols you look at, the expertise was engineering first and then it was the primary focus of the protocol second. So that was very interesting to me. I started contributing within the DAO at Nexus at the end of 2020 and into 2021, I helped them update their documentation and I started doing some risk research um through some grant uh initiatives. And then I got really involved in the DAO side of things and that's what led to me working with the team full-time. So I think what made me drawn to Nexus is risk was something that was kind of inherent, especially in the, you know, DeFi summer in 2020.

So how do you fix those things if you're actually going to scale, you know, the future of finance as everybody was talking about? That was a component that was really, really important. There were a lot of people working in the space and I thought, "Hey, if I could work in that space, that would be amazing." Um and so it all kind of lined up and came fruition and I've been with Nexus for uh 5 years and my role has evolved. When I first started it was more on the com side but eventually everybody internally saw that I was very interested in risk and that was what I did in my free time. So about a couple of years ago I transitioned to the head of product and risk role and now my role is primarily focused on doing due diligence for new listings managing our underwriting data, managing the pricing model, you know, updating the histogram based on the pricing model over time with the loss distributions that we see and this all informs how we price risk.

I'm also responsible for tracking our exposure internally, correlation concentration risk, making sure we don't exceed those risk limits. I do a little bit of everything within the company but my primary focus is again focusing on risk due diligence and working on new cover product development. >> What an excellent example of a true web 3 story of somebody joining initially through the Dow, right? Through the discords like getting in early hands-on and then scaling to essentially leading the product and risk on the team is I think a web 3 like love story almost written like written in in history here. Also want to go deeper with you later into the current status of the Dow because back in you know, >> [clears throat] >> launched 2019 early you know, D5 summer 2020 Dow's were super relevant, Dow's were successful and we've seen a scale down of the Dow architectures but Nexus Mutual has still done I think in my opinion I'll get your feedback later a very effective job of still including Dow members in terms of the liquidity provision and the usage of NXM.

So maybe to come back to that but I want to also just go back in time a little bit to let's say launch. You mentioned Hugh Karp and the core the founding team launched in 2017, and the first product uh cover product was launched in 2019. You were kind of still early in the Discord so on the downside that those days. I'd love to get your thoughts on what the perception was back in the day. Is this something, you know, when Nexus Mutual launched that the industry was had a positive, you know, reception to?

Is this something that users wanted at the time? Because I also see that, you know, this is a product that arguably scales as crypto as web three scales. So I would assume now the demand for cover is so much stronger than it was back then. But curious like, you know, back in the DeFi summer days when you were getting you know, the grassroots hand on kind of what the feedback was back then. >> Yeah, so Nexus Mutual actually launched on Ethereum in May of 2019.

So we're actually just hitting the 7-year mark. Hugh started working on the idea in 2017 and developed it over that time, you know, between 2017 and between launch in 2019. So when we first launched, if you think about it, I mean that was some of the earliest days of DeFi. You had Uniswap V1, you had Maker which is arguably the oldest protocol, you know, on Ethereum. You had those like fledgling protocols, but there really wasn't a lot that was active.

And the way that the protocol worked then was when you underwrite when you were underwriting risk, when you were staking on Nexus in the early days, you're actually staking directly against a contract address. So it required a lot more technical expertise wasn't as successful as it is now. The feedback that we got was people definitely wanted cover, especially when DeFi summer came around. That's really when the boom when the adoption for cover took off. People wanted to be able to purchase cover for smart contract risks.

They wanted to be able to go into some of these farms and know that they weren't going to lose all their money if there were hacks happening. And we saw an increase in hacks as well um, 2020 for various protocols. We saw a lot of people that were interested. It was just very complicated and it wasn't as easy to figure out. So, with that feedback over time we've improved the protocol, improved the UX.

Um, but in the earliest days people basically were like, "Can we get this covered? Can we get that covered? How does staking work?" And there were a lot of uh, a lot of feedback from users that helped us improve the product. But the overall thing was people wanted coverage. They wanted to be able to purchase coverage and they wanted to be able to go into these farms and be safe.

So, the initial reception was I think pretty strong. Um, the only thing that people didn't like is we are a discretionary mutual. And that means you have to join to become a member. It's a, you know, the mutual structure has been around for hundreds of years. And you had to go through KYC to become a member.

And so, that was not something people were keen on. That was one of the strongest pieces of feedback. Transition to now, you know, funds that's a requirement for them to participate. They like the KYC feature. And we have other partners through that allow people to buy cover without going through KYC, namely Open Cover.

And um, so in the earliest days the product was a lot different than it is now. Like we've learned a lot over time, just like other DeFi protocols. You know, if you're active in DeFi summer, you know how clunky some of those use UIs uh, were and how many forks were out there and, you know, things going wrong and kind of how risk has transformed since then. So, the mutual has transformed quite a lot from just having one product to having dozens now that we uh, that we use. >> Excellent.

Yeah, so I want to go deeper into that, what really what the products look like today. Um, you mentioned in the early days you were having user requests for cover for all different types of risk, smart contract risk, um, and and other types of inherent risks. Here's to see what that looks like today. What are the different uh, dimensions of cover that Nexus Mutual offers uh, when when evaluating risk within a different DeFi protocol? >> Yeah, so when we started we just had it was smart contract cover and it was covered against a smart contract exploit.

But risk has evolved since then, right? So we saw a lot of oracle manipulation attacks that happened in 2020 and 2021. This 2020 is when flash loans first became very popular and came out and that changed the way that people are looking at risk because it then became very easy to exploit, you know, a minor rounding error within a protocol to extract a lot of funds. Um so that wasn't in the original cover, that was added in 2021 when we first launched protocol cover. Uh we were looking at things like the Maker DAO Black Thursday event.

That wasn't a smart contract exploit, it was an economic design failure. So we had that and it's been improved. So we've looked at all of the risk over time and then what could we underwrite? What were factors that we could assess and verifiably prove that they happened on chain and that's what makes protocol cover what it is today. We've made a lot of improvements.

So now we're looking at protecting people against a loss of funds due to a smart contract exploit or as the language which says an unintended use of smart contracts that results in a loss. Um oracle failure, which is namely like stale oracle data that gets pushed out. If there's stale oracle data and it leads to a loss of funds, we cover that. It also includes fixed rate oracles where somebody fat fingers an update and that leads to wrongful liquidation. There's a few other um provisions in there in the definition as well.

Oracle manipulation, which is pretty clear. And then a liquidation fail failure, which is originally the thing that we wanted to cover for Maker DAO Black Thursday. We've seen a lot of that too in the last year um with some of these collateral impairment events like with KELP. So when you have a collateral impairment and liquidations cannot occur and that bad debt is realized and gets passed on to lenders, that is something that we cover with protocol cover and that's something especially in lending protocols because they are the base layer for most yield strategies. Anybody running leverage loops are doing it through some lending protocol, whether it's Morpho or Aave or some other venue.

Um and they definitely want coverage against those type of events. People providing liquidity and also people who are running those leverage trades need those cover products. So with protocol cover, that's what we're looking at when we're underwriting most protocols. We also have deep paid cover for deep paid events. We've got a product that we allow funds to purchase cover for which is called leverage liquidation cover.

If you have deep paid cover, you have to swap your covered token for the payout if there's a deep paid event. Doesn't work when you're running a leverage strategy with like kind assets. So that one is specifically tailored to these funds that are running strategies where if there's a deep paid event or some Oracle event that results in a liquidation of the position when they shouldn't have been liquidated, we cover against that risk. So you can think of it as deep paid cover for leverage loop positions. Covering against that collateral impairment or an event where if someone is liquidated and they shouldn't have been because of some other factor outside of the lending protocol.

So we have quite a few different products, but the core products that we sell are protocol cover and different variants of it. You know, that's one of the provisions included in fund portfolio cover. We underwrite cover for different funds. Deep paid cover is another popular one and then this lever leverage liquidation cover which is newer but is growing in popularity. >> And so how are you looking at opportunities moving forward?

Uh do you find that there's still segments that are not covered or rather catered to in terms of coverage because and just as like my immediate thought in response to that is one of the additional I guess uh vulnerabilities in DFI are bridges uh which is one that that you didn't mention. I'm curious how you guys think about this if there's a been a you know, a reason into uh covering or not covering let's say bridge exploits. >> Yeah, bridges are tough, right? So we have in protocol cover that we can't cover bridge components unless it's explicitly outlined in the annex that we're covering that. The problem with bridges is they are central points of failure and they're also honey pots.

So if you have something like if we look at the Kelp event as an example, that one collateral on Pyramid impacted lending markets across Ave across different networks. It also impacted, you know, other lending markets but not to the same degree. So that one event could trigger losses in almost every lending protocol and different yield strategies that are using those lending protocols. So now you have something that's akin not quite to a black swan event, but a mass loss event. So covering something like that becomes very difficult to control the amount of risk you're underwriting and limiting certain risk to certain business lines.

That'll lead someone to blow up, right? This is what we saw with different people underwriting risk and not controlling their exposure like with the UST depeg event. You know, a lot of people were underwriting that back in the day and then a lot of those protocols blew up because they had too much exposure and never recovered from it. So with Bridges it's really the same. We'd like to cover more bridge risk and we can do this on smaller levels, but until we see, you know, bridge risk kind of coming down, this is something that, you know, we'll look to cover more, but it's very difficult to cover things like that are central points of failure.

Things like sequencers, right? Like native bridges between Ethereum and let's say optimism or Arbitrum. Like things like that we could cover. The you know, the risk is lower there. But some of these other bridge solutions are trickier, especially when most people are using them.

I think people have realized that now about, you know, Layer Zero because so many people were using it, then people were servicing how many, you know, tokens were being bridged and used with a one-of-one DVNs and realizing that was a core weakness that could impact a lot of people. >> Mhm. Makes absolute sense. Thank you for that. I think that was a really >> [clears throat] >> clear essentially like business answer, right?

I mean this makes this makes complete sense from a business perspective as well. Um so I appreciate that and I'd love to zoom out cuz you know, you're the guy to pick their brain in terms of the state of DFI and especially the state of risk in DFI. Um comparing let's say DFI summer till until today. Obviously DFI protocols have become significantly more robust, right? But at the same time the space is super competitive.

Teams are challenged to adapt um and complete and continually create new innovative technology. I'm curious, do you see the general risk profile of DFI um being reduced over time uh and essentially being simplified or that these are just becoming increasingly more complex as new innovation comes out, new looping strategies, right? Uh new types of opportunities within the space. >> [snorts] >> I think the short answer here is it's both. Things are getting more complex and in some cases more simplified as time goes on.

If you look at something like DFI summer, when that started there wasn't the amount of capital in DFI. There was more experimentation going on, things were new, things were not battle tested. But you saw more protocols that were more immutable than there are now, right? There are a lot more protocols that are upgradeable than immutable. Um but we also saw things like I was talking about.

Flash loans came out, people were using Oracle sources where the price feeds were centralized, easier to manipulate or to have some out uh you know, outlier effect where like with compound and I want to say it was 2020 or 2021, um somewhere in that time frame between 2020 and 2022, there was like a the Thanksgiving event where they were using the die market on Coinbase as the Oracle source. There was a lot of demand for die, die got pushed up and people are wrongfully liquidated on compound to a large degree. So, transitioning to oracles that had different pricing sources that were more decentralized was a big feature, right? So, in that sense, we've seen more people secure their protocols against well-known risks. Uh in other instances, we've seen in lending markets, uh it it's a better protection for borrowers but using a fixed-rate oracle um where there's basically like a manual update to the price feed, exchange rate oracles.

These are good because you're not relying on market uh liquidity to determine the spot price. So, things can't be easily manipulated there. But, if there is a blow-up, if there is some event, especially with a fixed-rate oracle, if that oracle is not updated, liquidations are not happening in a lending market, and that's what creates bad debt. We saw that with the stream event, we saw that with resolve when there was the minting exploit, we saw that with Kelp. Um because people were quick to act on Kelp, uh the bad debt was somewhat limited.

But, if there are not liquidations happening, you're going to see bad debt. That has become a larger risk factor here in the last couple of years. We're also seeing RWAs come on chain, and they vary in quality. So, not all RWAs are created equal. That is going to introduce some more risk on chain as well.

You can't look into an RWA and understand what is in the underlying like you can with some other DeFi products. So, in some senses, things are more simplified, things are getting more complex. Um there are a lot of protocols with different dependencies. And I would say one of the biggest risk factors, which has been over time, is operational security failure. So, if you look within a protocol and you're looking at where the privileged functions within that protocol, and you see that there's one multi-sig, or let's say an EOA or an MPC, and an EOA and an MPC when you're looking on chain look the same.

So, you basically need to verify with the team, you know, is Is an EOA, or are you using an MPC, and if so, like what are some of the thresholds there? That is the leading cause of loss uh over the lifetime of DeFi and CeFi, but especially in the last several years. It's easier for North Korean state actors to compromise a dev or compromise somebody on a multi-sig than it is for them to actually hack a protocol. So, on the smart contract risk side, we are seeing risk come down um across some of these battle-tested protocols. With some of the more immutable protocols, like Morpho, you see the smart contract risk lessened, but all markets on Morpho are not the same, right?

So, you have to look at what long-tail assets are there, what oracles are being used, and what the collateral uh you know, risk it is itself, especially since we cover liquidation failure. The you know, the bottom line is that risk is always changing on chain. If you're looking at a lending protocol that's peer-to-pool, like Aave, that risk changes depending on what collateral becomes dominant. You know, somebody just posted in the thread about Athena providing liquidity to some of these different lending markets, like Aave, where people are also borrowing in size against sUSD and USD E. Right?

So, you have risks like that you need to keep track of because if there was some loss event within Athena, and they have liquidity for redemptions that's on Aave, and utilization goes to 100%, they now can't withdraw, and so the risk in that asset changes depending on where they're providing liquidity to and how they're earning yield, and you know, where their token is used as collateral. So, it's always changing, and you always have to track these things, so it's I think it's getting safer on the smart contract side and getting riskier in certain other elements on chain. >> And and so, does this does the dynamic does the hm dynamic um backing of risk, risk itself, as you just defined it, is dynamic, uh does it does this impact how Nexus Mutual approaches cover? Uh like, do different positions I guess the yield on a different position is associated with the risk and this is fluctuating as these details change in real time. >> Yes.

Yeah, so our due diligence process is pretty comprehensive. I've built this out and improved it quite a bit in the last couple of years. Now we have like a standard due diligence questionnaire. We'll send this to different teams when they come and ask for the protocol to be listed. Um we'll send this to funds.

We basically need a baseline of, you know, what is the risk and verifying what we're finding in our due diligence by looking on chain. Sometimes the code base is not public, so you need to look at the code base and get access to it to actually understand what the risk is for the code. You can look on chain. We want to verify that, you know, the byte code on chain is the same in the GitHub. So we're looking at all those things, but we're also monitoring a protocol over time to see when the risk is changing and how it's changing.

>> Mhm. >> [clears throat] >> So we're looking at a variety of different things. The oracle risk, the asset risk, smart contract risk. If there are off-chain components, we're looking at that. We're looking at the custody risk even though we're not covering that today.

I am working on a product that teams can purchase that's uh you know, operational security risk basically. Um still in development, but working on covering risk like that. It's always changing and so we're looking at these things when we're doing due diligence. And we're trying to see, you know, what are the risks here and how do we price this risk? The one interesting thing you said is, you know, there's the risk and the yield correlate.

And and the honest answer is no. Sometimes people will say, well, you know, this listing is too expensive. Right? I can earn 3% here, but the cost of cover is uh you know, 1.5%. So it doesn't make economic sense.

And my view is like in times like this where market yields compress, you actually see people move up the risk curve to get higher yields to be competitive. And so sometimes that risk is actually higher than the available yield. Things like that I stay away from. >> Mhm. >> But uh you know, when you're looking at things and you look into the underlying like somebody had asked us to look at Stream.

Like, can you cover this? And I looked at it and I came back and I was like, this is not a protocol. I'm pretty sure this is someone moving funds around with EOAs. Like, this is and everything they're doing is incredibly risky. Like, this is a hot ball of risk and we don't want to touch it.

So, we just politely went back and said, we can't write in there there's way too much risk here. Um we had multiple people ask us about this and so that's why we didn't have a lot of exposure to this. We were just had some exposure in some underlying yield protocols that we were covering. Um But, yeah. I mean, we look at all of this when we're looking at protocols and more when we're looking at other things like Dpeg cover.

Especially with Dpeg cover, you have to be very comprehensive in the due diligence. >> It it and so for me with this begs the question, right? You're explaining all the different dimensions of risk. Dpeg risk, sequencer risk, oracle risk, contract uh vulnerabilities. All of these are different dimensions of risk.

I I'm always curious from your end. Um do you look at these risks as compounding in the sense that, you know, I maybe I can best give an example here. Let's say you're looking at oracle risk. You already are deciding that the oracle price feed itself is based on low liquidity and thus more risky. Um but underlying the oracle is now dependent on let's say one RPC as opposed to two or as opposed to a primary and a failover.

And so in my understanding of the space, these risks can essentially compound on the infra side. They can be like inter dependent in a sense where um they're not necessarily isolated all the time. And I'm curious how you look at this. Do you guys break these down in isolated risk environments? Or do you can you also view this as you know, the overall picture as to all of these interconnections and dependencies on each other and the general risk profile as they all connect?

>> You have look at it from a holistic point of view where you layer everything together, right? You can't look at something in isolation and say, well, this is only the smart contract risk, so we don't have to worry about this. Sometimes, in a lot of complex exploits, you know, it's a variety of Oracle risk and a vulnerability within the code. Both things are exploited at the same time. But, speaking of like a lending protocol to go back, because lending protocols are riskier because there are just a lot of third-party dependencies, a lot of things you have to look at.

Um so, with something like Morpho, because markets are isolated, you're limiting some of the risk, but you have somebody that's allocating liquidity to different markets. So, if you have a lot of the same vaults allocating to the same markets and those markets incur a loss, they'll still see a large-scale losses. If you're looking at something like a peer-to-pool model like Aave uses for Aave V3, then you have to look at not just the Oracles, but the assets on there, right? So, if the Oracles you're looking at, you know, they're using an exchange rate or they're basically using a fixed-rate Oracle for something like USDE. I believe USDE, the Oracle source is still the USDT price for that.

So, if something happens and the Oracle isn't updated, that can cause a risk. But, also, if there's some impairment to USDE and the Oracle isn't updated in time, now you have bad debt, and then that is going to impact other markets and other liquidity providers, because this is a large, you know, it's used as USDE, SUSDE, and the collateral tokens on Aave. And that is going to have ripple effects elsewhere. So, in the case of something like Kelp, Aave didn't have any vulnerabilities. They were using an exchange rate Oracle.

Everything there was fine. It was just that collateral was impaired because the bridge risk wasn't taken into account. And when that was impaired, Aave acted very quickly to pause markets to limit damage. But, nonetheless, you know, your peer-to-pool market uh is as strong as the weakest collateral in it. So, it's things like that you have to look at in kind of a holistic picture of what's the worst case scenario and what's the likelihood of this happening.

So, that's what we're looking at when we're calculating, you know, estimated loss in a protocol based on any one of these factors. So, that's how all the loading is added together when we look at pricing. >> Excellent. Yeah, thank you for that. That that really helps to clarify.

I've been thinking [clears throat] about this for quite some time since these events of probably since November of last year. That helps to bring full circle clarity to kind of how I've been my curiosity as to how you guys look at this. Um I've got maybe like I hate to go so niche in my questions here. I'll zoom out after this, but I've got one more personal question based on you you're constantly touching on the point of oracles and hard-coded oracles. Um and the industry tends to really uh lean away from these.

I think these are always perceived negatively. And it's funny when something happens and it you know, something goes wrong and then you uncover that of this oracle was hard-coded. It's always like how how is this still an industry in which oracles can be hard-coded or hard-pegged to one? Um obviously there's benefits there could there's potential benefits mitigating, let's say, like reflexive liquidations based on low liquidity. Um but then it's all good until actually something goes wrong and then you end up with bad debt.

From the risk side, from the uh you know, from the Nexus Mutual side, how do you guys look at these? Do you feel that there are any instances in which hard-coded or you know, pegged oracles actually make sense in the space? >> Well, I think if you look at things from like a curator's perspective or a you know, a risk service provider in lending markets, where do you make your money? You make your money from the people that are actually borrowing funds in a lending market. And borrowers want protections to know that they're not going to get liquidated if there's, you know, like market volatility in a short period of time.

So, an exchange rate oracle makes sense when there's redemptions that are enabled, right? So, for LSTs, looking at the exchange rate is likely safer for borrowers than it is to look at you know, like spot prices because liquidity can fluctuate and if you get liquidated in a period where if you're using the exchange rate, you wouldn't have gotten liquidated, you're going to see people want to use those lending markets even if they have to pay a little bit more in borrow cost to get that certainty. So, that is something to think about. That risk gets passed on to let lenders and that's the thing that we're looking at when we're looking at risk. In some cases, I think it's appropriate to use an exchange rate oracle when there are redemptions.

For things like RWAs especially, like there's not a lot of secondary liquidity, but redemptions, depending on the settlement time, are there. So, as long as you can have timely redemptions, you know, it's okay to use some of these. So, it's kind of on a case-by-case basis. That being said, having fallback oracles is an important component that we're looking at, but the one thing that I want to touch on is hardcoded oracle in my mind is it's hardcoded and can't be changed. A fixed rate oracle is where the price is updated by somebody, typically by a multi-sig.

And the one really important thing there is who has the ability to update the asset price, right? If it's the issuer, then you kind of have this conflict of interest where if there's market volatility and like with Stream and Resolve, in both cases that those teams were updating the oracle, they didn't update the oracle after, you know, there was a loss of that. And that basically gives people a very cheap option to take deep bank collateral, go to a lending market, and borrow against it to either make a profit or exit and try to limit their losses. So, that is one of the bigger risks. We still see people doing this in lending markets.

It's hard for lenders to figure that out, and so a lot of times, like you always said before, the people that bear these risks are the people that are the least sophisticated and they're there because it benefits borrowers. These are all things that we take into account when we're pricing the Oracle on asset risk in these different lending markets for sure. >> Yeah, I think also a very good >> [clears throat] >> you know, explanation you shared as it relates to fixed rate versus exchange rate as well. Completely aligned with you on exchange rate. What is what's essentially it's underlying redeemability.

Whereas fixed rate would be more of like a locked in price that's set by a signer as you mentioned. Which is more so what I was leaning towards suggest fraying away from and more towards exchange rate. So I completely agree on that one. I want to go into what you guys are doing now on Vault and the recent partnerships that you guys have. But maybe off on, who are the current consumers mainly of Cover that you guys are working with?

Do you find that it's still retail or do you find that now it's institutions that are entering the space that are demanding and have more of an appetite uh for the Cover? >> It's actually largely been institutions for several years now. So the largest Cover buyers we have are our funds and different institutions that are purchasing Cover. They typically use our fund portfolio Cover product. So what they can do is they can pretty much send us their portfolio breakdown.

They can determine like what their AUM cap is, like how much Cover they want to buy for their fund. They specify the deductible and then we work that out and we update it on a monthly basis based on their exposures. So instead of having to buy Cover in piecemeal, they're buying it for their whole portfolio in just one Cover. And then we work with them on that. We provide discounts for funds that are using monitoring solutions.

You know, there's other things that we look at that we can give them discounts for. So we're giving them you know, a very competitive price based on their underlying exposure. So we see a lot of demand there. We also have some more institutions that are buying like leverage liquidation Cover and some of these other products. So that's where we see a lot of the demand from.

Now with things that have happened here in the last year, there are more protocol teams that are interested in providing cover for their users, whether it's purchasing it directly through something like a fund portfolio cover product or native protocol cover, or through having covered vaults, which we'll talk a little bit more about, but offering a solution for the users to access cover so they can protect themselves, or providing some base level of coverage for their users. So, we're talking to quite a few people about this here at the moment. >> Very clear. Absolutely makes sense. I mean, it's uh it's it it's a product that applies for pretty much all DeFi users.

So, and I would definitely assume that it's As mentioned in the beginning, I think it's exciting cuz the demand for cover scales in correlation with how the industry scales. So, it's a pretty good position to be in uh as more capital comes on chain. But, let's go deeper into vaults. Um vaults are, in my opinion, really the flagship DeFi use case right now for onboarding institutions and um allocating capital into different strategies. How are you guys targeting this?

How are How is Nexus Mutual going deeper into vaults? Um and I think you have some relevant partnerships that have allowed you guys to uh the Open Cover partnership that has allowed you guys to maybe access this a little bit. Can you tell me more about the context of that relationship that you guys have and how it's um breaking into the vault space? Yeah, absolutely. So, vaults are really interesting because a vault makes yield accessible.

It strips away all the complexity, and you're basically delegating to a vault manager the curation strategy, right? They have the strategy. It's much like Yearn back in DeFi summer, but with a lot more functionality now. Um So, there's the big vault providers like uh Veda, Upshift, um Lagoon, Mellow. Like, a lot of these vault providers are working with large curators, and it makes it a lot easier for retail institutions, a lot of different people to access yield.

And the underlying stack, again, can be very complex, can be very simple. So, providing coverage at that layer for a whole vault is really important. This is something that we've been talking about with Open Cover, who is one of our distribution partners. They're built on top of Nexus. We've been working with them for several years.

And they just built this really cool product called Covered Vaults. And a Covered Vault is essentially um an asynchronous vault that's built on the 4626 standard. So, it's the 7540 standard. And this plugs on top of any 4626 vault. So, you deposit into the 4626 vault, and you put your vaults here in the Covered Vault.

The Covered Vault harvests some of the yield to pay for the coverage. But you as a user deposit in the vault, you're covered, right? Your coverage is active. And then if you want to no longer pay for coverage, if you don't want to be covered anymore, then you just withdraw from the vault. It abstracts away all of the complexities of buying cover, of topping up your coverage.

And it also, if there's a claim event, strips away that complexity, too, because the vault manager files claim, and then reimburses the users in the vault. So, it makes cover dead simple, right? So, if you have an option in a UI somewhere to deposit into a vault with no coverage or with coverage, it simplifies the process and also makes coverage more accessible for people of all different user types, right? Retail users, institutions, funds, high net worth individuals, everybody has access to the same product. So, we're looking to make cover more accessible and more composable within DeFi through Covered Vaults.

We've already seen some really cool partnerships. Open Cover partnered with Picnic. Um they're offering basically on-chain savings for people, like a neo bank solution, for people in Brazil. So, we've already seen scale cover scale up in that vault as more people are depositing in clips that are small as like 500 bucks to $10,000 clips of cover for individuals. So, we're seeing a lot interesting use cases, and I've been working on a ton of quotes for covered vaults.

So, I think it's something that's very interesting. We're talking with different curators too that want to offer covered vaults uh within their app for their different platforms and their different vault strategies. So, it's something that has really resonated with people and I think we'll see a lot of success with covered vaults. >> Absolutely agree and I think that that's a really great user experience that you mentioned. You can take the vault share token that you receive for depositing the vault and just deposit that simply into the covered vault, right?

So, you're essentially getting your cover uh just using already it's just a creating additional capital efficiency essentially on top of the vault share token that you have uh to get cover on it. Um so, that that's a really cool that's amazing. Do you feel that this from the Nexus Mutual side and maybe zooming out the broader DeFi landscape is the largest growth vertical for you guys right now as relates to new demand for cover would be through these vaults? >> I think within DeFi, absolutely. Like covered vaults, it's a big unlock.

Right? It makes coverage more accessible. You don't have to manage things, you don't have to maintain things, you don't have to become a member of the mutual to access covered vaults. It really just simplifies things, you know? And it's a really great user experience.

I can say that as somebody that's deposited in the Origin uh stETH arm vaults. That's I have some ETH in there as well and I'm earning, you know, after you pay for cover, I'm earning about 5% of my ETH, which is pretty great. So, I think that user experience getting integrated in more interfaces. So, instead of having to go to open cover to deposit in the covered vault, you can just do it let's say on vaults.fyi or you can do it directly, you know, in these different curator uh curators apps. You just have that option.

I think that will be a way and that more people will be accessing yield. I still think we'll see funds that'll be buying fund portfolio cover, but I do think that we'll see more people offering some level of coverage um either first loss coverage or buying a layer of coverage for their users and then also um combining that with covered vaults as well. So, I think on that side with on-chain risk, we'll see that. We've also been working um with some of our own vaults. We have this vault called the real world insurance vault.

And what this does is it takes on-chain capital and bridges it through re protocol into traditional reinsurance markets. So, people can access yield that way through Nexus Mutual and that is a vault that deploys into the strategy and earns yield and there's this baseline yield coverage that we offer. So, it's a fixed 6% based on current rates that you earn now. If you lock up your tokens, if there's excess earnings from the strategy, you will get a proportional share of that. The longer you lock, the higher the proportional share you get.

Um so, this is really cool, too, because it's not everybody can get access to traditional reinsurance market yields. So, it makes a yield that is inaccessible to a lot of people accessible and it covers risks like if the yield drops below 6%, it would pay out so that you get that baseline 6% yield. And then if there is a loss because there's a payout on, you know, that traditional reinsurance side, it covers against that as well. It covers against some loss acting within the vault as well. So, that fixed coverage layer, I think for off-chain yield strategies, you know, things like the real world insurance vault or as we call it the RWI vault, I think that strategy will be more popular as well so people can have more access to off-chain yields through that structure.

>> Absolutely. [clears throat] Thank you. I'm glad you touched on this because so far we've really gone deeper into um taking out cover, but now this is kind of I wanted to before we transition towards kind of wrapping up, go deeper into the side of earning yield on providing liquidity for cover. So, you just touched on that with the um kind of the reinsurance and the RWA insured vault. And then more broadly speaking for the DeFi side of the other coverage, can you go can you take us back again through how this works?

I if you know and maybe you can update me, but my understanding is that this is really routed through NXM token stakers then they allocate or decide to which pools they would like to provide the liquidity for cover and then earn yield based on that. So, that's still the correct architecture understanding and can you give us some context on that? >> Yeah, so underwriting within the mutual works members can purchase NXM tokens, they hold NXM tokens, and that's backed by the assets that are held in the capital pool, which is largely ETH, some ETH LSTs, some stable coins, and a little bit of cvBTC. So, NXM holders can they can run their own staking pool if they want, right? Their own underwriting pool.

What a lot of them choose to do is to delegate their NXM to staking pools that are run by risk experts. I, for example, run my own staking pool, pool 22. It currently has the most NXM delegations. So, I'm running the largest underwriting pool. And I'm the one that decides where the NXM is allocated, you know, how much capacity we're opening up for certain risks.

And a lot of that is following, you know, the deal flow that we get for different products or where we're seeing demand, which we monitor through our Dune Dashboards and through alerts that we have internally. We also share this data with other people that are running staking pools, other large underwriting pool providers. And so, whenever cover is sold, that cover is going to be routed to the lowest-priced staking pool. And pricing moves around, so it's dynamic. So, if there's a lot of demand for one pool, the price shoots up.

That way we evenly distribute cover purchases around the different pool providers. And that yield is earned in NXM. And that is what underwriters are earning. So, as an NX M holder, you earn uh you know, revenue from premiums that come into the capital pool, from investment earnings over time, and from some of the automated buybacks that we have through the RAM when people redeem their NX M. The RAM captures some value and that all goes back to NX M holders.

And then those who choose to stake uh with their NX M and underwrite risk through these different staking pools, they're also earning additional NX M rewards for putting capital up to underwrite against risk. So, this is how underwriting works within the mutual. Um you know, returns vary over time, but the APY in my pool right now is uh 4.4% over the last year. It's been between, let's say, uh 4 and 8% as it scaled up. And then you've got the valuable pool from the book value growth that we see over time as well.

So, I think personally in my pool last year, I think I earned about 15% um between book value growth on NX M and the returns I earned in my pool. So, not too bad for an ETH-based asset. >> Not too bad. That's pretty good yield right there. So, shout-out to pool 22, right?

That's the that's [laughter] the one to look into, I suppose. Um excellent. And and I also really like the integral connection between NX M and the architecture itself. Um also something that is fascinating and great to see out of a product a project that was launched in 2019, right? Back back in the day where um a lot of ICOs and and governance tokens didn't really connect to core utility within the architecture.

So, really also like great to see how deeply connected that is within the mod the model itself. Um in the sake of time, I want to wrap it up, I guess, but I also want to make sure I didn't skip anything. I think this is a rather um comprehensive topic. Um and I I want to make sure that there's nothing I skipped over or missed that you feel would be worth highlighting or you know, details as to what might be coming next uh that that you that we should flag uh before we jump off. But, otherwise, not to put you on the spot, I just want to ensure that uh we tackle everything from the Nexus side.

>> Yeah, I think we covered a lot of the core topics. I mean, we could talk all day about Nexus and risk. Uh it's literally an endless topic. Um I think I can just speak to kind of the things we're working on. So, we're always working on new cover products.

My uh you know, passion project here over the last like 9 months has been trying to figure out ways that we can cover operational security for teams. Um so, combining that with like a you know, like a crime policy, something along those lines, trying to find better ways that we can protect against that risk cuz that's a growing risk. We're also looking at, you know, other types of risk and like new products that we can launch. We launched kidnapping and ransom cover uh here at the beginning of the year. That's seen a lot of interest from people as well.

So, we're expanding not just into crypto-native risks, but other risks that people need coverage for that are not being, you know, catered to with traditional insurance. And a lot of the reason is because traditional insurers don't know how to exactly price this risk and they don't understand some of the core concepts. So, we've been doing this for a long time. We have a very large database. You know, this is kind of our nation.

This is what we spend all of our time doing. So, I'm always looking to cover risks and cover the most comprehensive amount of risks and provide coverage where people really need it. So, um we have a lot of cover products that we're working on that in that space as well as just as well as getting out pricing quotes for people, keeping up with uh demand on that side and like again, we've seen a lot of inbound this year with all these hacks. So, >> Yeah. >> it's the job's never done.

>> That's fascinating. Again, it's just an ever-evolving case study as to the space at large. Um risks evolving and to keep up with Nexus Mutual is to keep up with um security in the space. What you guys are providing cover for are the new are our growing risks and clearly there's demand for cover for these items. So, kidnapping cover is honestly pretty dystopian, but very interesting, fascinating flag that you highlighted here.

So, something to look out for. Yeah, for those who are listening and want to go deeper, go look into either purchasing cover or providing liquidity for cover and maybe even going into um, you know, the different pools that you mentioned. Uh, what would be the best resource to go check out? >> Yeah, I think going to nexusmutual.io. You from there you can find our docs.

You can go into the Nexus Mutual app. Uh, there's lots of resources there. We have lots of resources, Dune dashboards, you know, things in our documentation. And we also have within our app, you know, we have a widget so you can actually reach out and talk to us. So, if people have specific questions, they can reach out to us there, reach out to us through the contact form.

You know, we'll respond and get back to you, but if people have questions, they can also reach out to me, you know, on Twitter. Um, and everything. Uh, if you want to get a hold of me, you definitely can. So, happy to chat with people more as well if they have questions. >> Excellent.

Well, Lee, thank you so much uh, for taking the time and diving deeper into Nexus Mutual. Um, always been fascinated about to learn more about it. So, really great opportunity for me to to go under the dive under the hood a little bit deeper and and get the chance to ask some questions. So, thank you for sharing about that. A lot of interesting topics touched today.

Um, and so I appreciate you for taking the time. >> Yeah, thanks for having me on. I really appreciate it. This was a great conversation. >> Excellent.

Yeah, absolutely. Um, well, then I'll end it off here. Uh, thank you everybody for listening to Beyond Yield and uh, with Nexus Mutual here and Lee and we'll see you on the next one. Thank you guys.

All episodes