Skip to content

LibraryData and agents2020Design paperCorpus record

UMA Data Verification Mechanism: Adding Economic Guarantees to Blockchain Oracles

UMA. UMA.

An oracle that does not answer every question in real time. It prices the cost of bribing the token holders who would resolve a dispute, and it asks contract designers to keep the profit of a lie below that cost. The draft is an economic argument, not a feed you can read as truth.

UMA's data verification mechanism is an optimistic oracle. A proposed value stands unless it is disputed, and a dispute is resolved by a token-holder vote. The design rule is that the profit from a lie must be smaller than the cost of buying that vote. A contract that can pay out more than the vote costs has stepped outside the paper.

The five-minute read

Silence accepts

Undisputed proposals become the value. The system is cheap when nobody fights. It is also wrong when nobody fights and the proposal was a lie.

The vote is the backstop

Token holders commit and then reveal votes, so a voter cannot simply copy the emerging answer. That is a mechanism detail, not evidence that voters know the truth.

Cost versus profit

The paper's framework compares the cost of corrupting the oracle with the profit a contract would hand a liar. Security is an inequality about those two numbers.

The contract has to cooperate

The oracle does not automatically know how much a given contract can extract. Designers are told to keep payouts inside the inequality. A logo does not enforce it.

One action, walked through

  1. A contract requests a value and someone proposes an answer with a bond.
  2. During the liveness window, anyone can dispute.
  3. If nobody disputes, the proposal is treated as true.
  4. If someone disputes, token holders vote.
  5. The economic claim is that buying enough votes should cost more than the dispute can unlock.

The argument, unpacked

An economic guarantee is not a truth guarantee

The draft is explicit that public chains cannot fetch off-chain facts, only incentivise reporters. A reader who wants an authenticated data feed is looking for a different design, such as a signed committee, and different failure modes.

The token price is inside the security

Cost of corruption moves when the voting token's price moves. A security argument that treats that cost as a constant has left the paper.

What has to be true

  • The voting token is liquid enough that the cost of buying a swing is meaningful. The paper does not prove that a market exists.
  • Disputes are possible in the window. A censored dispute path collapses the mechanism to 'first proposal wins'.
  • The contract's maximum payout is the one used in the inequality.
  • The 2020 draft is not a later deployment. Later code can add governance, different bonds, or different voters.

What happened after the paper

Optimistic oracles in this family still use propose-and-dispute. The useful test is unchanged: write down the profit of a successful lie and the cost of swinging the vote. Chainlink is the contrasting design, a committee that publishes a value rather than a vote that might be called.

What to check before you use the idea

  • What is the largest payout a false value can release?
  • What does it cost to swing the vote, at a stated token price?
  • How long is the dispute window, and can it be censored?
  • Is an undisputed value being described as verified truth?

Terms

Cost of corruption
What an attacker must spend to make the oracle adopt a false value, in the paper's framework.
Profit from corruption
What that false value would unlock from the contracts that trust it.

The problem the paper names

A smart contract that pays off on an outside event needs a value. A committee can sign the wrong value. UMA asks whether the contract can be designed so that lying does not pay, even if the voters can be coordinated.

What the design proposes

  • A price request is proposed and, if undisputed, accepted. Dispute is the expensive path.
  • Disputes are resolved by a vote of token holders, with a commit-reveal so votes are not free to copy.
  • The design rule is profit-from-corruption less than cost-of-corruption. The contract, not the oracle, is supposed to enforce that inequality.

How the mechanism is specified

  • Most queries are meant to settle without a vote. The security argument is about the vote that could be called.
  • The cost of corruption is framed as the cost of buying enough voting tokens. That cost moves with the token's market, which the paper treats as an input, not a constant.
  • A contract that can pay out more than that cost has left the design rule, whatever logo it uses.

What this page does not treat as proven

  • This is an April 2020 draft, version 0.2. Later contracts are not automatically inside its argument.
  • An optimistic oracle can be wrong for as long as nobody disputes it. Silence is not evidence.
  • Nothing here is a guarantee that a number is true. It is a story about bribes.

Why a venture studio still reads it

For any contract that cites UMA, write down the most a liar could extract and the cost of swinging the vote. If the first number is larger, the paper's own test fails.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.