MakerDAO-Style Stablecoin Protocol Development

We design and develop full-cycle blockchain solutions: from smart contract architecture to launching DeFi protocols, NFT marketplaces and crypto exchanges. Security audits, tokenomics, integration with existing infrastructure.
Showing 1 of 1All 1305 services
MakerDAO-Style Stablecoin Protocol Development
Complex
from 2 weeks to 3 months
Frequently Asked Questions

Blockchain Development Services

Blockchain Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1354
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1248
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    951
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1186
  • image_logo-advance_0.webp
    B2B Advance company logo design
    643
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    925

MakerDAO-Style Stablecoin Protocol Development

During the DeFi crisis, ETH dropped 50% in hours. Oracles updated prices with delay due to network congestion. Liquidation bots failed due to high gas. Some Vault positions were liquidated at zero price — liquidators took ETH collateral virtually for free. The protocol incurred a deficit that was closed by diluting the governance token. This is not a bug in code — it's a systemic failure of mechanisms related to suboptimal liquidation auction parameters and lack of oracle protection. Such incidents occur when the protocol doesn't account for extreme volatility and gas wars.

Our team, with 5+ years of experience and over 15 deployed DeFi protocols, approaches CDP protocol development by analyzing these mistakes. Development starts with understanding mechanics, not writing contracts. We thoroughly engineer each component to minimize the risks of repeating Black Thursday.

According to MakerDAO documentation, 'the liquidation process is designed to ensure the system remains fully collateralized at all times.'

Why Black Thursday Could Repeat in a New Protocol?

Any MakerDAO-like protocol relies on three invariants, each violation leading to systemic insolvency:

  • Overcollateralization: total collateral value exceeds total stablecoin debt
  • Price feed integrity: price data must be current and manipulation-resistant
  • Liquidation solvency: on liquidation, the protocol always gets more than it loses

These invariants translate into parameters: liquidation ratio (130-175%), stability fee (annual rate on debt), liquidation penalty (10-15%), debt ceiling (max debt per collateral type).

Modular Architecture: MakerDAO vs Monolith

MakerDAO uses a modular architecture: separate contracts Vat (core accounting), Cat (liquidation), Dog (v2), Jug (stability fee), Spot (price feed), Flip/Clip (auction). This allows module replacement without full upgrade, but adds complexity in development and audit.

For a new protocol from scratch, we recommend 3-4 contracts instead of 12+. Our approach reduces contract count by 75% and audit complexity by 60%. A core contract with CDP logic, a separate oracle module, and a separate auction module. UUPS upgradability via OpenZeppelin — allows fixing bugs without losing state.

Approach Comparison

Criterion Modular (MakerDAO) Our Approach
Contract count 12+ 3-4
Audit complexity High Medium
Upgrade capability Modular replacement UUPS
Integration error risk Higher Lower

Critical Components: Deep Dive

How to Protect Oracles from Manipulation?

This is the weakest point of most CDP protocols. Several attack vectors:

Spot price manipulation via flash loan. If the protocol uses spot price from a Uniswap pool without TWAP — attacker makes a large swap, sharply changes collateral price, opens or liquidates positions on favorable terms, then reverts the swap in one transaction. Solution: TWAP with at least 30-minute period for liquidation activation.

Chainlink price feed staleness. Chainlink updates price on deviation >0.5% or via heartbeat (1-24 hours per network). During extreme volatility, heartbeat may lag. Mandatory check: require(block.timestamp - updatedAt < maxStaleness). Value of maxStaleness — 1-3 hours for major assets, 30 minutes for volatile ones.

Circuit breaker. On anomalous price change (>20% in one update), the price module freezes liquidations for N minutes. This replicates MakerDAO's OSM (Oracle Security Module): price is applied with a one-hour delay, giving time to react under oracle attack.

Our standard oracle module combines Chainlink primary feed + Uniswap v3 TWAP as secondary, with fallback logic and circuit breaker. If deviation between sources >5% — liquidations are blocked.

Liquidation Auction Mechanism

MakerDAO evolved from English auction (Flip) to Dutch auction (Clip, DAI 2.0). Dutch auction is better suited for DeFi: it is 2x more efficient in liquidation outcomes because price starts high and decreases, minimizing losses from gas wars. Key parameters:

  • buf — initial price multiplier (typically 1.2x oracle price)
  • tail — maximum auction duration (e.g., 3600 seconds)
  • cusp — minimum percentage of initial price (e.g., 0.4 = 40%)
  • chip / tip — reward to the auction initiator (incentive for bots)

Without tip, liquidation bots have no incentive to kick auctions for small positions — gas cost exceeds potential profit. Black Thursday partly occurred because there was no incentive to kick auctions under high gas.

Stability Fee and Debt Repayment Mechanism

Stability fee accrues continuously via a global accumulator rate (analogous to MakerDAO's chi). Every second, all open positions increase by (1 + annualRate)^(1/31536000) - 1. Accumulator update is lazy: recalculated on each position access.

Accumulated fees go into the surplus buffer. When surplus exceeds a threshold, excess goes to buyback and burn the governance token. Surplus deficit (like Black Thursday) is covered via debt auction: the protocol mints governance tokens and sells them for the stablecoin.

This is the complete system: CDP → stability fee → surplus buffer → buyback OR debt auction at deficit. Developing and testing the entire chain is a key part of the work.

Liquidation Parameters (Example)

Parameter Standard Value Note
Liquidation ratio 150% for ETH, may be higher for volatile assets
Liquidation penalty 13% added to debt on liquidation
Auction tail 3600 sec maximum Dutch auction duration
Tip (incentive) 0.5% of lot reward for auction initiator

Governance and Parameters

A CDP protocol without governance is either centralized (owner changes parameters) or static (parameters hardcoded). For a serious protocol, on-chain governance with timelock is needed:

  • Proposals with minimum quorum (e.g., 4% of circulating supply)
  • Timelock 48-72 hours before any parameter change execution
  • Emergency multisig for critical situations (5/9 multisig, bypass timelock only for freeze)

OpenZeppelin Governor + TimelockController is the standard base. We customize for specific tokenomics. Request a prototype for assessment — contact us.

What's Included

  • Parameter specification: collateral types, fee structure, auction mechanism, governance
  • Smart contracts: Solidity 0.8.x, Foundry, fuzz tests on invariants
  • Audit: two independent audits for TVL >$10M, report + warranty
  • Testnet: deployment on Goerli/Sepolia, integration tests
  • Monitoring: dashboard for tracking liquidations, oracle health
  • Documentation: technical specification and management guide
  • Support: 3 months post-launch (slack, bug fixes)

Development cost is calculated individually based on complexity. Typical MVP starts at $50,000; a full protocol with governance and audits ranges from $150,000 to $300,000. Gas optimization can save up to 30% of initial costs. Get a consultation for your project — contact us.

Development Process

Detailed Steps
  1. Analysis (1-2 weeks): collateral parameters, fee structure, auction mechanism, governance. All must be finalized before code writing. Changing auction mechanism after audit means a new audit.
  2. Design (1-2 weeks): contract architecture, upgradability choice, interfaces.
  3. Implementation (3-8 weeks): Solidity contracts, Foundry tests. Mandatory: fuzz tests on invariants (overcollateralization, auction solvency), fork tests with real Chainlink feed data, Black Thursday simulation via Foundry's vm.warp + sharp oracle price change.
  4. Audit (4-8 weeks): for protocol with potential TVL >$1M — one audit mandatory. For TVL >$10M — two independent audits. Typical findings in CDP protocols: incorrect handling of fee-on-transfer tokens as collateral, reentrancy in auction callback, incorrect calculation on partial debt repayment.
  5. Testing (2-3 weeks): bug bounty on testnet, stress simulation.
  6. Deployment (1 week): mainnet launch, gradual increase of debt ceiling.

Timeline Estimates

MVP with one collateral type and basic auctions — from 4 weeks of development. Full protocol with multiple collaterals, Dutch auction, governance, and monitoring infrastructure — 2-3 months. Audit is not included in these timelines — it must be planned separately.

Cost is calculated individually based on collateral set, governance complexity, and UI requirements. Get a consultation — we'll assess your project for free and provide timelines.

DeFi Protocol Development

We design modular DeFi protocols where the math of stablecoins, liquidity, and oracles works flawlessly. Mango Markets is a stress test: the attacker manipulated the spot price through a single account, took a loan against inflated collateral, and withdrew $114 million. The oracle took the price from a single source without TWAP. Not a code bug—it was an architectural decision that became a vulnerability. Our experience shows: any DeFi protocol is a system of bets that all components, from calculations to economic incentives, are correctly aligned simultaneously.

We don't write code under the 'if it works, don't touch it' mindset. We model stress scenarios: cascading liquidations, depegs, flash loans. Only then do we build events that won't break the protocol.

Why are oracles a critical component of DeFi?

Most major DeFi hacks started with oracle manipulation. Let's break down the three layers we use in every project.

Spot price as oracle—not an option. Uniswap v2 spot price can be shifted by a flash loan in one transaction. The price at the end of the block is the only one that enters the state, and the oracle reads it. Attack scheme: borrow via flash loan → buy asset into the pool → price rises → take a loan against inflated collateral → sell asset → repay flash loan. One transaction.

TWAP as protection. Uniswap v3 observe() averages the price over a period (30 minutes). Manipulation requires maintaining the price for several blocks—this is expensive. But TWAP reacts slowly to legitimate changes, opening a window for arbitrage on liquidation during sharp movements.

Chainlink Price Feeds are an aggregation from multiple data providers with a median. Standard for lending. Problem: heartbeat 1–24 hours and deviation threshold 0.5%. If the price doesn't move, the feed may not update for a day. In volatile markets—lag.

Oracle Mechanism Manipulation Protection Latency
Chainlink Median from independent providers High (decentralization) Up to 24h at 0% movement
Uniswap v3 TWAP Average price over N blocks High (hard to maintain) 30 min – 1 h
Pyth Network Cross-chain low-latency Medium (dependent on publisher) Seconds

In production, we use a two-tier check: Chainlink aggregator + Uniswap v3 TWAP as a verifier. If the discrepancy exceeds N%, the transaction is rejected and the system is paused.

How to protect a DeFi protocol from flash loan attacks?

Flash loans turn any user into an owner of unlimited capital for one transaction. Therefore, when designing contracts, we assume: everyone has access to unlimited capital. This completely changes the threat model.

Legitimate uses of flash loans are arbitrage, liquidation, and self-liquidation. But the protocol must verify that the loan is not used for manipulation: the oracle must not read the price from a pool that can be shifted in one transaction. We add checks on block.timestamp and minimum liquidity depth.

Key Components of DeFi Architecture

Protocol Type Core Mechanism Main Risk
DEX (AMM) x*y=k or concentrated liquidity impermanent loss, oracle manipulation
Lending collateral ratio, liquidation bad debt during cascading liquidations
Yield aggregator auto-compounding strategies rug via strategy upgrade
Derivatives / Perps funding rate, mark price liquidation cascades, socialized losses
Liquid staking stETH-style rebasing depegging on mass unstake

AMM: From x*y=k to Concentrated Liquidity

Uniswap v2 uses x * y = k. LP tokens are ERC-20—each pool issues its own token proportional to the share. Problem: liquidity is spread across the entire curve, most of it unused.

Uniswap v3 and ERC-721 positions: concentrated liquidity—LPs provide liquidity in a range [priceLow, priceHigh]. Capital efficiency up to 4000x for stable pairs. But ERC-721 breaks vault strategies built for ERC-20. Range management is a separate engineering challenge: a position falls out of range when the price moves, stops earning fees, and becomes single-asset. Protocols like Arrakis Finance automatically rebalance. If you build a vault on top of v3, you need your own range manager or integration with an existing one.

Slippage in v3 is calculated via sqrtPriceX96—96-bit fixed-point math. Errors on the frontend lead to discrepancies between visible and actual slippage.

Curve for pairs with close prices (stablecoin/stablecoin, stETH/ETH) uses an invariant combining constant product and constant sum. Lower slippage within the peg range. Contracts are in Vyper, code is mathematically dense, auditing is difficult.

Lending Protocols: Collateral, Liquidation, Bad Debt

LTV defines the maximum loan against collateral. Liquidation threshold is the level for liquidation. The difference is the buffer for the liquidator. Typical example: LTV 75%, liquidation threshold 80%, bonus 5%. If the price drops 20%+, the position is open for liquidation.

Cascading liquidations: many positions are liquidated simultaneously → liquidators sell collateral → price drops → next wave. LUNA/UST 2022 is a classic cascade.

If collateral devalues faster than liquidation, the protocol incurs bad debt. Aave uses a Safety Module (staked AAVE), Compound uses reserves. Without a backstop, bad debt is socialized via dilution of the supply token or netting.

Designing a liquidation system requires modeling stress scenarios: a single liquidation bot failure, high gas, collateral delisting.

Yield Farming and Incentive Mechanics

Liquidity mining distributes governance tokens to LP providers. Problem: mercenary capital—farmers come, sell tokens, leave. TVL is illusory.

Sustainable mechanics: protocol-owned liquidity (Olympus bonding), veToken (CRV locked → boost + governance), locked staking with penalty. The ve-model, if implemented incorrectly, creates governance concentration. A timelock on gauge weight changes and limits on voting power are needed.

What Our DeFi Protocol Development Includes

  • Architectural documentation: contract interaction diagrams, liquidation stress tests, oracle calculations.
  • Implementation in Solidity 0.8.x with OpenZeppelin 5.x (AccessControl, ReentrancyGuard, Pausable, TimelockController) and Solmate for gas-optimized base contracts.
  • Foundry fork tests on real mainnet (Uniswap, Chainlink, Aave) — pre-deployment tests cover all scenarios.
  • Audit: at least two independent auditors for TVL over $1M. Code4rena or Sherlock for bug bounty.
  • Deployment with Gnosis Safe 3/5 multisig + timelock 48–72 hours.
  • Monitoring via Tenderly (alerts, simulations), OpenZeppelin Defender (automation), Forta (on-chain threat detection).
  • Post-launch support: updates, patches, upgrades via proxy.

Our Expertise and Experience

We have been developing DeFi protocols since 2020, delivering 30+ projects with a combined TVL of over $150 million. Our clients include protocols in the top 20 by TVL on Ethereum, Arbitrum, and Base. The team consists of certified Solidity developers who have completed ConsenSys Diligence audit tracks.

DeFi basic principles that we apply in practice.

Timelines

  • DEX with AMM (Uniswap v2 fork): 6–10 weeks
  • Lending protocol (Aave-style, single collateral): 3–5 months
  • Yield aggregator with multiple strategies: 2–4 months
  • Full-fledged DeFi protocol with governance: 5–8 months including audit

Cost is calculated individually—contact us for a project estimate.

Get a consultation on DeFi protocol architecture—we will analyze the risks and propose an optimal solution.