Upbit Oracle migration
How the Kimp Index switches its Upbit KRW input to the official Upbit Oracle on GIWA through a governance-controlled source switch.
GIWA has announced an Upbit data oracle. When it ships on GIWA, KIMP will use it as the primary source for the Upbit KRW price in the index. This page describes how the switch works and what stays the same.
Current design#
In the launch design, every input to the index is supplied by the reporter set:
| Input | Supplied by |
|---|---|
| P_upbit_krw | Reporters |
| P_global_usd | Reporters |
| USDKRW | Reporters |
Reporters read Upbit's public market data like any other participant. The value is aggregated by median across reporters and secured by their bonds.
After migration#
| Input | Primary source | Fallback |
|---|---|---|
| P_upbit_krw | Upbit Oracle on GIWA | Reporters |
| P_global_usd | Reporters | None needed |
| USDKRW | Reporters | None needed |
A first-party oracle removes one layer of intermediation for the Upbit input. Reporters keep supplying the global price and FX, which the Upbit Oracle does not provide, and remain on standby for the Upbit input.
The source switch#
The KimpIndex contract separates where each input comes from and how the index is computed. The source for the Upbit input is set per asset with setSource on KimpIndex. Like every parameter setter in KIMP, it is callable only by the timelock.
The switch follows the standard governance process:
- 1Forum discussion of the oracle's properties: update frequency, coverage of listed assets, latency, and failure behavior.
- 2On-chain proposal by stakers above the proposal threshold.
- 3A 5-day vote with quorum.
- 4A 48-hour timelock, during which the pending change is visible on-chain.
- 5Execution of
setSourcefor the approved assets.
The switch can be made per asset. An asset not covered by the Upbit Oracle keeps using reporters for its Upbit input.
Fallback behavior#
If the Upbit Oracle fails to deliver a fresh value for an epoch, the index falls back to the reporter median for the Upbit input in that epoch. The fallback conditions are set in the same governance proposal as the switch. Reporter operations continue to be tested in production during the whole period, so the fallback is never cold.
If the oracle and the reporter set both fail to produce a value, the standard rules apply: the epoch is stale, and after 5 minutes without a finalized value the market becomes reduce-only. See Sampling and median.
What does not change#
- The formula and the unit, signed basis points.
- The 60-second epoch and the settlement TWAP.
- Global price and FX sourcing, and the rules in Sources.
- Reporter bonding, flagging and disputes for the inputs reporters supply.
- Open positions. A source switch takes effect at an epoch boundary and applies to marks from that point.
Reverting#
If the Upbit Oracle proves unreliable, governance can revert the source to reporters with the same setSource call through the same timelock.
Timing#
The switch happens after the official Upbit Oracle ships on GIWA and passes review. There is no date. The step is listed in the Roadmap.