Keepers: DeFi’s Blind Spot
Keepers are exterior bots or providers that monitor onchain exercise and provoke transactions when predefined situations are met. As a result of they’ll occupy privileged positions inside a protocol’s execution move, the dangers prolong past downtime, congestion, or compromised non-public keys. The execution path itself can change into an assault floor.
GMX V1 Keeper Execution-Stream Exploit — $42 Million
The attacker used GMX V1’s keeper execution move to entry a brief window wherein leverage was enabled, then re-entered the vault to create unusually massive brief positions. These positions manipulated the worldwide brief common value utilized in GMX’s AUM calculation, artificially inflated the value of GLP, and enabled roughly $42 million to be extracted by redemptions.
GMX demonstrates how keeper execution can change into a part of an exploit path. The keeper wasn’t compromised and didn’t execute an unauthorized transaction. The attacker exploited privileged protocol habits that grew to become out there whereas the keeper was legitimately executing an order.
Extra generally, keepers carry out routine actions similar to auto-compounding. In lots of liquidity and yield methods, they periodically declare collected charges or rewards and submit transactions that reinvest them into the place.
Carbon DeFi supplies native auto-compounding. Earnings are robotically added again to the place as trades execute, with out requiring an exterior bot to watch the place or submit a separate compounding transaction.
Automation isn’t a further service layered on prime of Carbon DeFi. It’s a part of the protocol’s underlying execution logic. Eradicating keeper-based execution eliminates one other exterior dependency and the operational dangers that include it.









