RWA: Past, Present and FutureChapter 5 of 12
How a fund's price gets on-chain
A tokenized fund trades on no exchange, so a lending market that accepts it as collateral needs someone to write its value into the chain. That someone is an oracle, and the number it carries is the fund's NAV, computed off-chain by a firm that keeps the fund's books. This chapter follows that number from the books to the contract, compares the four oracle providers that carry it, and shows that the costly failure in this layer is usually an old number that nobody replaced.
What you'll learn
- Explain why a blockchain cannot fetch a price by itself and what an oracle does about it.
- Say who computes a fund's NAV and why the oracle only carries it.
- Tell a push feed from a pull feed and check any feed's freshness yourself.
- Compare Chainlink, RedStone, Pyth and Chronicle by design and by specialty.
- Separate a proof of reserve from an attestation and an audit.
In this chapter
Why a blockchain needs an oracle
A blockchain is a machine that thousands of computers run in lockstep, so every one of them must reach the same result from the same inputs. A contract that asked a website for a price would break that rule, because two computers asking a second apart could get two answers. So contracts read only what has already been written into the chain.
An oracle is the service that writes a number from outside the chain into a contract that other contracts can read. Chainlink's Data Feeds are the best-known example: a network of node operators agrees on a price and posts it to a contract, and lending protocols read it from there. The oracle moves data. It does not create it.
This matters because a contract acts on whatever number it is given with the same certainty. If a feed says a token worth 0.86 USD is worth 1.06 USD, the lending market will lend against 1.06 USD, which is what happened in the Stream Finance collapse described at the end of this chapter.
What NAV is and who computes it
NAV, net asset value, is what one unit of a fund is worth: total assets minus liabilities, divided by the units outstanding. A fund administrator is the firm that keeps a fund's books under fund accounting rules and strikes that official number. For BlackRock's BUIDL it is BNY Mellon, which is also the custodian.
Securitize, the tokenization platform behind BUIDL and other funds, puts the division of labour plainly in its 2026 SEC filings: it uses oracle providers to deliver NAV to smart contracts, and the NAV itself comes from the fund administrator or the transfer agent. A perfect oracle network will still carry a wrong number if the administrator computes it wrong or publishes it late. Decentralizing the oracle protects the number in transit and says nothing about how it was made.
This also breaks the standard oracle recipe. For a crypto asset, a provider takes prices from ten exchanges, drops the outliers and publishes the median. A private credit fund has no exchange price. It has one valuation from one administrator, and ten copies of that valuation are one source copied ten times.
Two more distinctions catch analysts out. Daily publication is not daily valuation: private credit is classically valued once a quarter, and a daily feed between those marks can be interpolation plus accrued interest. Daily NAV is also not daily liquidity. Apollo's ACRED fund strikes a daily NAV, yet it redeems quarterly and caps each redemption window at 5% of the fund.
Push, pull and the freshness trap
There are two ways to deliver a number, and they fail differently.
A push feed stores a value in a contract, where it sits until the provider writes a new one. A consumer calls a function such as latestRoundData() and gets the value plus updatedAt, the time it was written. A pull feed keeps the data off-chain as a signed package, and whoever needs it attaches the package to their own transaction, where a contract checks the signatures. Pyth works this way.
A push feed writes for one of two reasons. A heartbeat is the maximum idle time, after which the provider writes whatever the price did. A deviation threshold is the size of move that triggers an early write. The asset sets the spacing, as two reserve feeds published by Spark in July 2026 show.
| Feed | Heartbeat | Deviation threshold |
|---|---|---|
| TUSD reserves | 24 hours | 5% |
| WBTC reserves | about 10 minutes | 1% |
The trap sits with the consumer. Chainlink's documentation tells applications to check updatedAt themselves and stop if the value is too old. A stale feed raises no error. It returns an old value with a truthful old timestamp, and only a consumer that reads the timestamp can tell.
An oracle that was 225 days old
On 4 September 2026 at 11:08 UTC I read eight NAV and rate oracle contracts on Ethereum. Six were LlamaGuard contracts carrying NAV and risk data for tokenized funds, and two were Pendle rate feeds. All eight use Chainlink's standard interface, so from a consumer's side they look exactly like a Chainlink feed.
Most showed a daily rhythm. The JAAA and JTRSY feeds had been written 3.8 hours earlier, and USYC and USTB about 21 hours earlier, consistent with a write each business day.
Two did not. The USCC feed, for Superstate's crypto carry fund, had last been written on 22 January 2026, 225 days before my read, and it returned its old value with no error of any kind. The ACRED contract I read had never been written at all and returned zero. A zero is worse than a wrong value: a stale price mis-sizes a loan, while a zero can liquidate a whole position at once.
Behind the standard interface, the WRITER_ROLE that posts values on three of these contracts, USCC, USYC and ACRED, belonged to a single proxy contract, and the admin roles sat with externally owned accounts, meaning single private keys. Seven of the eight contracts returned maxPriceDeviation = 0, and the code comment says zero disables the check that caps how far a new value may jump. On USCC that call failed, so its setting is unknown.
The ACRED zero has a likely innocent explanation. RedStone publishes its ACRED feed at different addresses on Ethereum and Polygon, so the contract I read was probably an unused one. My read also measured state, not use: I did not establish that any live market prices collateral from these eight addresses.
Four providers, four designs
Four providers carry most RWA data, and each built its network around a different problem.
Chainlink is the incumbent. Its Data Feeds use Off-Chain Reporting: nodes exchange observations off-chain, one node assembles a report, a quorum co-signs it, and one on-chain transaction posts the median. Data Streams is its pull product for low-latency trading. For RWAs it sells SmartData, a family of three feeds: Proof of Reserve, NAVLink for fund NAV, and SmartAUM for assets under management. Securitize adopted NAVLink to price its funds as collateral on Aave Horizon, with VanEck's VBILL among the first assets.
Pyth specializes in fast market prices. More than 120 institutions, including Cboe, Coinbase and Virtu, publish their own prices to Pyth's dedicated chain, Pythnet, which combines them into one price with a confidence interval. The Wormhole bridge relays those prices to other chains, and anyone can post an update when a transaction needs it. Pyth pushes into equities, ETFs and commodities, and it built a USDY feed with Ondo in July 2024. It is not a NAV specialist.
Chronicle is the oracle MakerDAO built in 2017 for DAI's predecessor, spun out as Chronicle Labs and opened to outside projects in September 2023. Its Scribe design aggregates many signatures into one, so adding signers barely raises the gas cost of an update. In RWA it verifies assets rather than trading prices: a Chronicle Proof of Asset feed has covered BUIDL since March 2026, and Superstate chose Chronicle's Verified Asset Oracle for USTB, the fund it launched and still tokenizes, now managed by Invesco.
RedStone is the provider that has gone furthest into fund NAV, and it gets the next section.
RedStone and the single-source problem
RedStone's nodes sign data packages off-chain, and the same signed packages can arrive either way. In the pull model the user attaches them to a transaction. In the push model permissionless relayers post them to an on-chain adapter when a heartbeat or deviation trigger fires. RedStone treats both as first-class, and says it is the only provider to offer both across chains.
Securitize named RedStone its primary oracle partner on 12 March 2025. On 1 July 2025 the two announced TSSO, the Trusted Single Source Oracle, which accepts that a fund has one source and makes that source verifiable instead of pretending to aggregate. Each NAV update carries the asset ID, price, timestamp, a sequence number, and the hash and signature of the previous record, so any gap or edit in the chain of updates shows. A key kept in cold storage signs initial and large changes, and a separate key may post small routine updates within a narrow band.
The second product addresses what happens after the price. Lending markets liquidate in seconds, while redeeming a fund can take 30 to 180 days, in RedStone's own words. RedStone Settle, launched on 28 April 2026, auctions a failing RWA position to KYC-verified solvers. The winner repays the lender in one atomic transaction and then waits for the fund's normal redemption, earning the discount. RedStone has not disclosed any settlement volume.
Proof of reserve answers a narrower question
A NAV says what a unit is worth. A proof of reserve says whether the backing exists at all, and it sits next to two older checks.
An attestation is an accounting firm testing one claim by the issuer, at one moment, and signing a report on it. USDC's reserves are attested monthly. An audit is an opinion on a full set of financial statements over a period, including internal controls. BUIDL's fund is audited annually by PwC. An attestation says nothing about the day before or after, or about whether the assets were pledged elsewhere.
A proof of reserve feed turns that monthly snapshot into a stream: an oracle posts the reserve balance on-chain, and a contract can pause minting if the balance falls short. Chainlink's documentation names the limit. When the list of reserve addresses is self-reported by the issuer, the feed confirms that those addresses hold the funds, but not that the issuer owns them. Checking how a given feed builds its address list belongs in any product analysis.
Where oracle failures come from
Most losses blamed on oracles had nothing to do with the node network. Three documented cases fail at three different points.
| Incident | Date | Loss | Where it failed |
|---|---|---|---|
| Stream Finance, xUSD | Nov 2025 | about 93 mn USD | pricing source |
| Moonwell, cbETH feed | Feb 2026 | 1.78 mn USD bad debt | consumer configuration |
| Tectonic, TONIC token | Aug 2026 | about 75 mn USD | thin market read correctly |
In Stream's case, a lending market valued xUSD at 1.06 USD while the market paid about 0.86 USD, because the value came from a hardcoded price or the protocol's own reported NAV instead of a feed. Moonwell's loss came from a misconfigured feed on Base, with no attacker involved.
Tectonic, on the Cronos chain, is the sharpest lesson for RWA collateral. An attacker pumped the TONIC token roughly a hundredfold in 20 minutes on a thin pool, posted it as collateral and borrowed against it. RedStone, whose feed was used, said the oracle reported the pool price accurately, and that reporting a price and judging it safe to lend against are two different jobs. A tokenized fund with a thin secondary market carries the same risk.
The fourth failure mode has no incident yet: a value that ages while nobody attacks anything, like the USCC feed.
What to watch next
- Freshness checks in lending markets: protocols that reject stale NAV by reading
updatedAtclose the gap measured in this chapter, and their risk parameters show whether they do. - Pull-model NAV feeds: no provider offers one yet, and one would let a borrower bring a signed, current NAV instead of relying on a stored value.
- Settle volume: the first disclosed settlement numbers will show whether instant liquidation of RWA collateral works outside RedStone's own descriptions.
- Valuation cadence for private credit: disclosure of how often a credit fund is valued, as opposed to published, decides what a daily NAV feed is worth.
- Proof of reserve with verified addresses: feeds that prove ownership of reserve wallets would remove the self-reporting gap Chainlink documents.
Key takeaways
- A blockchain cannot fetch outside data, so every price a contract uses was written there by an oracle, and the contract trusts it completely.
- The fund administrator computes the NAV, and the oracle only carries it, so a perfect oracle still delivers a wrong or late number unchanged.
- Aggregating many sources protects market prices, while a fund with one administrator needs that single source signed and made verifiable.
- A push feed keeps its last value until someone writes a new one, and a stale value returns no error, so the consumer must check the timestamp.
- Chainlink leads on breadth and institutional mandates, Pyth on fast market prices, Chronicle on cheap verification, and RedStone on NAV for funds with no market.
- A proof of reserve confirms that listed addresses hold funds, which is narrower than an audit and only as good as its address list.
- Most oracle-blamed losses start at the pricing source, in the consumer's configuration or in a thin market, which no amount of node decentralization fixes.
Glossary
- Oracle
- a service that writes outside data into a contract other contracts can read.
- NAV (net asset value)
- what one unit of a fund is worth, total assets minus liabilities per unit.
- Fund administrator
- the firm that keeps a fund's books and strikes the official NAV.
- Push feed
- a value stored on-chain and replaced when the provider writes a new one.
- Pull feed
- signed data kept off-chain that a user attaches to a transaction when needed.
- Heartbeat
- the longest a push feed may go without a write.
- Deviation threshold
- the price move that triggers an early write to a push feed.
- TSSO
- RedStone's Trusted Single Source Oracle, which signs a single administrator's NAV into a verifiable chain of updates.
- Attestation
- an accountant's signed check of one issuer claim at one moment, narrower than an audit.
- Proof of reserve
- an on-chain feed reporting whether the reserves behind a token exist.
Go deeper
- Who holds the keys to a tokenized fund: the same split between an off-chain source of truth and an on-chain copy, applied to ownership.
- RWAs in DeFi: where these NAV feeds become collateral prices and liquidation triggers.
- RedStone and Chainlink: company profiles.
- 🟢 Chainlink Documentation, "Data Feeds" and "SmartData", https://docs.chain.link/data-feeds/smartdata
- 🟢 RedStone, "RedStone x Securitize unveil TSSO", 1 Jul 2025, https://blog.redstone.finance/2025/07/01/redstone-x-securitize-unveil-tsso-a-new-standard-for-tradfi-proof-of-reserve/
- 🟢 Pyth Network, "How Pyth works", https://docs.pyth.network/price-feeds/how-pyth-works
Sources
🟢 primary · 🟡 credible secondary · 🔴 tertiary (never used to cite a number)
- 🟢 Invesco and Superstate, "Invesco and Superstate Advance Institutional Tokenization Through USTB Partnership", PR Newswire, 24 Mar 2026, https://www.prnewswire.com/news-releases/invesco-and-superstate-advance-institutional-tokenization-through-ustb-partnership-302722437.html
- 🟢 Author's on-chain read, Ethereum, 4 Sep 2026, 11:08 UTC:
latestRoundData(),maxPriceDeviation()and role events on USCC0x129c32858fD67645Ae9FB37c9f41b81D380e29c9, ACRED0xE952F28c9DB1424e120d8c78aA174B0dC98200B9, USYC0x228Cb3e49EAeb10dD1B56Eeae0A8cBffD0bdF2A4, USTB0xc11B9FbFF1739dba70D1418BC8E6828cE66f61A2, JAAA0x8fA713d4E79238E5f6eB7479bEF0B7CFA51a9Ada, JTRSY0x74c0e98b5853e418219D6bF87fD26A73182F8876and two Pendle feeds. - 🟢 SEC EDGAR, Securitize Holdings, Form S-4/A amendments of 13 Apr, 8 May and 20 May 2026: NAV supplied by the fund administrator or transfer agent, oracle providers RedStone and Chronicle.
- 🟢 Chainlink Documentation, "Data Feeds", https://docs.chain.link/data-feeds, and "Off-Chain Reporting", https://docs.chain.link/architecture-overview/off-chain-reporting
- 🟢 Chainlink Documentation, "SmartData" and Proof of Reserve address-manager disclosure, https://docs.chain.link/data-feeds/smartdata
- 🟢 Chainlink on X, Securitize NAVLink integration for Aave Horizon, https://x.com/chainlink/status/1986437194035134609
- 🟢 RedStone Documentation, push and pull models, https://docs.redstone.finance/docs/dapps/redstone-push/ and https://docs.redstone.finance/docs/dapps/redstone-pull/
- 🟢 RedStone, "Securitize selects RedStone as primary blockchain oracle partner", 12 Mar 2025, https://blog.redstone.finance/2025/03/12/securitize-selects-redstone-as-primary-blockchain-oracle-partner-bringing-all-tokenized-assets-to-defi-ecosystems/
- 🟢 RedStone, "RedStone x Securitize unveil TSSO", 1 Jul 2025, https://blog.redstone.finance/2025/07/01/redstone-x-securitize-unveil-tsso-a-new-standard-for-tradfi-proof-of-reserve/
- 🟢 RedStone, "Tokenize the world: RedStone's role in the Securitize ecosystem", 6 Jul 2026, https://blog.redstone.finance/2026/07/06/tokenize-the-world-redstones-role-in-the-securitize-ecosystem/
- 🟢 RedStone, "RedStone powers onchain NAV for BlackRock's BRSRV", 12 Aug 2026, https://blog.redstone.finance/2026/08/12/redstone-powers-onchain-nav-for-blackrocks-brsrv/
- 🟢 RedStone, "RedStone Settle", 28 Apr 2026, https://blog.redstone.finance/2026/04/28/redstone-settle-bringing-instant-settlement-to-real-world-assets-liquidations/ and https://www.redstone.finance/settle/
- 🟢 RedStone, "Blockchain oracles comparison: Chainlink vs Pyth vs RedStone", 30 Mar 2026, https://blog.redstone.finance/2026/03/30/blockchain-oracles-comparison-chainlink-vs-pyth-vs-redstone-2026/ (company claims)
- 🟢 Pyth Network documentation, "How Pyth works" and "Cross-chain", https://docs.pyth.network/price-feeds/how-pyth-works; publishers page, https://pyth.network/publishers
- 🟢 Chronicle Labs, "Chronicle Protocol opens access to all Web3 builders", GlobeNewswire, 5 Sep 2023, https://www.globenewswire.com/news-release/2023/09/05/2737624/0/en/Chronicle-Protocol-the-Exclusive-5B-Oracle-of-MakerDAO-Opens-Access-to-All-Web3-Builders.html
- 🟢 Chronicle Labs, "What is Scribe", https://chroniclelabs.org/blog/what-is-scribe-the-novel-oracle-by-chronicle, and "Superstate opts for Chronicle Verified Asset Oracle for USTB", https://chroniclelabs.org/blog/superstate-opts-for-chronicle-verified-asset-oracle-for-ustb-fund
- 🟢 Securitize and Apollo, ACRED launch, PR Newswire, 30 Jan 2025, https://www.prnewswire.com/news-releases/apollo-and-securitize-announce-partnership-and-launch-tokenized-access-to-credit-fund-on-aptos-avalanche-ethereum-ink-polygon-and-solana-networks-302364212.html
- 🟡 The Block, "BlackRock tokenized BUIDL fund taps Chronicle", 26 Mar 2026, https://www.theblock.co/post/395173/blackrock-tokenized-buidl-fund-taps-chronicle-new-verification-layer
- 🟡 Unchained, ACRED quarterly redemptions capped at 5%, 9 May 2025, https://unchainedcrypto.com/defi-looping-comes-to-apollos-1-3-billion-credit-fund-what-could-go-wrong/
- 🟡 Spark, "Real-Time Reserve Attestation", 20 Jul 2026: TUSD and WBTC reserve feed parameters.
- 🟡 CCN, BlockEden and Tiger Research, Nov 2025: the Stream Finance disclosure and xUSD pricing.
- 🟡 cryptonews.com, "Oracle error leaves DeFi lender Moonwell with 1.8 million in bad debt", Feb 2026.
- 🟡 crypto.news, "Tectonic's 75M exploit not an oracle failure", 1 Sep 2026, https://crypto.news/tectonics-75m-dollars-exploit-not-an-oracle-failure/