15,000 USDC
View results
Submission Details
Severity: medium
Valid

Missing check for Layer2 Sequencer when fetching Chainlink oracle

Summary

Missing check for L2 sequencer, when fetching oracle price.

Vulnerability Details

The DCS uses chainlink oracles. There is a check for staleness, when fetching the oracle price. However there is no check if the L2 sequencer is down, which could lead to a wrong price returned.

Impact

Wrong price from oracle returned, when the L2 sqeuencer is down.

Tools Used

Manual Review

Recommendations

Check for L2 when fetching the oracle price.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.