15,000 USDC
View results
Submission Details
Severity: medium
Valid

Wrong WBTC price evaluation

Summary

WBTC would be wrongly evaluated as a BTC price.

Vulnerability Details

HelperConfig.s.sol contains BTC/USD CL price feed address 0x1b44F3514812d835EB1BDB0acB33d3fA3351Ee43. The protocol would use it as a source of WBTC price. However, while WBTC should be pegged to BTC price it's not always true. This could lead to a situation in which some positions would be unliquidatable during WBTC/BTC depeg. Also it would allow to mint lot of stablecoins for the low value of depegged WBTC.

Impact

Contracts deployed with the current deployment script would not receive correct prices WBTC from CL.

Tools Used

Manual review

Recommendations

Consider using WBTC/BTC:BTC/USD CL feeds ratio for evaluating the actual WBTC price.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.