The Standard

The Standard
DeFiHardhat
20,000 USDC
View results
Submission Details
Severity: medium
Invalid

Chainlink's `latestRoundData` might return stale or incorrect results

Summary

In function distributeAssets of LiquidationPool.sol, we are using latestRoundData function to retrieve the price, but there is no check if the return value indicates stale data.

(,int256 priceEurUsd,,,) = Chainlink.AggregatorV3Interface(eurUsd).latestRoundData();

This could lead to stale prices according to the Chainlink documentation:

https://docs.chain.link/docs/historical-price-data/#historical-rounds

https://docs.chain.link/docs/faq/#how-can-i-check-if-the-answer-to-a-round-is-being-carried-over-from-a-previous-round

Vulnerability Details

(,int256 priceEurUsd,,,) = Chainlink.AggregatorV3Interface(eurUsd).latestRoundData();

(,int256 assetPriceUsd,,,) = Chainlink.AggregatorV3Interface(asset.token.clAddr).latestRoundData();

Impact

The price returned might be stale price, which will impact in the fund calculation.

Tools Used

Manual review

Recommendations

Consider adding following checks for stale data.

(uint80 RoundID, int256 priceEurUsd, , uint256 Timestamp, uint80 AnsweredInRound) = Chainlink.AggregatorV3Interface(eurUsd).latestRoundData();
require(AnsweredInRound >= RoundID , "Stale price");
require(Timestamp != 0 ,"Round not complete");
require(priceEurUsd > 0 ,"Chainlink answer reporting 0");
Updates

Lead Judging Commences

hrishibhat Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

Chainlink-price

hrishibhat Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Known issue
Assigned finding tags:

Chainlink-price

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.