DeFiFoundry
60,000 USDC
View results
Submission Details
Severity: low
Valid

Missing Price Feed for weETH Leading to Order Creation Failure and Potential Manipulation Risks

Summary

The contract relies on Chainlink price feeds to determine the value of collateral. However, weETH does not have a Chainlink price feed, causing the createMarketOrder function to revert when attempting to fetch its price.

Vulnerability Details

Missing Price Feed: The weETH collateral lacks a Chainlink price feed.

Revert on Price Fetch: The getPrice function reverts if the price feed is not defined.

Price Discrepancy Risk: Using alternative price feeds could lead to price discrepancies and potential manipulation.

Impact

Order Creation Failure: Users cannot create orders with weETH as collateral due to the missing price feed.

Potential Manipulation: Using non-standard price feeds could introduce risks of price manipulation and discrepancies.

Tools Used

Manual Review

Recommendations

Ensure a reliable price feed is available for weETH. If Chainlink is not available, consider using a trusted alternative with similar security guarantees.

Updates

Lead Judging Commences

inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

Some in-scope tokens don't have Chainlink feeds on Arbi

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.