First Flight #21: KittyFi

First Flight #21
Beginner FriendlyDeFiFoundry
100 EXP
View results
Submission Details
Severity: medium
Valid

Lack of Data Staleness Check

Summary

The lack of data staleness from the price feed oracle potentially reduces accuracy.

Vulnerability Details

The code on line 155 of KittyVault contract consumes price data from Chainlink oracle. However, there is no check to determine whether the data retrieved from the feed is fresh or not. Stale data could cause price discrepancy on the system and can be exploited by the eager users.

Impact

Potential loss of fund due to stale data.

Tools Used

Manual review.

Recommendations

Consider adding data staleness check. Refer to this link for further information.

Updates

Lead Judging Commences

shikhar229169 Lead Judge about 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

Stale Price from Chainlink Datafeed

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.