Algo Ssstablecoinsss

AI First Flight #2
Beginner FriendlyDeFi
EXP
View results
Submission Details
Impact: low
Likelihood: high
Invalid

Unused FEED_PRECISION constant (dead code / code quality)

Root + Impact

Description

The engine declares precision constants to normalize Chainlink's 8-decimal prices to the protocol's 18-decimal math. Only ADDITIONAL_FEED_PRECISION (1e10) is actually referenced in the valuation functions (_get_usd_value, _get_token_amount_from_usd).

The specific problem is that FEED_PRECISION (1e8) is declared public(constant(...)) but is never used anywhere in the contract. Unused public constants add to the deployed bytecode and the ABI, and mislead readers/auditors into thinking the value participates in the pricing math when it does not.

ADDITIONAL_FEED_PRECISION: public(constant(uint256)) = 1 * (10**10)
@> FEED_PRECISION: public(constant(uint256)) = 1 * (10**8) # declared, never referenced

Risk

Likelihood:

  • The dead constant is present in every deployment.

Impact:

  • No security impact and no fund risk. The effect is wasted bytecode, a larger interface surface, and reduced readability/maintainability — a reviewer can waste effort reasoning about a value that does nothing.

Proof of Concept

Explanation: The public constant generates an ABI getter (so it is externally visible and adds to bytecode) yet has zero internal usages. The snippet below confirms the getter exists while a source search shows the constant is referenced nowhere except its declaration:

import boa
​
def test_feed_precision_is_declared_but_unused(engine):
# The public constant exists and is callable (it adds to the ABI/bytecode):
assert engine.FEED_PRECISION() == 10**8
​
# ...yet it is used nowhere in the contract logic. A source search shows only its declaration:
# grep -n "FEED_PRECISION" src/dsc_engine.vy
# -> line 27: FEED_PRECISION: public(constant(uint256)) = 1 * (10**8) # declaration only
# (ADDITIONAL_FEED_PRECISION is used on lines 315 and 362; FEED_PRECISION: 0 usages)

Recommended Mitigation

Explanation: Remove the unused constant. If a bare feed-precision value is genuinely needed later, derive it from the feed's decimals() at the point of use rather than hard-coding an unused constant.

- FEED_PRECISION: public(constant(uint256)) = 1 * (10**8)
Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge about 2 hours ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!