The engine declares precision constants to normalize Chainlink's 8-decimal prices to the protocol's 18-decimal math. Only ADDITIONAL_FEED_PRECISION (1e10) is actually referenced in the valuation functions (_get_usd_value, _get_token_amount_from_usd).
The specific problem is that FEED_PRECISION (1e8) is declared public(constant(...)) but is never used anywhere in the contract. Unused public constants add to the deployed bytecode and the ABI, and mislead readers/auditors into thinking the value participates in the pricing math when it does not.
Likelihood:
The dead constant is present in every deployment.
Impact:
No security impact and no fund risk. The effect is wasted bytecode, a larger interface surface, and reduced readability/maintainability — a reviewer can waste effort reasoning about a value that does nothing.
Explanation: The public constant generates an ABI getter (so it is externally visible and adds to bytecode) yet has zero internal usages. The snippet below confirms the getter exists while a source search shows the constant is referenced nowhere except its declaration:
Explanation: Remove the unused constant. If a bare feed-precision value is genuinely needed later, derive it from the feed's decimals() at the point of use rather than hard-coding an unused constant.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.