Open hats-bug-reporter[bot] opened 1 week ago
DUPLICATE #9
This issue is out of scope as it has already been addressed by the auditors. We decided not to make any changes since the price oracle is only being used for the performance fee.
@deadrosesxyz
Github username: @@deadrosesxyz Twitter username: @deadrosesxyz Submission hash (on-chain): 0xcfc3b04a3854a4535f46dd36ba508f6142b80f5b8371a105020f6012ce8a0f8b Severity: medium
Description: Description\
PriceOracle
uses same stale period for all data feedsAttack Scenario\ Different Chainlink data feeds have different heartbeats. For some feeds it is 1 hour and for some it is up to 48 hours. Using the same
oracleExpirationThreshold
value of all data feeds would lead to one of the two possible scenarios:Every data feed should have its own
oracleExpirationThreshold
after which the data would be deemed stale.Attachments
Proof of Concept (PoC) File
Revised Code File (Optional)