smart-contract-vulnerabilities icon indicating copy to clipboard operation
smart-contract-vulnerabilities copied to clipboard

Add oracle price manipulation issue.

Open 0xSandyy opened this issue 1 year ago • 4 comments

Checklist

  • [x] I have searched the existing issues and pull requests for duplicates.

Type of Issue

  • [x] New vulnerability addition
  • [ ] Feature request
  • [ ] Update existing vulnerability

Description

Oracles are widely used by smart contract to retrieve off-chain data. I would like to create an issue which focuses on how oracle price manipulation can occur(mainly flash loans) and some ways / best practices to mitigate the issue.

Additional Information

This issue might include a lot of DeFi terminologies like liquidity pools, flash loans, Amms, token price, etc. I would try to make this issue as simple as possible.

0xSandyy avatar Jun 14 '24 17:06 0xSandyy

While the proposed issue on oracle price manipulation via flash loans is undoubtedly important, it may not be well-suited for the repository due to its specialized nature within the DeFi ecosystem. The primary focus of the repository is on smart contract vulnerabilities, and the suggested topic requires a deeper understanding of DeFi-specific mechanisms, which might be outside the core knowledge base of the repository's intended audience.

Maybe a separate branch to focus on DeFi specific vulns. But come to think of it, does it mean that we also create another branch if we want to focus on vulns related to RWA's, Decentralized Insurance etc...

We should just focus on general smart contract issues IMO

director-of-chaos avatar Jun 15 '24 09:06 director-of-chaos

Exactly! That's why I created another issue regarding exactly that.

0xSandyy avatar Jun 15 '24 09:06 0xSandyy

@0xSandyy, could you please check issue #27? This issue was mentioned in that.

rakesh0x7 avatar Jun 16 '24 07:06 rakesh0x7

Yeah, but 27 is an old one. Been waiting for @kadenzipfel reply on this issue.

0xSandyy avatar Jun 16 '24 17:06 0xSandyy