Oracle security: when a true price is the wrong price

Most of the money lost to what gets called an oracle failure was not stolen by breaking an oracle. The feed reported, correctly, a price that genuinely existed on a venue the attacker had moved, and the lending protocol liquidated against it exactly as designed. The flaw was in which market the protocol agreed to believe.

What follows is the oracle problem as a trust question, a documented incident with its mechanism, the defenses and what each costs, how aggregation and volume weighting work, pull against push delivery, and what a protocol should do when a feed goes stale.

Fiber-optic cables connect secured hardware appliances inside a data center rack.

The oracle problem is a trust question

A smart contract can verify anything on its own chain and nothing outside it. To act on a price, an exchange rate, an interest rate or a reserve balance, it has to accept a statement from outside, and the only question that matters is whose statement and under what conditions. No amount of cryptography removes that, because the issue is the truth of the input and not the integrity of its transport.

Framing it as a technology problem leads to the wrong fixes. A perfectly signed, perfectly delivered, perfectly aggregated value is still wrong if the source it came from was wrong, which is why an audit has to cover how prices are sourced, aggregated and updated and not only how a contract uses them. The oracle networks page covers the mechanics and what a blockchain oracle is the basics.

A documented incident and its mechanism

Mango Markets in 2022 lost around 117 million US dollars, and the mechanism is worth following because nothing about it was a software bug. The attacker began with about 10 million US dollars of USDC split across two accounts, then traded between them to drive up the price of the platform's own token. With the inflated token valued as collateral at the market price, the attacker borrowed a large part of the platform's other assets and drained its liquid reserves.

The pattern repeats at different scales. The bZx exploit in early 2020 took around 350,000 US dollars using a flash loan to move a price within a single transaction, which is the same attack funded with borrowed capital instead of owned capital. KiloEx lost around 7 million in April 2025. In each case the price the protocol read was the real price on the venue it chose to read, and the loss came from that venue being cheap to move.

The defenses and what each one costs

A time-weighted average price samples at intervals and averages over a window, which defeats a manipulation that lasts one block or one transaction. It costs responsiveness: in a genuine fast move the TWAP lags the market, so a lending protocol using one liquidates too late and can end up undercollateralized. And it does not help when an attacker can hold a skewed price across the whole window, which a well-capitalized attacker on a thin venue can.

A deviation threshold updates the onchain value only when the off-chain price has moved by more than a set percentage, which keeps costs down. It costs precision: between updates the onchain value is stale by up to that threshold, and a protocol has to be solvent across that band. A heartbeat forces an update after a maximum interval regardless of movement, which bounds staleness and costs gas on quiet days. Multiple independent sources and sanity checks against historical data remove the single point of failure, and cost integration work and the need to decide what to do when the sources disagree.

Aggregation across venues and volume weighting

Taking a price from one venue makes the protocol only as secure as that venue's liquidity. Aggregating across many produces a figure that costs much more to move, because an attacker now has to move the whole set and not its cheapest member.

Weighting by volume is what makes the aggregate resistant. An unweighted mean across ten venues can be dragged by one tiny venue with no volume, which is the thing an attacker looks for; weighting each venue by traded volume means the manipulation has to happen where the real depth is, and that costs real capital. Outlier removal, discarding a venue whose price sits too far from the others, closes the remaining gap. These are the same mechanics a regulated benchmark administrator applies, which is the point of contact with the crypto market data page and with the providers listed on crypto price feed providers.

Pull against push delivery

In push delivery the oracle network writes the value onchain on its own schedule, driven by the deviation threshold and the heartbeat, and the contract reads whatever is there. The value is always available and may be slightly old, and the network pays the gas.

In pull delivery the signed value sits off chain and the user's transaction carries it onchain at the moment it is needed, where the contract verifies the signature and the timestamp. The value is fresh and the user pays for delivery, and the freshness window becomes a parameter the contract has to enforce: accept a signature that is too old and the design advantage disappears. For a lending market the difference is concrete. Push means liquidations run against a value that updated on a schedule, so the protocol's solvency depends on the threshold being tight enough. Pull means a liquidator brings a current price with the liquidation, which is sharper and makes the protocol dependent on someone being willing to act. The DeFi lending page covers those markets, and Chronicle and RedStone the networks built around these models.

Circuit breakers and a feed that goes stale

Every protocol has to decide in advance what to do when the price it depends on stops arriving or arrives implausibly, because the decision taken during the incident is always the wrong one. A circuit breaker suspends the sensitive operations, usually borrowing and liquidation, when a price deviates beyond a plausible band or when the feed's last update is older than a stated limit.

The hard part is that both choices hurt. Continuing to operate on a stale or implausible price is how the losses above happened. Halting means positions cannot be liquidated while the market moves, so the protocol can emerge undercollateralized and users cannot exit, and a halt also creates a party who decides when to resume. Stating the rule in the contract, with the thresholds and the resumption condition, is better than either, because it is at least knowable in advance by anyone deciding whether to lend there. Smart contract audit covers the review that should surface whether the rule exists.

Can an oracle be manipulated if the network is honest?

Yes, and this is the point the subject turns on. An oracle network of honest, well-run, well-capitalized operators faithfully reporting what the market shows will report a manipulated price if the market it reads was manipulated. Every incident on this page worked that way: the operators did their job and the attacker moved the source. That is why the operator set, covered on Chainlink node operators in Europe, answers a different question from the one about source selection and aggregation, and a protocol needs both answered.

What should a regulated firm ask about a feed it depends on?

Six things, and none of them is about the oracle network's reputation. Which venues the price is sourced from and what the combined depth of those venues is, because that number is the cost of an attack. How the sources are weighted and whether outliers are removed. What the deviation threshold and the heartbeat are, which together bound how stale the onchain value can be. Whether delivery is push or pull, and for pull, what freshness window the contract enforces. What the protocol does when the feed stops or deviates implausibly. And who the operators are, which the Chainlink node operators in Europe page shows how to look up. A firm that can answer those six has documented the dependency; a firm that can only name the oracle brand has not.

Oracle security and Finance Loop

Finance Loop brings the oracle network operators, the protocol engineers and the risk officers who have to price this exposure into the same room, in its Digital Infrastructure & Sovereignty and Risk & Compliance tracks. Finance Loop keeps the subject on the agenda because the decision that caused the losses, which market to believe, is a risk decision dressed as a technical one.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.