Vulnerability: Oracle Manipulation via Spot Price (No TWAP)
Severity: HIGH to CRITICAL
Summary
The DeXe Protocol's PriceFeed contract uses spot price from PancakeSwap V2/V3 without any Time-Weighted Average Price (TWAP) protection. This allows attackers to manipulate prices via flash loans in a single transaction.
Affected Files
- contracts/libs/price-feed/UniswapPathFinder.sol (Lines 221-222, 249-255)
- contracts/core/PriceFeed.sol
Vulnerability Details
The PriceFeed contract uses direct spot price queries:
router.getAmountsOut() for V2
quoter.quoteExactInputSingle() for V3
Without TWAP protection, these prices can be manipulated via flash loans.
Attack Vector
- Flash loan large amount from Aave/PancakeSwap
- Swap to manipulate pool reserves
- Call PriceFeed.getNormalizedPriceOutUSD()
- Protocol uses manipulated price
- Profit in same transaction
Impact
- Token purchases at 90%+ discount
- Voting power inflation 1000x+
- Reward pool draining
- Unfair liquidations
Proof of Concept
Deployed contract: 0xc7730074736c10ed0d3F928A10Ee4162DA9a7983 on BSC
Recommended Fix
- Implement TWAP with 30-minute minimum window
- Add price deviation bounds (max 5% per block)
- Consider using Chainlink oracle
- Add time delay between queries
References
- Similar exploit: Mango Markets ($100M+ loss)
- Best practice: Uniswap V3 TWAP implementation
Vulnerability: Oracle Manipulation via Spot Price (No TWAP)
Severity: HIGH to CRITICAL
Summary
The DeXe Protocol's PriceFeed contract uses spot price from PancakeSwap V2/V3 without any Time-Weighted Average Price (TWAP) protection. This allows attackers to manipulate prices via flash loans in a single transaction.
Affected Files
Vulnerability Details
The PriceFeed contract uses direct spot price queries:
router.getAmountsOut()for V2quoter.quoteExactInputSingle()for V3Without TWAP protection, these prices can be manipulated via flash loans.
Attack Vector
Impact
Proof of Concept
Deployed contract: 0xc7730074736c10ed0d3F928A10Ee4162DA9a7983 on BSC
Recommended Fix
References