Inspiration While auditing Spark Protocol's Aave V3 implementation, I studied historical DeFi exploits—Venus Protocol ($200M loss) and Cream Finance ($130M loss)—both involving oracle manipulation. This inspired me to investigate Spark's oracle security, where I discovered a critical vulnerability allowing attackers to exploit stale prices for direct fund theft. What it does Identifies a CRITICAL vulnerability (CVSS 9.8) in Spark Protocol's AaveOracle contract: Uses deprecated latestAnswer() without staleness validation Allows exploitation of outdated prices during market volatility Enables borrowing more than collateral is worth Impact: $19,469 profit per 100 ETH with 25% price drop Attack flow: Attacker detects stale oracle → market crashes 25% → oracle still shows old price → deposits 100 ETH valued at $389k instead of $311k → borrows $311k → never repays → profit $19k. How I built it Analysis: Audited 16 contracts, found vulnerable getAssetPrice() function lacking timestamp checks PoC: Built Foundry test suite with 4 passing tests proving vulnerability, impact, attack scenario, and fix Verification: Tested on mainnet fork with real contract addresses Documentation: Created formal security report with exploitation steps and recommended fix Challenges I ran into Compiler errors: Stack too deep in large codebase—solved by isolating test environment RPC limits: Rate-limited during testing—optimized calls and documented successful runs Impact quantification: Required modeling real market conditions and historical oracle data Complex dependencies: Traced through multiple layers of contract inheritance

Built With

  • api
  • apis
  • audit
  • cast
  • chainlink
  • contracts
  • eth/usd:
  • ethereum
  • etherscan
  • fork
  • forking
  • hardhat
  • javascript
  • mainnet
  • markdown
  • openzeppelin
  • oracles
  • rpc
  • solidity
  • testing
Share this project:

Updates

Submission history