TL;DR
- An oracle delivers external facts, most often prices, to a smart contract, which consumes them as truth. Liquidations, settlements and peg defences downstream execute against the reported number, which is why feed design carries so much weight.
- An attacker can move the source (manipulation), time can move past the feed (staleness), or the feed can be dominated by the venue it serves (self-reference). Each executes through machinery doing its job on a wrong number.
- Whoever the machinery marks: positions are liquidated against the reported number, so being right about an asset's value offers no protection once the engine has acted. The spread of the damage follows the feed's blast radius: a failure in one venue's internal price hurts that venue's users, while a failure in a shared feed would reach the protocols that read it.
- Five questions: how many independent sources, what happens on disagreement, can the reported price depart from tradeable reality, how bounded is the lag, and who can change the answers. A price drawn from one source is a single point of failure, and these questions are a way to find it.
ในบล็อกเดียว
Oracle risk is a design risk that arises whenever an automated system acts on a price it cannot check for itself. An on-chain lending market relies on its oracle, and a centralised exchange's margin engine relies on an internal index the exchange computes.
What does an oracle actually do, and why is it load-bearing?
ตอบด่วน
An oracle delivers external facts, most often prices, to a smart contract, which consumes them as truth. Liquidations, settlements and peg defences downstream execute against the reported number, which is why feed design carries so much weight.
As the guide to smart contracts explains, a contract can only read state on its own chain, so every external fact arrives through an oracle. The Ethereum developer documentation frames this as the oracle problem: the data must be correct, available when needed, and produced by parties with an incentive to report honestly, and a single centralised oracle is a single point of failure on all three counts (ethereum.org, Oracles documentation). For prices, collateral values, health factors and liquidation thresholds are all computed from the feed, and the liquidation engine acts on the computation unless the protocol's code adds a separate check. A feed that says collateral halved is, to the contract, collateral that halved.
How prices reach a contract
Two mechanics matter. In the publish-subscribe pattern, an oracle network writes a value to an on-chain feed contract on a schedule or when the price moves by more than a set threshold, and any contract may read it; in the request-response pattern, a contract asks for a specific value and the oracle delivers it (ethereum.org, Oracles documentation). Chainlink's data feeds, a widely documented example of the first pattern, aggregate prices from multiple data sources through a decentralised set of node operators and update the on-chain answer when the value deviates beyond a threshold or when a heartbeat interval passes; the documentation states that feeds are not streaming data and that consumers should check the answer's timestamp (Chainlink, Data Feeds documentation). Some protocols instead read a time-weighted average price from a decentralised exchange pool, which spreads a price over a window so that a momentary spike cannot mark positions instantly, at the cost of lag (Uniswap, v3 oracle documentation).
Exchange index and mark prices: a separate object
A centralised exchange's margin engine solves a similar problem without a blockchain. In general terms, an exchange computes an index price from prices on one or more markets, which may include its own order book, derives a mark price from it, and liquidates leveraged positions against those internal numbers. Nothing is written onto a chain, and the exchange sets the formula, its inputs and their weights. Binance's October 2025 notice, for example, refers to the "price index weights" it applies to USDe, wBETH and BNSOL (Binance, 11 October 2025).
The two objects differ in ways that matter to a user. An on-chain oracle is a public contract whose sources, update rules and admin keys can be inspected on-chain and in its documentation. An exchange index is an internal calculation that users can inspect only as far as the exchange documents it, and the exchange can change it without any public on-chain record. This guide discusses both because their failure logic is similar, and it names which of the two each example concerns.
Three layers that are easy to conflate
A position that is liquidated passes through three separate layers, and a fault in one does not imply a fault in the others. The first is the price source: an on-chain oracle, or the index an exchange computes from the markets it chooses. The second is the venue's price design: how a protocol selects and checks the oracle answer it reads, or how an exchange derives a mark price from its index and applies any floors or caps. The third is the liquidation logic: the thresholds, health factors or maintenance margins, penalties and execution method that decide what happens once a value is reported. A correct price can meet liquidation parameters set too tight for an asset's liquidity, and well-specified liquidation logic still executes on a wrong price. This guide covers the first two layers; the guide to DeFi lending and liquidations covers the third. In the examples that follow, the Mango Markets record concerns a price source and the October 2025 notice concerns an exchange's index rules. The named incidents, protocols and providers illustrate mechanisms, and this guide does not use them to assess any venue, oracle provider or liquidation design overall.
The design space, on-chain or off, is a trade around one question: how hard is it for any single party, including the venue itself, to make the reported price diverge from the price the world would actually trade at?

How do feeds actually break? Manipulation, staleness, self-reference
ตอบด่วน
An attacker can move the source (manipulation), time can move past the feed (staleness), or the feed can be dominated by the venue it serves (self-reference). Each executes through machinery doing its job on a wrong number.
Manipulation
Manipulation is the adversarial mode, and its arithmetic is what makes thin markets dangerous. Where a feed reads prices a trader can move, briefly moving them is a cost, and whatever the inflated number unlocks is the payoff. A case documented in court and agency records is Mango Markets, a Solana-based venue, on 11 October 2022. According to the court's account of the trial evidence, the MNGO perpetual's oracle averaged the spot price of MNGO from three exchanges, FTX, AscendEX and Serum; the trader bought large quantities of MNGO on those three venues, which raised the oracle price and the value of his long perpetual position, and then used the position as collateral to borrow and withdraw the platform's assets (United States v. Eisenberg, S.D.N.Y. opinion and order, 23 May 2025). The CFTC's complaint alleges that the oracle price of MNGO rose more than thirteen-fold within about thirty minutes and that over 110 million dollars in digital assets was withdrawn; it states that about 67 million dollars was later returned to Mango Markets and about 47 million dollars retained (CFTC, 9 January 2023). The SEC's parallel complaint alleges a figure of approximately 116 million dollars (SEC, 20 January 2023). The two agencies count differently, so this guide uses "over 110 million dollars" and attributes it. Both complaints are allegations that no court has decided. A jury convicted the trader in April 2024; the trial court set those convictions aside on 23 May 2025, and the government has appealed (the FAQ below gives the detail).
Protocol designers describe the same arithmetic for on-chain pool prices. Uniswap's v2 documentation explains that even a price measured before any trade in a block can be moved by a bad trade at the end of the previous block, and that "if significant value settles based on the price resulting from this mechanism, an attack's profit will likely outweigh the loss"; it adds that "the ecosystem has witnessed numerous high-profile hacks where the oracle implementation is the primary attack vector" and presents its time-weighted accumulator as the response (Uniswap, v2 Oracles documentation). The Mango Markets record, as the court described it, shows the same exposure applying to an average across three exchanges when each of them is thin.
Staleness
Staleness is the passive mode. Feeds update on intervals and conditions, so in a fast market the last published price can describe a market that has already moved. Chainlink's documentation describes the two triggers, a deviation threshold and a heartbeat, and tells integrators to check the timestamp of the answer they read (Chainlink, Data Feeds documentation). A stale price can make liquidations fire late or wrongly and gives arbitrageurs a gap to trade, and time-weighted designs accept a measure of lag as the cost of spike resistance. Some lag is unavoidable, so the useful evaluation question is whether the lag is bounded, known and accounted for by the systems consuming the feed.
Self-reference
Self-reference is the structural mode. A venue that values collateral from a price its own order book dominates has built a loop: stress on the venue thins its book, a thin book prints extreme trades, extreme trades mark collateral down, positions are liquidated, and the liquidations thin the book further. The same loop can form in an on-chain protocol that reads its own pool or in an exchange whose internal index leans on its own spot market. It is a pattern that explains how a loop can form, and by itself it diagnoses no particular incident.
The 10 October 2025 episode concerns an exchange's internal index; Binance's notice describes no on-chain oracle. What the notice establishes: USDe, wBETH and BNSOL depegged on Binance between 21:36 and 22:16 UTC on 10 October 2025; Binance compensated Futures, Margin and Loan users who held those tokens as collateral and were affected in that window, paying the difference between the market price at 00:00 UTC on 11 October and the user's liquidation price, plus liquidation fees; and, as forward measures, Binance said it would add the redemption price to the price index weights for the three tokens, add a minimum price threshold to the USDe index rule and increase the frequency of risk control parameter reviews (Binance, 11 October 2025). The notice refers to "recent market volatility and platform-related issues", does not name the tokens' issuers, and gives no root cause and no liquidation total. Nothing in it attributes the depeg to any issuer or to the backing of any of the three tokens. Market-wide scale and venue-specific price lows reported in the press are outside what the notice supports, and this guide does not rely on them.
One reading of the remedies follows; it is this guide's inference, and Binance has not stated it. An index to which redemption prices were added afterwards, with a minimum price threshold added for USDe, appears to have relied on traded market prices for collateral valuation during the window. The notice does not say whether Binance's own order books dominated those traded prices, so the episode illustrates the self-reference risk without confirming it. The remedies Binance announced all concern its own index rules.
Who gets hurt when a feed breaks, and why is solvency no defence?
ตอบด่วน
Whoever the machinery marks: positions are liquidated against the reported number, so being right about an asset's value offers no protection once the engine has acted. The spread of the damage follows the feed's blast radius: a failure in one venue's internal price hurts that venue's users, while a failure in a shared feed would reach the protocols that read it.
The October 2025 case shows the mechanism at user level. Binance users holding USDe, wBETH or BNSOL as collateral who were liquidated during the forty-minute window were liquidated against Binance's internal prices for those tokens. Binance compensated them with the difference between the market price at 00:00 UTC on 11 October and their liquidation price, plus fees (Binance, 11 October 2025). The formula shows that Binance used the later market price as its reference for compensation; the notice does not say in terms that the liquidation prices were wrong. The general point is that a venue's price design is part of any position held there, in the same way as who holds the crypto and the wallet firmware in use.
Blast radius cuts both ways. A venue-local price confines the effects of an error to that venue's users: Binance recorded the October 2025 depeg as an event on its own platform, and its compensation covered its own users. Aggregating many sources is intended to make a widely shared feed harder to move, and if one were moved, the protocols reading it would be exposed together. Relying on a small number of widely used oracle networks therefore reduces some risks and concentrates others, a trade the risk overview describes for other shared infrastructure.

What should you ask of any system that believes a price?
ตอบด่วน
Five questions: how many independent sources, what happens on disagreement, can the reported price depart from tradeable reality, how bounded is the lag, and who can change the answers. A price drawn from one source is a single point of failure, and these questions are a way to find it.
The questions turn into checks a careful user can make. Protocol documentation usually states its oracle provider and methodology; the provider's documentation states sources, operators and update conditions, and for Chainlink feeds the deviation threshold and heartbeat are published per feed (Chainlink, Data Feeds documentation). The asset-level question, whether a collateral asset's real liquidity is deep enough that its price cannot be profitably traded against its own feed, can be approached with public market data, and it is the question that applied to MNGO collateral on Mango Markets. For exchange exposure, the October 2025 episode points to a specific check: whether the venue values collateral against a multi-venue index, its own spot book, an issuer redemption price or some blend, and whether floors or caps apply. Binance's notice shows those parameters can change after an event, so any answer has a date. The guide to exchange safety covers the wider venue checks.
Governance closes the loop. On-chain feeds commonly have admins, upgrade paths and parameter keys, and an exchange index has a formula that the exchange alone sets, so whoever can repoint or reconfigure the price holds real power over every position valued by it. The five questions will not make a reader an oracle engineer. They help a reader find out, before funds move, whether a system's design has already answered them. Each architecture described here answers them differently and trades one risk for another, and this guide does not recommend any oracle architecture, provider or exchange pricing method.
Frequently asked questions
Is oracle risk only a DeFi problem?
Any automated system that acts on a price it cannot verify for itself carries the risk. The October 2025 Binance episode concerned a centralised exchange's internal collateral index, and Binance's notice describes no on-chain oracle. The same question also applies to systems this guide does not cover in detail, such as tokenised assets and cross-chain systems that consume prices. The mechanism decides the risk, whatever the venue's category.
What happened in the Mango Markets court case?
The CFTC and the SEC filed civil complaints against Avraham Eisenberg in January 2023, and he was prosecuted in the US District Court for the Southern District of New York. A jury convicted him on 18 April 2024 of commodities fraud, commodities market manipulation and wire fraud (US Department of Justice, 18 April 2024). On 23 May 2025 the trial judge granted his motion under Rule 29 of the Federal Rules of Criminal Procedure: the court vacated the two commodities counts, finding that venue in that district had not been established, and entered a judgment of acquittal on the wire fraud count, finding the evidence insufficient on venue and on whether he made a false representation to Mango Markets (United States v. Eisenberg, S.D.N.Y., opinion and order, 23 May 2025). According to a joint letter recorded in the court's order of 1 August 2025, the government filed a notice of appeal on 22 July 2025; that order stays the CFTC and SEC civil actions until the criminal case concludes after the appeal (CFTC v. Eisenberg, S.D.N.Y., order of 1 August 2025). As at 24 September 2026 this guide has not located an appellate decision, and no court has ruled on the agencies' allegations. The design lesson does not depend on the outcome.
Do time-weighted average prices solve manipulation?
They make a trade-off: spikes cannot mark positions instantly, and the average lags fast markets, so protocols choose per use. Uniswap's v3 oracle lets a consuming contract construct an average over a long window, which raises the cost of moving the price, at the cost of the window's lag (Uniswap, v3 oracle documentation). A window sized for one attack model can be wrong for another, which is why the lag question belongs in the checklist.
How can a non-engineer check which price a platform uses?
Two checks need no engineering: which price a venue uses to value collateral (multi-venue index, its own order book, an issuer redemption price, floors or caps), and whether a collateral asset has real market depth relative to the positions built on it. Where a venue publishes index or mark price documentation, the first is described there, and the second is observable in public market data. As a worked example, if a venue's index for a token drew only on its own order book, a sharp sell-off on that one book would lower the collateral value of every position using the token, whatever other venues were quoting at the time.
Does using a major aggregated oracle remove oracle risk?
Aggregation is designed to raise the cost of the simplest manipulation against a single thin source, and it ties the protocol to shared infrastructure, which reduces one risk and concentrates another. The remaining risks, such as parameters, listing thin assets as collateral, governance keys and the protocol's own liquidation logic, belong to the protocol, which is why the checklist has five questions.
Sources and further reading
Primary and reference sources for this guide, checked on 23 and 24 September 2026.
- Oracles. ethereum.org developer documentation, undated (living document). https://ethereum.org/en/developers/docs/oracles/ (accessed 23 September 2026)
- Data Feeds. Chainlink documentation, undated (living document). https://docs.chain.link/data-feeds (accessed 23 September 2026)
- Oracle (Uniswap v3 concepts). Uniswap documentation, undated (living document). https://docs.uniswap.org/concepts/protocol/oracle (accessed 23 September 2026)
- Oracles (Uniswap v2 core concepts). Uniswap documentation, undated (living document). https://docs.uniswap.org/contracts/v2/concepts/core-concepts/oracles (accessed 24 September 2026)
- CFTC Charges Avraham Eisenberg with Manipulative and Deceptive Scheme to Misappropriate Over $110 Million from Mango Markets (press release on a civil complaint; allegations, not findings). US Commodity Futures Trading Commission, 9 January 2023. https://www.cftc.gov/PressRoom/PressReleases/8647-23 (accessed 24 September 2026)
- SEC Charges Avraham Eisenberg with Manipulating Mango Markets' MNGO Token (press release on a civil complaint; allegations, not findings). US Securities and Exchange Commission, 20 January 2023. https://www.sec.gov/newsroom/press-releases/2023-13 (accessed 24 September 2026)
- Man Convicted for $110M Cryptocurrency Scheme (jury verdict of 18 April 2024; the convictions were set aside by the trial court on 23 May 2025, see the next entry). US Department of Justice, Office of Public Affairs, 18 April 2024. https://www.justice.gov/archives/opa/pr/man-convicted-110m-cryptocurrency-scheme (accessed 24 September 2026)
- United States v. Eisenberg, No. 23-cr-10, Opinion and Order. US District Court for the Southern District of New York, 23 May 2025. https://nysd.uscourts.gov/sites/default/files/2025-05/23cr10%20Opinion%20and%20Order.pdf (accessed 24 September 2026)
- Commodity Futures Trading Commission v. Eisenberg, Nos. 23 Civ. 173 and 23 Civ. 503, order continuing the stay (records the government's notice of appeal of 22 July 2025). US District Court for the Southern District of New York, 1 August 2025, as published by CourtListener. https://www.courtlistener.com/opinion/10647732/commodity-futures-trading-commission-v-eisenberg/ (accessed 24 September 2026)
- Resolution of USDE, BNSOL, and WBETH Price Depeg and Risk Control Enhancements (exchange notice, title as displayed on 24 September 2026; establishes what the exchange acknowledged and offered, not root cause). Binance, 11 October 2025. https://www.binance.com/en/support/announcement/detail/0989d6c7f32545bfb019e3249eaabc3f (accessed 24 September 2026)
แบบทดสอบด่วน: มันติดไหม?
คำถามสองสามข้อเพื่อตรวจสอบพื้นฐานที่มาถึง คำตอบพร้อมคำอธิบายจะตามมา และไม่มีใครให้คะแนนคุณนอกจากผลงานในอนาคตของคุณ
คุณทำแบบทดสอบเรื่อง “Oracle Risk: How Price Feeds Break, and What Breaks With Them” เสร็จแล้ว! แชร์ความสำเร็จของคุณบนโซเชียลมีเดีย




