Chainlink aggregator min/max bound misconfig
Stake DAO's assessment for RD-F-060 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Major Chainlink blue-chip feeds used (ETH/USD, BTC/USD, USDC/USD, LINK/USD). ETH/USD (0x5f4eC3Df9cbd43714FE2740f5E3616155c5b8419) is the canonical Ethereum mainnet feed with well-established minAnswer/maxAnswer bounds. Trust Security 2025-08 audit covered misc Curve oracles and presumably reviewed feed configuration; no bound-misconfig finding flagged in profile. RPC-level minAnswer/maxAnswer not independently verified in this session. Yellow: major feeds used with audit coverage; RPC-level bounds not independently verified.
Sources #
- Audit
- Data cache Chainlink feed addresses and parameters.research/protocols/stake-dao/00-data-cache.json — ETH/USD 0x5f4eC3Df9cbd43714FE2740f5E3616155c5b8419, deviation 0.5%; BTC/USD 0xF4030086522a5bEEa4988F8cA5B36dbC97BeE88cretrieved 2026-05-16
Methodology #
Determine whether the Chainlink aggregator's `minAnswer` and `maxAnswer` circuit-breaker bounds are misconfigured (too wide or too narrow) for the asset class.
See the full factor methodology and distribution across all protocols →