★ Oracle source = spot DEX pool (no TWAP)
Wormhole's assessment for RD-F-053 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Oracle source = spot DEX pool (no TWAP, no fallback) | Not applicable — no DEX spot price is used in any security-critical path. The Guardian network (multisig attestation) is the trust primitive. No DEX pool price is consumed for VAA verification, asset pricing, or fee computation in audited production contracts. | Messages.sol: no DEX oracle calls; Token Bridge whitepaper (0003_token_bridge.md); data cache oracle_feeds attribution to peripheral contracts | GREEN
Sources #
- Curator noteExtracted from 03-oracle-deps.md — RD-F-053; no URL citedretrieved 2026-04-28
Methodology #
Determine whether the primary oracle for any asset/market reads spot price from a single DEX pool without a TWAP window or secondary source.
See the full factor methodology and distribution across all protocols →