defirisk.co
rubric v1.7.0

Oracle source = spot DEX pool (no TWAP)

Chainlink CCIP's assessment for RD-F-053 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

[★ CRITICAL] GREEN - CCIP does not use spot DEX prices for any security-critical function. Token transfers use OCR3 Merkle-root attestation + RMN bless (not DEX-priced). FeeQuoter uses Chainlink AggregatorV3 + Keystone push feeds for fee estimation only - not DEX spot prices. No TWAP needed as no DEX oracle is in use.

Sources #

Methodology #

Determine whether the primary oracle for any asset/market reads spot price from a single DEX pool without a TWAP window or secondary source.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol chainlink-ccip factor RD-F-053 score green collected_at 2026-05-16 01:55:09