defirisk.co
rubric v1.7.0

Immutable oracle address

Concrete's assessment for RD-F-180 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

[★ CRITICAL — F180 PD-017 CANDIDATE, compose-counted] GREEN. No oracle address of any kind exists in Concrete's vault contracts — neither immutable, nor admin-replaceable. The 19 Chainlink feed addresses in the data cache belong to external strategy protocols (Aave, Morpho, Silo) consumed by those protocols' own contracts. Concrete's vault bytecode (ConcreteStandardVaultImpl, AllocateModule, BaseStrategy) contains zero oracle address constants, no oracle interface imports, and no oracle function calls. There is nothing to be immutable. Source inspections of all three core contracts confirmed. Halborn V2 audit (Sep 2025) found zero oracle-related findings in the audited scope.

Sources #

Methodology #

Determine whether any collateral oracle address is marked `immutable` in protocol config with no admin-replaceable adapter wrapper, preventing the protocol from repricing when the upstream asset depegs.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol concrete factor RD-F-180 score green collected_at 2026-05-17 14:36:59