defirisk.co
rubric v1.7.0

Oracle source = spot DEX pool (no TWAP)

Convex Finance's assessment for RD-F-053 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

[★ CRITICAL] No spot DEX oracle in any Convex core contract. Source inspection of Booster.sol, CvxLocker.sol, BaseRewardPool.sol, ExtraRewardStashV3.sol, and Interfaces.sol confirms zero oracle calls (no slot0(), getReserves(), consult(), latestAnswer(), latestRoundData(), getPrice()). The cvxCRV/CRV Curve factory pool carries Curve's internal EMA oracle (TWAP-based) inside the Curve pool contract — this oracle is not consumed by any Convex contract. No spot DEX oracle manipulation vector exists in Convex's core path. Scored green: no spot DEX oracle, no TWAP oracle, no oracle of any kind in Convex's executable logic.

Sources #

Methodology #

Determine whether the primary oracle for any asset/market reads spot price from a single DEX pool without a TWAP window or secondary source.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol convex-finance factor RD-F-053 score green collected_at 2026-05-16 02:41:28