defirisk.co
rubric v1.7.0

Oracle source = spot DEX pool (no TWAP)

Spiko's assessment for RD-F-053 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

[STAR CRITICAL] Not a spot DEX oracle. Spiko Oracle contract receives NAV data from CACEIS fund administrator via Spiko oracle-operator relayer. Published via publishPrice(uint48 timepoint, uint208 price) gated by restricted() modifier (ORACLE role). No DEX pool consulted. No AMM price. No flash-loan manipulation vector. Issuer-attested NAV is the most manipulation-resistant oracle design for RWA tokens.

Sources #

  • GitHub
    Oracle.sol — spiko-tech/contracts GitHubOracle.sol publishPrice(uint48 timepoint, uint208 price) — admin-only NAV publishing, no DEX or spot price sourceretrieved 2026-05-16
  • Etherscan
    Spiko UKTBL Oracle — EtherscanUKTBL Oracle contract 0x903d5990119bC799423e9C25c56518Ba7DD19474 on Ethereum — custom AggregatorV3Interface implementation, not a standard Chainlink price feed or DEX poolretrieved 2026-05-16
  • URL
    Spiko Smart Contracts — Spiko Tech Blogtech.spiko.io/posts/spiko-smart-contracts/ — 'two entities publish price data: Spiko internal oracle-operator relayer (which receives NAV calculations from CACEIS Fund Administration), and Chainlink (through their recent partnership, receiving data directly from CACEIS)'retrieved 2026-05-16

Methodology #

Determine whether the primary oracle for any asset/market reads spot price from a single DEX pool without a TWAP window or secondary source.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol spiko factor RD-F-053 score green collected_at 2026-05-15 22:52:13