Skip to content

CYS3-03: DEX Quotes Are A Single Point Of Failure For Claim Settlement - #101

Merged
evercoinx merged 11 commits into
mainfrom
serge/CYS302
May 9, 2026
Merged

evercoinx merged 11 commits into
mainfrom
serge/CYS302

Conversation

@evercoinx

@evercoinx evercoinx commented May 6, 2026 •

Copy link
Copy Markdown
Contributor

Note

High Risk
High risk because it changes claim slashing math and swap minimum-output derivation, and introduces new upgradeable storage/initialization requirements for ClaimManager that can break live claim settlement if misconfigured.

Overview
Hardens claim settlement against manipulated or unavailable DEX quotes. ClaimManager now uses OraclePriceFeed fair value as the primary pricing anchor for cross-token slashing and amountOutMin, while requiring the DEX quoteSwap to be within a configurable priceDeviationToleranceBps (otherwise claims revert).

Adds ClaimManager V2 state (oraclePriceFeed, priceDeviationToleranceBps) with initializeV2 + admin setters, updates deployment/upgrade scripts to support upgradeToAndCall initialization, and wires initializeV2 during Deploy.s.sol.

Renames configuration and documentation throughout from CHAINLINK_PRICE_FEED/IChainlinkPriceFeed to ORACLE_PRICE_FEED/IOraclePriceFeed, updates CI/fork scripts/tests accordingly, and removes the old Chainlink interface in favor of the new oracle interface (with getUSDValue, getTokenAmount, hasPriceFeed).

Reviewed by Cursor Bugbot for commit fa0f51a. Bugbot is set up for automated code reviews on this repo. Configure here.

Comment thread src/ClaimManager.sol
Comment thread script/UpgradeClaimManager.s.sol Outdated
Comment thread src/ClaimManager.sol Outdated
Comment thread src/ClaimManager.sol
Comment thread src/ClaimManager.sol
@evercoinx
evercoinx merged commit 84ee4f3 into main May 9, 2026
5 checks passed
@evercoinx
evercoinx deleted the serge/CYS302 branch May 9, 2026 10:21

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit fa0f51a. Configure here.

Comment thread script/Deploy.s.sol
);

ClaimManager(payable(contracts.claimManagerProxy)).setPremiumManager(contracts.premiumManagerProxy);
ClaimManager(payable(contracts.claimManagerProxy)).initializeV2(external_.oraclePriceFeed, 300);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deploy script hardcodes deviation tolerance, inconsistent with upgrade

Low Severity

The initializeV2 call in Deploy.s.sol hardcodes 300 for priceDeviationToleranceBps, while UpgradeClaimManager.s.sol reads it from the PRICE_DEVIATION_TOLERANCE_BPS environment variable with a default of 300. Fresh deployments cannot override this value without modifying the script, unlike the upgrade path which is properly configurable.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit fa0f51a. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants