Home / History / DeFi Dawn / Oracle games
2019–2020

Oracle games

Data feeds become attack surfaces; flash loans weaponize price moves.

DeFi Dawn

Story beats & cast

OraclesMedianizersTWAPsFlash loans
Events
  • bZx oracle manipulations
  • Synthetix oracle glitch
  • Flash loan exploit combos
Actors
  • Sergey Nazarov — Chainlink co-founder

Oracle games

Why oracles matter

The bridge between chains and prices

DeFi protocols need external prices to decide collateral health, liquidations, swaps, and rewards. On-chain AMMs can act as “prices,” but thin liquidity makes them easy to push around. Off-chain data feeds (like Chainlink) bring depth but add dependency. Either way, the oracle is a choke point—if it lies or lags, money moves the wrong way.

Early protocols underestimated this. They used a single exchange price or a thin AMM pool as an oracle, assuming markets would stay honest. Attackers saw an opening: move the oracle, win the payout.

Latency and liquidity as risk

Block times and gas fees add latency. If an oracle updates every minute, a 30-second price swing can bankrupt positions. If a price source is shallow, a single big trade can skew it. Designing oracles means balancing freshness, cost, and manipulation resistance—trade-offs many teams learned mid-attack.

Attacks in the wild

Flash loan-fueled swings

Flash loans let anyone borrow millions for one transaction. Attackers used them to buy or sell against a thin AMM, spike the price, and trigger liquidations or mint/burn events in protocols reading that AMM as truth. Profit came from the mismatch when the price snapped back but the protocol had already acted.

TWAP and “instant oracle” pitfalls

Time-weighted average prices (TWAPs) smooth volatility, but if the window is too short, it’s still manipulable; too long, and it lags reality. Some protocols mistakenly used spot prices or short TWAPs from their own pools. Others relied on a single CEX feed, inviting downtime or “exchange maintenance” surprises.

Specific blows

bZx (2020) was hit multiple times: attackers manipulated low-liquidity pairs and oracles to drain funds. Synthetix suffered an oracle glitch in 2019 when a faulty feed posted wrong prices. Smaller projects were rugged daily via oracle gaps that let attackers mint worthless collateral or over-liquidate victims. bZx’s postmortem ↗ reads like a checklist of what not to do.

“If your oracle can be moved cheaper than your profit cap, it will be.” — Common security review warning in 2020

Defenses and design shifts

Multiple sources and aggregation

Protocols migrated to decentralized oracle networks (Chainlink, Band), using multiple exchanges and data providers. On-chain TWAPs were lengthened and combined with off-chain feeds. Medianizers and sanity checks filtered outliers. Some protocols paid for premium data to reduce stale or skewed inputs.

Buffers, delays, and circuit breakers

Liquidations and mints gained buffers: higher collateral ratios, price caps, or delayed execution through oracle security modules. If a feed moved too fast, contracts could pause or limit actions until humans or governance verified the move. These brakes traded speed for safety.

Liquidity requirements

Some designs required a minimum liquidity depth across venues before trusting a price, or weighted deeper markets more. Others introduced “guarded launches” with lower caps until oracles and liquidity matured. The goal: make manipulation more expensive than any reward.

Legacy

Oracle design became a core discipline. Audits now scrutinize price feeds and manipulation cost. Teams plan for latency, liquidity droughts, and black swan moves. The era of oracle games left one message: don’t assume price—model its failure.