Ripe Protocol ·Base
Missing L2 sequencer uptime validation in ChainlinkPrices
Verified against real source, 3 findings total
Summary
ChainlinkPrices has no check for Base sequencer liveness anywhere in its price validation path - a known, precedented vulnerability class (multiple Arbitrum protocols were exploited by exactly this gap in 2023).
Root cause
The six checks gating price validity in _getChainlinkData never reference sequencer state. During a sequencer outage, stale pre-outage prices remain fully valid for up to 24 hours, producing incorrect liquidation eligibility on live collateral like WETH.
Verification
Independently traced through the actual ripe-protocol source, not an AI-generated summary - confirmed no sequencer feed exists anywhere in the codebase under any naming convention. Two secondary findings included in the same report, one with an explicit self-correction after re-verification (dust-balance exclusion is temporary, not permanent) and one honestly scoped down to defense-in-depth once the real governance timelock was accounted for.
Verified against real source code, not live deployed on this chain.
Receipt on GitHub