Oracles: how blockchains learn prices, and why it matters

Blockchains can't see the outside world. Learn how price oracles like Chainlink bring market prices on chain, how they can fail, and how to check them yourself.

9 min read

A slender terrazzo tower with a glowing orange sphere at its top, lighting coins below
On this page
  1. Key takeaways
  2. The oracle problem
  3. How a decentralized price feed works
  4. Why a single market's price is dangerous
  5. How lending and trading apps use price feeds
  6. On-chain prices are open to everyone
  7. Other designs: Pyth and Uniswap TWAP
  8. Frequently asked questions
  9. Sources

A smart contract can hold millions of dollars and follow its rules perfectly, yet it has no idea what a bitcoin is worth. A blockchain can only see data that is already on it. An oracle is the bridge: a service that brings outside information, most often prices, on chain.

This guide explains why that bridge is needed, how decentralized price feeds such as Chainlink's work, what goes wrong when an app trusts a single market, and how you can check on-chain prices yourself.

Key takeaways

  • Blockchains cannot fetch outside data by themselves. Oracles write it on chain as ordinary transactions.
  • Chainlink's price feeds combine many independent node operators, each drawing on several data sources, and publish a median that updates after a set price move or a set time.
  • Trusting the spot price of one exchange or pool is dangerous: a flash-loan attack on the lending app bZx in 2020 netted about $635,000 in a single transaction.
  • Lending and trading apps use oracle prices to value collateral and trigger liquidations, and careful ones add their own safety checks.
  • Prices on public chains are transparent: anyone can read the latest value, when it was set and its history.

The oracle problem

Every node in a blockchain network re-runs each transaction and must reach exactly the same result. That is how thousands of strangers agree on balances without trusting one another. If a contract could call a website, two nodes might get different answers, or the same node a different answer a minute later, and agreement would collapse.

So blockchains reach consensus using only data stored on the chain itself. Outside data has to be written there by someone, as a transaction, and that someone is an oracle. The oracle problem is the catch: a contract is only as trustworthy as the data it acts on, and relying on one data provider brings back the very trust that blockchains were meant to remove.

How a decentralized price feed works

Chainlink Data Feeds are designed so that no single party decides the price. Chainlink describes three layers of aggregation. Data aggregators first combine raw prices from many exchanges, weighting them by volume and filtering out outliers. Each node operator then pulls from several of these aggregators and takes the median. Finally, the network combines the answers of many independent node operators and takes the median again.

Several slender pillars of different materials feeding light into one central plinth
Many independent sources, one aggregated answer

The nodes do the heavy lifting off-chain, with a protocol called Offchain Reporting (OCR). They exchange signed observations over a peer-to-peer network, and a leader node gathers them into a report. Once a quorum of nodes has signed the report, one transaction delivers it on chain, where the aggregator contract checks the signatures and stores the median with a timestamp and a round number.

Steps: Nodes collect prices → They share observations → A quorum signs one report → One node submits it → The contract stores the answer → Apps read the latest value1Nodescollectpricesfromseveraldataaggregators2Theyshareobservationsoff-chain,peer topeer3A quorumsigns onereportcontainingthe median4One nodesubmits itin a singletransaction5Thecontractstores theanswerwith atimestampand roundID6Appsread thelatestvaluethrough aproxycontractSteps: Nodes collect prices → They share observations → A quorum signs one report → One node submits it → The contract stores the answer → Apps read the latest value1Nodes collect pricesfrom several data aggregators2They share observationsoff-chain, peer to peer3A quorum signs one reportcontaining the median4One node submits itin a single transaction5The contract stores the answerwith a timestamp and round ID6Apps read the latest valuethrough a proxy contract
  1. Nodes collect prices (from several data aggregators)
  2. They share observations (off-chain, peer to peer)
  3. A quorum signs one report (containing the median)
  4. One node submits it (in a single transaction)
  5. The contract stores the answer (with a timestamp and round ID)
  6. Apps read the latest value (through a proxy contract)

Writing every tiny price move on chain would waste fees, so a feed updates when one of two triggers fires. The deviation threshold starts a new round when the off-chain price moves more than a set percentage away from the on-chain value. The heartbeat starts one when a set time has passed since the last update, even if the price has barely moved.

Key figures31oracle nodes behindETH/USD on Ethereum0.5%price move that triggers anupdate1 hourlongest gap betweenupdatesKey figures31oracle nodes behind ETH/USD on Ethereum0.5%price move that triggers an update1 hourlongest gap between updates
  • 31: oracle nodes behind ETH/USD on Ethereum
  • 0.5%: price move that triggers an update
  • 1 hour: longest gap between updates
Feed on EthereumDeviation thresholdHeartbeat
ETH/USD0.5%1 hour
BTC/USD0.5%1 hour
USDC/USD0.25%23 hours
USDT/USD0.25%24 hours
TAO/USD2%24 hours

These are the settings Chainlink lists as of September 29, 2026. A calm stablecoin feed may update once a day, while ETH/USD can update many times an hour when markets swing.

Why a single market's price is dangerous

The simplest way to get a price on chain is to read it from one place: one exchange or one pool on a decentralized exchange (DEX). But a price is only as sturdy as the amount of money needed to move it, and on a thin market that can be surprisingly little.

Flash loans make it worse. A flash loan must be borrowed and repaid within the same transaction; if it is not repaid, the whole transaction is undone. Anyone can therefore command millions for a moment, without collateral, as long as the attack pays for itself in one go.

The bZx attack, February 2020

On February 18, 2020, an attacker used exactly this against bZx, a lending and margin-trading app on Ethereum. bZx priced the stablecoin sUSD from two small on-chain markets, a Uniswap pool and a Kyber reserve. Researchers at Imperial College London later reconstructed the steps:

Steps: Borrow 7,500 ETH → Buy sUSD in two small pools → Buy more sUSD at the market price → Pledge 1.1 million sUSD on bZx → Borrow 6,799 ETH, repay the loan1Borrow7,500 ETHflash loan, onetransaction2Buy sUSDin twosmall poolsits price therejumps3Buy moresUSD at themarket priceabout 944,000from Synthetix4Pledge 1.1million sUSDon bZxvalued at theinflated price5Borrow 6,799ETH, repaythe loankeep about2,381 ETHSteps: Borrow 7,500 ETH → Buy sUSD in two small pools → Buy more sUSD at the market price → Pledge 1.1 million sUSD on bZx → Borrow 6,799 ETH, repay the loan1Borrow 7,500 ETHflash loan, one transaction2Buy sUSD in two small poolsits price there jumps3Buy more sUSD at the market priceabout 944,000 from Synthetix4Pledge 1.1 million sUSD on bZxvalued at the inflated price5Borrow 6,799 ETH, repay the loankeep about 2,381 ETH
  1. Borrow 7,500 ETH (flash loan, one transaction)
  2. Buy sUSD in two small pools (its price there jumps)
  3. Buy more sUSD at the market price (about 944,000 from Synthetix)
  4. Pledge 1.1 million sUSD on bZx (valued at the inflated price)
  5. Borrow 6,799 ETH, repay the loan (keep about 2,381 ETH)

In those two pools, sUSD briefly cost about 2.5 times as much as elsewhere, so bZx lent far more ETH than the collateral was worth. The attacker kept 2,381.41 ETH, about $634,900 at the time, for a transaction fee of $118.79. bZx's lenders bore the loss.

Averaging is not a cure-all

Combining sources does not help if they all watch the same thin market. In October 2022, according to a complaint by the US Commodity Futures Trading Commission (CFTC), a trader on Mango Markets, a crypto trading and lending platform, bought large amounts of the MNGO token on the three exchanges that fed the platform's oracle. The oracle's MNGO price jumped more than 13-fold in 30 minutes, and he used his inflated positions as collateral to withdraw over $110 million.

Chainlink's own documentation warns that thinly traded assets can be manipulated by flash-loan-funded attacks or by a well-capitalized actor.

Warning

A price is only as strong as the money needed to move it. If an app values collateral from one exchange, one pool or a thinly traded token, a large enough trade (or a flash loan) can push that price almost anywhere for a moment.

How lending and trading apps use price feeds

On a lending app, you deposit collateral and borrow against it, and the app needs a price for every asset to know whether your loan is still safe. Aave expresses this as a health factor: your collateral's value, multiplied by a safety factor called the liquidation threshold, divided by what you owe. Below 1, others can repay part of your debt and take some of your collateral plus a bonus, which is called a liquidation. Aave V3's price oracle takes its prices from Chainlink aggregators and turns to a fallback oracle if a feed returns zero or less.

A wrong price is costly either way. Too low, and healthy borrowers get liquidated. Too high, and borrowers can walk away with more than their collateral is worth, as bZx's lenders found out.

Leveraged trading apps need prices faster than a feed's heartbeat. Many use pull-based feeds such as Chainlink Data Streams, which deliver sub-second prices as signed reports that are verified on chain in the same transaction that uses them.

Careful apps add their own checks. Chainlink recommends bounds, circuit breakers and freshness checks. The Sky protocol, formerly MakerDAO, passes prices through an Oracle Security Module that holds each new value back, by default for an hour, so there is time to react to an oracle attack.

On-chain prices are open to everyone

Because feeds live on public blockchains, every update is a transaction anyone can inspect. You can read a feed's latest answer, when it was updated and its round number, look back through earlier rounds, and see which nodes serve it. When a lending app liquidates someone, the price it used is on the record.

For example, the ETH/USD feed on Ethereum sits behind the proxy address 0x5f4eC3Df9cbd43714FE2740f5E3616155c5b8419. Calling latestRoundData on a block explorer returns the price, with eight decimals, and the time of the last update. nowcoin reads the prices it shows from Chainlink feeds on chain in the same way.

That openness has limits. You can see what the network reported and when, but not every raw input from the data providers behind it.

Other designs: Pyth and Uniswap TWAP

Chainlink's push feeds are one design among several:

Mind map: Price oraclesPush feedsChainlink Data FeedsUpdate on deviationor heartbeatPull feedsPythChainlink Data StreamsOn-chain averagesUniswap v2 TWAPUniswap v3 observationsSingle spot priceOne exchange or poolEasy to manipulatePrice oraclesMind map: Price oraclesPrice oraclesPush feedsChainlink Data FeedsUpdate on deviation or heartbeatPull feedsPythChainlink Data StreamsOn-chain averagesUniswap v2 TWAPUniswap v3 observationsSingle spot priceOne exchange or poolEasy to manipulate

Mind map: Price oracles

  • Push feeds
    • Chainlink Data Feeds
    • Update on deviation or heartbeat
  • Pull feeds
    • Pyth
    • Chainlink Data Streams
  • On-chain averages
    • Uniswap v2 TWAP
    • Uniswap v3 observations
  • Single spot price
    • One exchange or pool
    • Easy to manipulate

Pyth takes a pull approach. Its prices come from more than 120 first-party providers, including exchanges, banks, trading firms and market makers, and update every 400 milliseconds. Each price carries a confidence interval, a range that widens when providers disagree. In its standard pull model, a price reaches a blockchain only when someone needs it: anyone can submit a signed update to the Pyth contract, which verifies it, usually in the same transaction that uses the price.

Uniswap offers a different tool, the time-weighted average price, or TWAP. A Uniswap v2 pool keeps a running total of its price, measured at the start of every block and weighted by how long each price lasted; comparing that total at two moments gives the average over the period. To move a one-hour TWAP by 5%, an attacker would have to hold the pool 5% off the market for about an hour, paying arbitrageurs all along. Uniswap v3 pools can store up to 65,535 observations, while v4 has no built-in oracle.

DesignHow it worksMain trade-off
Push feedNodes post a median on deviation or heartbeatMoves smaller than the threshold don't show
Pull feedSigned prices are verified when usedThe app must fetch updates and check their age
TWAPA pool's own prices averaged over timeLags fast markets; only as safe as the pool is deep
Single spot priceOne exchange or pool, read directlyCheap to manipulate

Frequently asked questions

Why can't a smart contract just call an exchange's website?

Because every node must re-run the contract and get the same result. Web data changes by the second and can differ by location, so nodes would disagree. An oracle turns outside data into a transaction, which every node sees identically.

Whenever the price moves beyond the feed's deviation threshold or the heartbeat runs out, whichever comes first. For ETH/USD on Ethereum, that means a 0.5% move or one hour.

Can an oracle be wrong?

Yes. The markets underneath can be manipulated, nodes can fail, and feeds can be retired: Chainlink notes that a shut-down feed returns zero or no data. That is why apps add freshness checks, price bounds and fallbacks.

What is the difference between push and pull oracles?

A push oracle writes prices on chain on its own schedule, so the latest value is always there to read. A pull oracle keeps signed prices off-chain until an app or user submits one, usually in the same transaction that needs it.

Sources

For information only; not financial, legal or tax advice.

A universal wallet for your crypto.

Hold Bitcoin, Ethereum, USDT, USDC and more in one account, with prices read on chain and every fee shown before you confirm.

Create account

A universal wallet for your crypto.

nowcoin is a custodial wallet: we hold the coins that back your balance. Crypto-assets are not bank deposits and are not covered by deposit insurance. Their value can go down as well as up.

© 2026 nowcoin