Oracle Staleness Can Break DeFi Without an Oracle Hack

Central conclusion: configuration drift and stale parameters can break DeFi even when oracle networks are uncompromised. Recent incidents at Aave and Moonwell turned small pricing inaccuracies into real losses through automated liquidations and bad debt. This is not an exotic edge case. It is a systemic operational risk tied to how protocols configure, update, and monitor their price inputs.
Verified facts: on March 10, 2026, Aave’s CAPO risk-oracle misconfiguration capped the on-chain wstETH exchange rate roughly 2.85% below market, triggering about 10,938 wstETH liquidations and roughly $26–27 million in liquidation volume. Liquidators captured around 499–512 ETH in value. Aave’s post-mortem attributes the fault to desynchronized CAPO parameters after a constrained update, not an oracle-network integrity breach, and notes refunds via BuilderNet and the Aave DAO treasury for affected users (Aave governance).
Verified facts: on February 15, 2026, Moonwell executed a governance change that misconfigured a Chainlink OEV wrapper, using the cbETH/ETH ratio as a USD price. The feed reported cbETH at about $1.12 instead of roughly $2,200, allowing opportunistic liquidators to seize 1,096.317 cbETH and leaving the protocol with about $1.78 million in bad debt. The root cause was a governance parameter error, not a node compromise (Moonwell forum).
… Continue reading the full article at the original source below.



