Skip to main content
Chain Media

Protocols, chains and markets, reported

What Missing Oracle Protection Costs on Chainflip

Without Chainflip’s maximum oracle slippage limit, a swap has no oracle-based price bound; the cost is exposure to worse execution, not a fixed fee.

The Chain Media Editors2 min read

What Missing Oracle Protection Costs on Chainflip

On Chainflip, leaving maximum oracle slippage unset removes a price bound that can stop a swap from executing at a rate too far from the oracle price. The cost is exposure to worse execution if market conditions change before the AMM processes the swap. It is not a separate fee, and the size of any loss depends on the market and the order.

What does maximum oracle slippage protect against?

Maximum oracle slippage, also called Live Price Protection, sets the largest allowed deviation between a swap’s output and the oracle price. If the available AMM price falls outside that limit, the protocol does not execute the swap under that condition. The protection is optional and is not supported for every asset.

Chainflip processes witnessed swaps through its JIT AMM, where liquidity providers compete to fill orders. A price quoted when a swap is initiated may differ from the price available when it is processed. The oracle limit gives the swap a check against that change; it does not guarantee a particular output or eliminate ordinary trading costs. A fuller account of the swap flow and its integration details is available in this chainflip reference.

What happens when a swap has no oracle limit?

Without the limit, there is no oracle-based threshold to reject a price that has moved against the trader. The AMM can execute at the price available when it processes the swap, subject to any other protection the user set. That leaves the trader exposed to price movement and the pool’s available liquidity. The protocol does not turn that exposure into a known dollar cost in advance.

A minimum accepted price is a separate protection. It specifies the worst price the user will accept based on available liquidity. Maximum oracle slippage instead compares the output with an oracle price. A trader can use either or both, depending on whether the desired bound is tied to the executable pool price, the oracle reference, or both.

Does the oracle limit cap the full cost?

No. The limit is enforced at the AMM level and does not include network or broker fees, which are charged outside that layer. The resulting output can therefore reflect those charges as well as liquidity-provider spread. A trader setting a limit should account for that difference; a tight threshold may prevent execution even when the AMM price itself is within the chosen deviation.

If the chosen protection is not satisfied during the swap’s retry duration, the deposited assets are refunded to the specified refund address on the source chain. A refund is not costless: refund and broadcast fees may apply, and a boost fee is not refunded. The practical choice is between accepting a wider range of execution prices and risking that a tighter bound expires without a swap.

  • Use maximum oracle slippage when you want execution constrained against an oracle reference.
  • Use a minimum accepted price when you want a floor tied to the available AMM price.
  • Set the threshold with external fees and possible refund costs in mind.

For most swaps where price discipline matters more than guaranteed execution, setting a suitable bound is the clearer choice. Leaving it unset removes that specific check; it does not mean the swap pays an extra fee.