X402 Git

icp-multi-exchange-price-oracle

Rust/ICP multi-exchange price oracle with Binance, Coinbase and OKX HTTPS outcalls, provenance and validation safeguards.

Top level of the repository
SizeFolderInside
1.4 kBcandid/1 asset
26.8 kBsrc/1 source file
43.2 kB(root)12 docs · 5 config files
21 files · 71.3 kB · computed 2026-09-16
SizePath
25 B.gitignore
1.2 kBAGENT_EVAL.md
2.7 kBARCHITECTURE.md
503 BCHANGELOG.md
20.8 kBCargo.lock
369 BCargo.toml
399 BDEPENDENCIES.md
1.7 kBLICENSE.md
794 BLIMITATIONS.md
2.3 kBPREVIEW.md
1.3 kBQUICKSTART.md
3.6 kBREADME.md
1.6 kBSECURITY.md
624 BSUPPORT.md
1.5 kBTEST_REPORT.md
376 BVERIFICATION.md
1.4 kBcandid/market_oracle.did · binary
1.2 kBcommercial-manifest.json
254 Bdfx.json
2 kBrelease-manifest.json
26.8 kBsrc/lib.rs
computed 2026-09-16 21:19 UTC · analyzer 0.1.0

Already bought this?

View your purchases

README

ICP Multi-Exchange Price Oracle Canister

Multi-Venue Spot Market Data & Candlestick Oracle for the Internet Computer

Tests Target License


1. WHAT IS THIS?

The ICP Multi-Exchange Price Oracle Canister is a production-ready Rust smart contract for the Internet Computer (ICP). It fetches, validates, normalizes, and caches real-time and historical candlestick (OHLCV) market data from three Tier-1 exchanges (Binance, Coinbase, OKX) via deterministic HTTPS outcalls, serving queries to frontend clients with zero cycle fees.

2. WHO IS IT FOR?

  • Web3 DeFi & DEX Developers: Needing validated multi-timeframe OHLCV bars and multi-exchange spread data for interactive charting and on-chain trade logic.
  • DAO Treasuries: Requiring automated asset valuation without recurring third-party oracle subscription fees.
  • Canister Architects: Requiring a secure reference implementation for rate-limited, single-flight HTTPS outcalls with cycle reserve protection.

3. WHAT PROBLEM DOES IT SOLVE?

The official DFINITY Exchange Rate Canister (XRC) provides single spot price cross-rates but has structural limitations for interactive applications:

  1. Cycles Attached on Query: XRC requires the caller to attach cycles to every query call, making direct, unauthenticated frontend web client queries impossible.
  2. No Candlestick (OHLCV) Series: XRC returns a single spot price; it does not aggregate, normalize, or cache multi-timeframe OHLCV series required for charting.
  3. Black-Box Aggregation: XRC hides individual exchange order-book/candle provenance.
  4. Bankruptcy Risk: Naive outcall loops can rapidly exhaust a canister cycle balance during upstream network disruptions.

4. WHY PAY FOR IT INSTEAD OF BUILDING IT?

  • Free Client Queries: An in-canister RAM cache serves authenticated query calls (cached_market_data) to browser frontends at zero cycle cost to the user.
  • Full OHLCV Candlestick Parsing: Parses and normalizes native candlestick streams across M1, M5, M15, H1, H4, D1, W1 timeframes.
  • Multi-Exchange Transparency: Queries Binance, Coinbase, and OKX concurrently, returning validated series and provenance alongside explicit failure tracking for each venue.
  • 100 Billion Cycle Reserve Protection: Automatically aborts outcalls if canister reserves drop below 100B cycles (~0.1 TC), preventing canister freeze.
  • Single-Flight Coalescing: Concurrent requests for the same asset/timeframe share an in-flight promise to eliminate duplicate outcall expenses.

5. WHAT IS VERIFIED?

  • 10 / 10 Automated Rust Unit Tests Passed: OHLCV validation, duplicate timestamp rejection, negative/zero price rejection, case-insensitive asset normalization, boundary calculation, and exchange parser error handling.
  • WASM Compilation: Compiles to optimized wasm32-unknown-unknown canister binary.
  • Candid Interface: Fully verified Candid contract (candid/market_oracle.did).

6. HOW DO I RUN IT?

# 1. Run unit tests
cargo test --manifest-path Cargo.toml

# 2. Build optimized canister WASM
cargo build --manifest-path Cargo.toml --target wasm32-unknown-unknown --release

# 3. Deploy locally with dfx
dfx start --background
dfx deploy market_oracle
dfx canister call market_oracle refresh_market_data '(record { asset = "BTC"; timeframe = variant { H1 }; limit = 20 })'

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
none in 5 packages
OSV
known vulnerabilities
none in 5 packages
OSV
dependency behaviour
3 direct packages declare install scripts, filesystem access, environment variables and more · 100 more in transitive packages · 3 packages flagged for review
Socket
instruction smuggling
none found
X402 Git
what it can do
listed below
X402 Git

What this can do

Tools
none
Runs
nothing
Talks to
  • api.coinbase.com
  • data-api.binance.vision
  • github.com
  • www.okx.com
Reads
no environment variables
At install
nothing runs
Links to
  • ic0.app
  • img.shields.io
  • internetcomputer.org
Findings (22)
  • flagged for reviewblock-buffer 0.10.4 — block-buffer 0.10.4 (transitive) — flagged for review by Socket's classifier as a security risk
  • MODERATEserde 1.0.229 — serde 1.0.229 (direct) — ships compiled native code
  • MODERATEserde_json 1.0.151 — serde_json 1.0.151 (direct) — ships compiled native code
  • MODERATEserde 1.0.229 — serde 1.0.229 (direct) — install scripts run when installed
  • MODERATEserde_json 1.0.151 — serde_json 1.0.151 (direct) — install scripts run when installed
  • MODERATEblock-buffer 0.10.4 — block-buffer 0.10.4 (transitive) — has a known vulnerability GHSA-qwgh-2vcv-g2f7 GHSA-qwgh-2vcv-g2f7
  • LOWfutures 0.3.34 — futures 0.3.34 (direct) — reads environment variables
  • LOWserde 1.0.229 — serde 1.0.229 (direct) — reads environment variables
  • LOWserde_json 1.0.151 — serde_json 1.0.151 (direct) — reads environment variables
  • LOWserde 1.0.229 — serde 1.0.229 (direct) — reads or writes files
  • LOWsrc/lib.rs — Talks to api.coinbase.com
  • LOWsrc/lib.rs — Talks to data-api.binance.vision
  • LOWCargo.lock — Talks to github.com
  • LOWsrc/lib.rs — Talks to www.okx.com
  • flagged for reviewgptAnomaly — 2 transitive packages, e.g. anyhow@1.0.104, num-bigint@0.4.8
  • MODERATEhasNativeCode — 22 transitive packages, e.g. anyhow@1.0.104, ar_archive_writer@0.5.3, binrw@0.15.2
  • MODERATEinstallScripts — 22 transitive packages, e.g. anyhow@1.0.104, autocfg@1.5.1, binrw@0.15.2
  • MODERATEshellAccess — 7 transitive packages, e.g. autocfg@1.5.1, darling_core@0.20.11, libc@0.2.189
  • MODERATEnetworkAccess — 3 transitive packages, e.g. arrayvec@0.5.2, object@0.39.1, quote@1.0.47
  • LOWenvVars — 27 transitive packages, e.g. anyhow@1.0.104, ar_archive_writer@0.5.3, autocfg@1.5.1
  • LOWfilesystemAccess — 13 transitive packages, e.g. ar_archive_writer@0.5.3, autocfg@1.5.1, either@1.18.0
  • LOWurlStrings — 2 transitive packages, e.g. libc@0.2.189, unicode-width@0.2.2

Releases 1

  1. v1.0.02026-09-16

    release: v1.0.0 commercial source edition

$249updates $59

Buy — go to the order block