icp-multi-exchange-price-oracle
Rust/ICP multi-exchange price oracle with Binance, Coinbase and OKX HTTPS outcalls, provenance and validation safeguards.
| Size | Folder | Inside |
|---|---|---|
| 1.4 kB | candid/ | 1 asset |
| 26.8 kB | src/ | 1 source file |
| 43.2 kB | (root) | 12 docs · 5 config files |
| Size | Path |
|---|---|
| 25 B | .gitignore |
| 1.2 kB | AGENT_EVAL.md |
| 2.7 kB | ARCHITECTURE.md |
| 503 B | CHANGELOG.md |
| 20.8 kB | Cargo.lock |
| 369 B | Cargo.toml |
| 399 B | DEPENDENCIES.md |
| 1.7 kB | LICENSE.md |
| 794 B | LIMITATIONS.md |
| 2.3 kB | PREVIEW.md |
| 1.3 kB | QUICKSTART.md |
| 3.6 kB | README.md |
| 1.6 kB | SECURITY.md |
| 624 B | SUPPORT.md |
| 1.5 kB | TEST_REPORT.md |
| 376 B | VERIFICATION.md |
| 1.4 kB | candid/market_oracle.did · binary |
| 1.2 kB | commercial-manifest.json |
| 254 B | dfx.json |
| 2 kB | release-manifest.json |
| 26.8 kB | src/lib.rs |
Already bought this?
View your purchasesREADME
ICP Multi-Exchange Price Oracle Canister
Multi-Venue Spot Market Data & Candlestick Oracle for the Internet Computer
1. WHAT IS THIS?
The ICP Multi-Exchange Price Oracle Canister is a production-ready Rust smart contract for the Internet Computer (ICP). It fetches, validates, normalizes, and caches real-time and historical candlestick (OHLCV) market data from three Tier-1 exchanges (Binance, Coinbase, OKX) via deterministic HTTPS outcalls, serving queries to frontend clients with zero cycle fees.
2. WHO IS IT FOR?
- Web3 DeFi & DEX Developers: Needing validated multi-timeframe OHLCV bars and multi-exchange spread data for interactive charting and on-chain trade logic.
- DAO Treasuries: Requiring automated asset valuation without recurring third-party oracle subscription fees.
- Canister Architects: Requiring a secure reference implementation for rate-limited, single-flight HTTPS outcalls with cycle reserve protection.
3. WHAT PROBLEM DOES IT SOLVE?
The official DFINITY Exchange Rate Canister (XRC) provides single spot price cross-rates but has structural limitations for interactive applications:
- Cycles Attached on Query: XRC requires the caller to attach cycles to every query call, making direct, unauthenticated frontend web client queries impossible.
- No Candlestick (OHLCV) Series: XRC returns a single spot price; it does not aggregate, normalize, or cache multi-timeframe OHLCV series required for charting.
- Black-Box Aggregation: XRC hides individual exchange order-book/candle provenance.
- Bankruptcy Risk: Naive outcall loops can rapidly exhaust a canister cycle balance during upstream network disruptions.
4. WHY PAY FOR IT INSTEAD OF BUILDING IT?
- Free Client Queries: An in-canister RAM cache serves authenticated query calls (
cached_market_data) to browser frontends at zero cycle cost to the user. - Full OHLCV Candlestick Parsing: Parses and normalizes native candlestick streams across M1, M5, M15, H1, H4, D1, W1 timeframes.
- Multi-Exchange Transparency: Queries Binance, Coinbase, and OKX concurrently, returning validated series and provenance alongside explicit failure tracking for each venue.
- 100 Billion Cycle Reserve Protection: Automatically aborts outcalls if canister reserves drop below 100B cycles (~0.1 TC), preventing canister freeze.
- Single-Flight Coalescing: Concurrent requests for the same asset/timeframe share an in-flight promise to eliminate duplicate outcall expenses.
5. WHAT IS VERIFIED?
- 10 / 10 Automated Rust Unit Tests Passed: OHLCV validation, duplicate timestamp rejection, negative/zero price rejection, case-insensitive asset normalization, boundary calculation, and exchange parser error handling.
- WASM Compilation: Compiles to optimized
wasm32-unknown-unknowncanister binary. - Candid Interface: Fully verified Candid contract (
candid/market_oracle.did).
6. HOW DO I RUN IT?
# 1. Run unit tests
cargo test --manifest-path Cargo.toml
# 2. Build optimized canister WASM
cargo build --manifest-path Cargo.toml --target wasm32-unknown-unknown --release
# 3. Deploy locally with dfx
dfx start --background
dfx deploy market_oracle
dfx canister call market_oracle refresh_market_data '(record { asset = "BTC"; timeframe = variant { H1 }; limit = 20 })'
Security scan report
Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.
- secrets
- none found
- X402 Git
- size limits
- within caps
- X402 Git
- known malware
- none in 5 packages
- OSV
- known vulnerabilities
- none in 5 packages
- OSV
- dependency behaviour
- 3 direct packages declare install scripts, filesystem access, environment variables and more · 100 more in transitive packages · 3 packages flagged for review
- Socket
- instruction smuggling
- none found
- X402 Git
- what it can do
- listed below
- X402 Git
What this can do
- Tools
- none
- Runs
- nothing
- Talks to
- api.coinbase.com
- data-api.binance.vision
- github.com
- www.okx.com
- Reads
- no environment variables
- At install
- nothing runs
- Links to
- ic0.app
- img.shields.io
- internetcomputer.org
Findings (22)
- flagged for reviewblock-buffer 0.10.4 — block-buffer 0.10.4 (transitive) — flagged for review by Socket's classifier as a security risk
- MODERATEserde 1.0.229 — serde 1.0.229 (direct) — ships compiled native code
- MODERATEserde_json 1.0.151 — serde_json 1.0.151 (direct) — ships compiled native code
- MODERATEserde 1.0.229 — serde 1.0.229 (direct) — install scripts run when installed
- MODERATEserde_json 1.0.151 — serde_json 1.0.151 (direct) — install scripts run when installed
- MODERATEblock-buffer 0.10.4 — block-buffer 0.10.4 (transitive) — has a known vulnerability GHSA-qwgh-2vcv-g2f7 GHSA-qwgh-2vcv-g2f7
- LOWfutures 0.3.34 — futures 0.3.34 (direct) — reads environment variables
- LOWserde 1.0.229 — serde 1.0.229 (direct) — reads environment variables
- LOWserde_json 1.0.151 — serde_json 1.0.151 (direct) — reads environment variables
- LOWserde 1.0.229 — serde 1.0.229 (direct) — reads or writes files
- LOWsrc/lib.rs — Talks to api.coinbase.com
- LOWsrc/lib.rs — Talks to data-api.binance.vision
- LOWCargo.lock — Talks to github.com
- LOWsrc/lib.rs — Talks to www.okx.com
- flagged for reviewgptAnomaly — 2 transitive packages, e.g. anyhow@1.0.104, num-bigint@0.4.8
- MODERATEhasNativeCode — 22 transitive packages, e.g. anyhow@1.0.104, ar_archive_writer@0.5.3, binrw@0.15.2
- MODERATEinstallScripts — 22 transitive packages, e.g. anyhow@1.0.104, autocfg@1.5.1, binrw@0.15.2
- MODERATEshellAccess — 7 transitive packages, e.g. autocfg@1.5.1, darling_core@0.20.11, libc@0.2.189
- MODERATEnetworkAccess — 3 transitive packages, e.g. arrayvec@0.5.2, object@0.39.1, quote@1.0.47
- LOWenvVars — 27 transitive packages, e.g. anyhow@1.0.104, ar_archive_writer@0.5.3, autocfg@1.5.1
- LOWfilesystemAccess — 13 transitive packages, e.g. ar_archive_writer@0.5.3, autocfg@1.5.1, either@1.18.0
- LOWurlStrings — 2 transitive packages, e.g. libc@0.2.189, unicode-width@0.2.2
Releases 1
- v1.0.02026-09-16
release: v1.0.0 commercial source edition