> For the complete documentation index, see [llms.txt](https://fx100.gitbook.io/fx100-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://fx100.gitbook.io/fx100-docs/how-the-system-works/oracle.md).

# Oracle and price risk

Where prices come from, and what happens when they fail.

FX100 has no order book, so the oracle is the single most important piece of infrastructure in the system. Every fill, every PnL calculation, and every liquidation references it.

## Sources

**Chainlink Data Streams** is the primary source. Off-chain signed quotes carrying bid and ask, rather than a single mid price. This is what allows FX100 to apply a directional spread rather than filling everything at the mid.

Chainlink Data Streams is validated against Pyth as a second source. When the two feeds diverge beyond a defined threshold, operations on the affected asset are rejected rather than filled at a suspect price.

## Freshness

Oracle prices carry a maximum age (`MAX_ORACLE_PRICE_AGE`). If the latest price is older than that, orders and liquidations are **rejected** until a fresh price arrives.

This is why an order can be cancelled with no obvious cause during a quiet period or a network disruption. It is a safety property: filling against a stale price would harm either you or the vault.

## Deviation protection

If the Chainlink and Pyth feeds diverge beyond a defined threshold, that market's oracle is treated as unreliable: opening, closing, and liquidation are rejected until the feeds realign. Existing positions are unaffected and cannot be liquidated during the pause.

This guards against a corrupted or manipulated feed moving a single source, protecting LPs from bad fills against the vault, and traders from being liquidated on a price that never existed.

## Sequencer protection

Base is an optimistic rollup with a centralised sequencer. If the sequencer goes down, the chain stops accepting transactions — including yours.

FX100 rejects operations during the sequencer's recovery window after an outage. Without this, the first prices after a restart would arrive against a backlog of stale state, and positions could be liquidated on prices that never reflected a tradeable market.

{% hint style="warning" %}
A sequencer outage means you cannot open, close, or adjust positions until it resolves. This is a property of the chain, not of FX100. Size positions with the possibility in mind.
{% endhint %}

## No automatic fallback

If the primary oracle fails, the protocol **freezes**: no fills, no liquidations. It does not silently switch to the backup.

Switching to the secondary source requires a governance action, and the switch carries a time lock to prevent oscillation between sources during a disputed period.

This is a deliberate trade-off. An automatic fallback would keep the venue running through an oracle failure, but it would also make the backup feed a target by corrupting the secondary, breaking the primary, and the system filling against users price. Freezing is the conservative choice, and it means an oracle failure looks like downtime rather than bad fills.
