Skip to content
Tech Interview Prep home
Technical interview guide

Oracles & Cross-Chain Interoperability

How smart contracts get real-world data they can't natively access, and how assets and messages move between otherwise-isolated chains.

Read
50 min
Practice MCQs
25
Interview QA
25
Edition
v5
Editorial status
Reviewed

Scope: Chainlink Data Feeds, Sequencer Uptime Feeds, VRF v2.5 and CCIP documentation; Uniswap v2 oracle design; IBC core and ICS-23 specifications; EIP-3668 reviewed 2026-09-07.

Overview

Curated: · Written: · Reviewed:

External truth and cross-chain state require explicit verification

Smart contracts cannot natively know an asset's market price, a weather outcome or another chain's state. An oracle imports a claim; a bridge imports a state transition or message. Neither is merely plumbing. Each creates a new security boundary whose data sources, observation rules, signers, proofs, finality, upgrades and failure behavior can directly control funds.

A price feed is identified by chain, contract, base, quote and units. Consumers must validate the feed address, decimals, positive range, timestamp, round completeness and application-specific freshness. A returned number can be perfectly encoded yet refer to the wrong market or stale conditions. Normalize units once through a reviewed adapter and reject ambiguity.

Freshness is not simply “updated this block.” Feeds may update on a heartbeat or when deviation crosses a threshold. Choose a maximum age from the application's liquidation latency, volatility, market hours and value at risk. During an L2 sequencer outage, an L2 price can appear current while users cannot transact normally; uptime state and a recovery grace period prevent unfair liquidations immediately after restart.

Decentralization must be traced through the data pipeline. Many reporting nodes may consume overlapping exchanges, common infrastructure or the same thin market. Median aggregation resists outliers below a threshold but not correlated bad inputs. Multiple oracle products are not independent merely because their contract addresses differ.

Onchain AMM prices are endogenous and atomically manipulable. A time-weighted average raises the cost of distortion by averaging cumulative prices across a window, but trades responsiveness for resistance. Security depends on pool depth, window, observation cadence, asset behavior and value extractable by the consumer. A spot read from a shallow pool is not a safe general-purpose oracle.

Fallbacks are alternative trust models, not automatic safety. Switching from a stale primary feed to a manipulable spot price can turn a recoverable outage into insolvency. Define bounded deviation, quorum, pause and manual recovery states; test disagreement and total failure. Conservative behavior may limit new borrowing while still allowing repayment rather than globally freezing all users.

Verifiable randomness separates request from later fulfillment. The consumer should bind request identifiers and purpose, tolerate delay, prevent replay and avoid allowing users to re-request only after seeing an unfavorable result. Proof verification establishes that the randomness follows the protocol; application fairness still depends on correct mapping, confirmation depth and state handling.

Cross-chain communication is asynchronous. Source finality, proof or validator acceptance, destination execution and application acknowledgement occur at different times. Messages need domain-separated identity including source chain, source sender, destination, payload and sequence. Destination handlers authenticate the protocol endpoint and original sender, record replay protection before effects and remain idempotent across retries.

Light-client bridges verify source consensus and commitment proofs on the destination, inheriting client correctness, update liveness and source security. Multisignature or committee bridges instead trust a threshold of signers. Optimistic bridges add a challenge window and watcher assumption. Liquidity networks add providers and repayment paths. Describe the actual verification path rather than saying a bridge is simply decentralized.

IBC-style protocols make lifecycle explicit: authenticated clients establish connections; channels bind applications; packet commitments prove sends; acknowledgements prove results; and timeouts let senders recover when delivery does not complete. Ordered channels enforce sequence while unordered channels accept each sequence once. Relayers transport proofs but should not be trusted to forge them; they can still censor or delay.

Finality mismatch is central. A destination that acts on a source block before adequate finality may need to reverse an irreversible action after a reorganization. Confirmation policies must reflect source consensus, transaction value and downstream reversibility. A faster message is usually purchasing additional risk, insurance or liquidity—not abolishing finality.

Token bridges must conserve claims across lock-and-mint or burn-and-mint paths. Identify the canonical asset, representation, escrow and upgrade authority. Rate limits and per-chain caps bound blast radius but do not repair invalid verification. Fee-on-transfer, rebasing and callback tokens require balance-delta accounting and explicit support.

Cross-chain upgrades are compatibility events. Changing message encoding, verifier, chain selector or token pool on one side can strand or misinterpret in-flight messages. Version payloads, stage lanes, drain or migrate queues and test mixed-version behavior. Emergency pause should distinguish new sends, verification, execution and user recovery.

Operate the complete dependency graph: feed age and deviation, node and source diversity, sequencer uptime, request backlog, bridge commitment and execution lag, client expiry, packet sequences, failed messages, replay attempts, token conservation, rate-limit utilization and privileged changes. Reconcile independent endpoints and retain proofs and message IDs for incident reconstruction.

Chainlink CCIP (Cross-Chain Interoperability Protocol) and EIP-3668 CCIP Read share an acronym and nothing else. Chainlink CCIP is a commit-and-execute messaging and token-transfer network with lanes, risk management and destination execution. EIP-3668 is an off-chain lookup pattern: a contract reverts with a gateway URL, a client fetches bytes, and a callback verifies them. Mixing the two in an integration review is a category error—one is a bridge trust model, the other is a data-availability helper with its own callback-binding rules.

Sequencer-uptime feeds illustrate why “the number looks fresh” is not a product policy. After an L2 sequencer recovers, a feed may resume publishing while users who could not cancel or top up during the outage become instantly liquidatable. A grace period after uptime restoration is part of the oracle contract with users, not an optional dashboard nicety.

The production invariant is bounded external trust: every imported value or cross-domain effect is authenticated, fresh enough for its use, uniquely identified, replay-safe and subject to a documented failure mode that limits loss and preserves recovery.

Worked example: pricing an oracle manipulation

A lending protocol takes a spot price from a single DEX pool. Say the pool is a constant-product pair holding $2,000,000 in total: 10,000 tokens at $100 against $1,000,000 of quote, so k = 1e10. An attacker borrows against an inflated collateral mark:

  t+0   Flash loan $350,000 of quote.
  t+0   Swap $334,000 in. Constant product moves the pool to 7,495 tokens against
        $1,334,166, so the reported price becomes $178 -- a 78% move.
  t+0   Deposit collateral, borrow against the inflated mark.
  t+0   Reverse the swap, repay the flash loan.
        Cost: two 0.30% swap fees on $334,000, about $2,000, plus gas.
        Take: the over-borrowed amount, bounded only by protocol liquidity.

Work the constant product rather than guessing, because the intuition is badly wrong in both directions. It takes only $334,000 to move a $2,000,000 pool by 78% -- not millions. And an $8,000,000 swap into that pool would not move it 78%; it would take the price to roughly $8,100, an 81x move, because price scales with the square of the reserve ratio rather than linearly with the amount swapped. Pool depth is what sets the cost, and depth is public.

Every step is one transaction, so no arbitrageur intervenes and no human reacts. The defense is not to watch for manipulation; it is to make manipulation cost more than it yields:

DesignCost to move the mark 25%Attacker's window
Spot, single $2M pool~$2,000 in feesone transaction
30-minute TWAP, same poolthat cost re-paid every block against arbitrage, ~$300,000 over 150 blocks~30 minutes, publicly visible
Median of 5 independent sourcesmust move 3 of 5 at onceas long as the slowest source
Median of 5 + TWAP + deviation breakeras above, and >10% divergence halts the marketnone without tripping the breaker

A TWAP does not make manipulation impossible. It converts one atomic transaction into a sustained, capital-intensive, publicly visible attack — arbitrageurs pull the pool back every block, so the attacker pays the round trip again each time — which is a different economic proposition. The median across independent sources removes the single point of failure. The circuit breaker turns a successful manipulation into a halt rather than a loss.

The number that decides the design is the ratio of secured value to manipulation cost. A protocol securing $50,000,000 on a spot read from that pool is defending against a $2,000 attack: not underspecified, mispriced by four orders of magnitude. The 30-minute TWAP moves the cost to roughly $300,000 and makes the attempt public for half an hour, which is what buys a human the chance to react.