Centralized Oracles as Single Points of Failure
A perfectly written smart contract can still be exploited if it relies on a centralized or vulnerable oracle feed.
If hackers manipulate the price feed feeding data to the contract, they can trigger false liquidations or drain collateral.
Oracle health is just as critical as code audits.