Malicious lender can lend a loan with minimum auction length by front-running.
Pool auction length can be updated through setPool method by the lender.
A malicious lender can update the auction length to 1 by front-running a borrower, leading to the borrower taking a loan with minimum auction length.
Malicious lender can start an auction for the loan, the auction will end in a very short time (1 block), the loan can then be seized and borrower will lose collateral before realizing the problem.
Manual Review
Please consider to allowing borrower to specify auction length when borrows a loan.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.