Malicious lender can lend a loan with maximum interest rate by front-running.
Pool interest rate can be updated through updateInterestRate method by the lender.
A malicious lender can update the interest rate to MAX_INTEREST_RATE by front-running a borrower, leading to the borrower taking a loan with maximum interest rate.
Borrower may have to pay much more interest before realizing the problem.
Manual Review
Please consider to allowing borrower to specify interest rate when borrows a loan.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.