seizeLoan() can be called by any user, even if they are not the lender, after an auction has ended. This can result in an unfavourable loan closing/loss-of-funds for the lender.
Just because an auction ended in insolvency, that does not mean that the loan won't be solvent in a future point in time. The loan is not seized automatically and must be called manually, meaning there would be a time gap between when the auction ends and when the loan is seized.
During this time period, the loan can become solvent again due to changes in price between the loan and collateral tokens. In this case calling seizeLoan() can result in a loss of funds for the loaner.
Potential unfavourable seize of loans for lender.
Manual Review
Add access controls to seizeLoans()
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.