20,000 USDC
View results
Submission Details
Severity: medium
Valid

SeizeLoan function susceptible to Reentrancy

Summary

Reentrancy danger

Vulnerability Details

Malicious lender can create pool with reentrant collateral token and use seize loan function to drain the collateral token from protocol reserves. SeizeLoan function doesnt follow CEI methodology and no reentrancy guard modifier exist

Impact

Protocol suffer the loss of collateral tokens inside the protocol.Malicious lender may create multiple pool and can drain the tokens.

Tools Used

manuel-review

Recommendations

Following CIE methodology
Adding reentrancy-guard

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.