setPool
and updateInterestRate
functions in Lender.sol
contract allow the lender to change the interest rate to up to 1000% at any time without a delay, this also includes frontrunning the borrowers' transactions.
The arbitrary change of interest rates may be unexpected for borrowers and can result in an inability to repay the loan on time.
Manual Review
Consider adding a delay (for instance: 1 day) for the interest rate update to go live in both the setPool
and updateInterestRate
functions.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.