If ERC20 is used that has callback we can reenter and not pay for tokens and it increases poolBalance
If the token has beforeHook
then we can reenter and inflate poolBalance without giving funds
The lender will make loan tokens out of thin air stealing other loan tokens from other lenders and then getting the borrowers collateral
use the checks and effects pattern, transfer tokens before the update (note: only do this addToPool
)
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.