20,000 USDC
View results
Submission Details
Severity: medium
Valid

Frontrunning Attack Vulnerability

Summary

The lending may be frontrunned by the lenders.

Vulnerability Details

The setPool function call may be executed before the borrow function call (frontrunned) and the pool rules may be changed to the different ones that are expected by the borrower.

Impact

The borrower may change the interest rate and the borrower will have to pay more than was expected.

Tools Used

Manual review

Recommendations

Add the expectedInterestRate parameter to the borrow function and verify if it is the same as the current pool interestRate value.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!