Lender can front-run borrwer to increase interest rate.
When a borrower borrows a loan, the borrower can only specify poolId, debt and collateral , but cannot specify the interest rate:
This is problematic as lender can front-run and change the interest rate by calling setPool(…) function or updateInterestRate(…) function.
Borrower may get a bad loan with much higher interest rate than expected;
Manual Review
Borrower should be allowed to specify interest rate and auction length when borrowing, transaction should be revert if the pool's interest rate or aution length is not as expected.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.