Adversary can DOS a pool for little to no cost.
Adversary can be monitoring a pool and completely DOS it by sandwiching any attempt to borrow from the pool. Upon seeing a borrowing transaction, the malicious user can front-run it taking all of the pool's liquidity, making sure the innocent user's transaction will revert. Then, the malicious user can back-run it and repay their borrow. As everything will happen in a matter of seconds, the interest will be negligible.
Full DoS of a pool for almost no cost.
Manual review
Add a minimum interest fee, despite the length of the borrow, in order to make this attack costly and prevent it.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.