20,000 USDC
View results
Submission Details
Severity: low
Valid

User can DoS pool lender's withdrawals.

Summary

Adversary can DoS pool withdrawals.

Vulnerability Details

Upon a lender attempting to withdraw funds from their pool, a malicious user can front-run them and borrow all liquidity. Then the user can back-run the pool lender's transaction and repay the loan. Because of the small duration of the loan, the interest is negligible and the pool lender cannot withdraw their funds.

Impact

Pool lender cannot withdraw their funds.

Tools Used

Manual review

Recommendations

Add a minimum interest fee, despite the length of the borrow in order to make this attack costly for the attacker.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!