Hacker could cancel orders in for loop.
Contract has function cancelOrderFarFromOracle(), which allow everyone cancel last order. And user could cancel only 1 order in each call. But user could make calls in loop.
Hacker could call function cancelOrderFarFromOracle() in for loop.
Manual review
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.