The method used in determining the price of the asset is unreliable as it could lead to a flash loan attack.
Price is gotten on-chain directly from the pool of the token. The issue here is that prices can easily be manipulated. For example, in a given block, an attacker with high liquid can decide to inflate prices which would make the price of tokens at that given block to be wrong. The attacker can then decide to exploit the protocol based on this.
Financial loss for the protocol as well as many users.
Manual Review
use TWAP to determine the prices of the underlying assets in the pool.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.