An asset price drops off-chain, but an oracle is not yet updated the price
An attacker can use block stuffing to further delay the update, or it's just a sudden price drop
The price drop must be more than collateralRate + mintFee - 100% , e.g. 11%
The attacker gets a flash-loan
Deposits
mint
EUROs as much as they can
Sell all the minted EUROs
Returns flash-loan
The attacker made a profit and now the protocol has bad debt
Manual review
Consider adding a delay to allow mint
only after X block after the deposit. Don't allow assets that are too volatile.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.