The Bid offer owner/maker can call the DeliveryPlace::settleAskTaker function and steal the taker's funds.
The DeliveryPlace::settleAskTaker function is used to settle a Bid offer ( sending the point tokens to the offer owner and the collateral to the taker). If called by the offer owner the point tokens are sent to the offer owner and the taker's collateral is also sent to the offer owner.
The taker will lose their collateral. This is especially beneficial for the offer owner if the collateral token has greater value then the point token.
Manual analysis
Add access control to prevent the offer owner from calling DeliveryPlace::settleAskTaker.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.