The protocol relies on a single priceOracle
for NFT prices, which can be manipulated or compromised, leading to incorrect collateral valuations.
The getNFTPrice
function fetches prices from a centralized oracle without staleness checks or fallback mechanisms:
Incorrect Valuations: Attackers can manipulate NFT prices to borrow excessive funds.
Bad Debt: Protocol accumulates undercollateralized loans during market crashes.
manual review
Add staleness checks and circuit breakers:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.