The RAAC NFTs can be traded on secondary markets (like OpenSea) while being used as collateral in the LendingPool:
A malicious user can:
Deposit NFT as collateral
Borrow maximum amount against it
List NFT for sale on OpenSea
When buyer purchases NFT:
They receive an NFT that's locked in LendingPool
Can't withdraw it due to existing debt
NFT could be liquidated if original borrower defaults
Now let's check the impact:
Buyers lose funds purchasing encumbered NFTs
NFTs can be liquidated without buyer's knowledge
Creates reputation risk for protocol
Block secondary market transfers while NFT is collateral:
Add metadata flag for collateral status:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.