Summary
there is no time lock to claim back the locked r token in `stabilitypool.sol` leading to a malicious user sweep all the raactoken from the contract
deposit
a malicious user can observe the contract stabilitypool know when there is the highest amount of raac present in the contractThe contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.