computablelabs / compspec

The Computable Book
2 stars 0 forks source link

Document race conditions on large buy orders #30

Open rbharath opened 5 years ago

rbharath commented 5 years ago

It is possible for attackers to front-run large calls to Reserve.support to take advantage of large in-bound patron fees. The attackers can buy them immediately sell via Reserve.withdraw. If the boost in price is larger than spread, this attack can be profitable. Suggest that patrons either: