Neverland Money Smart Contract Auditvia Composable Security
Smart contract security audit of Neverland Money — a Monad-based lending protocol that combines an AAVE V3 fork with proprietary veDUST vote-escrowed tokenomics, custom emissions, revenue distribution, and self-repaying loan logic. The two-week review (with one-week retest) was performed by Carlos (Bloqarl) and 0xluk3 as contractors under Composable Security. The audit scope excluded the unmodified AAVE and Velodrome base, focusing on Neverland's custom-developed emissions, libraries, rewards, and token contracts. Fifteen vulnerabilities were identified: one Critical (early withdrawal penalty fee mechanism bypass), three High (invalid update of voting power; integer division truncation in reward calculation; permanent reward loss for burnt veNFTs), three Medium (self-repaying loan reward receiver persists across veNFT transfers; missing permanent lock validation in split function; inability to delegate claim permissions), and eight Low. Eleven additional best-practice recommendations were delivered. All Critical, High, and Medium issues were fixed; seven Low were fixed, one Low acknowledged.
1C3H3M8L0IMonadSoliditylendingmonadveToken