This audit was performed by Carlos (Bloqarl) as an external contractor at Composable Security, prior to or alongside founding Zealynx Security. It is not a Zealynx engagement, but is included here as part of Carlos’s professional security record.
Neverland Money Smart Contract Audit
Smart contract security audit of Neverland Money — a Monad-based lending protocol that combines an AAVE V3 fork with proprietary veDUST vote-escrowed tokenomics, custom emissions, revenue distribution, and self-repaying loan logic. The two-week review (with one-week retest) was performed by Carlos (Bloqarl) and 0xluk3 as contractors under Composable Security. The audit scope excluded the unmodified AAVE and Velodrome base, focusing on Neverland's custom-developed emissions, libraries, rewards, and token contracts. Fifteen vulnerabilities were identified: one Critical (early withdrawal penalty fee mechanism bypass), three High (invalid update of voting power; integer division truncation in reward calculation; permanent reward loss for burnt veNFTs), three Medium (self-repaying loan reward receiver persists across veNFT transfers; missing permanent lock validation in split function; inability to delegate claim permissions), and eight Low. Eleven additional best-practice recommendations were delivered. All Critical, High, and Medium issues were fixed; seven Low were fixed, one Low acknowledged.
Scope
9 filesFindings
click any row for the full write-upKey Findings
- Early withdrawal penalty fee mechanism bypass (Critical, fixed). A logic flaw allowed users to bypass the early-withdrawal penalty mechanism that was supposed to disincentivize unlocking veNFTs before their lock period ended.
- Invalid update of voting power (High, fixed). The
biasvariable and the adjustments toslopeChangesdid not correctly track the total voting power, leading to inaccurate governance and reward weights. - Integer division truncation in reward calculation (High, fixed). A division-before-multiplication pattern in the reward computation produced systematic precision loss that compounded over time, distributing rewards unfairly toward large holders.
- Permanent reward loss for burnt veNFTs (High, fixed). Rewards accrued to veNFTs that were later burned could not be recovered, causing user funds and treasury revenue to be permanently locked.
- Three Medium findings: self-repaying loan reward receiver persists across veNFT transfers (a new owner could end up paying off the previous owner's loan); missing permanent lock validation in the split function (split mechanics could be used to break invariants on permanently locked veNFTs); inability to delegate claim permissions by users.
- Eight Low findings covered single-step ownership transfers in
setTeamand upgradeable contracts, transferability of the DustLock NFT to address 0, non-compliant ERC-721totalSupply(acknowledged), missing minimum transaction validation enabling dust-attack network congestion, missing ownership validation in reward claiming, precision loss in voting power calculation, and an inability to collect any rewards in certain configurations. - Eleven Informational recommendations were delivered alongside the findings: do not use
assert, upgrade Solidity version, validate voting state before splits/merges, use named constants, consistent error message formatting, zero-address validation, redundant decimals, zero-address rewards receiver validation, fix value emitted in event, require minimum lock amount, and naming convention fixes. Nine were implemented, two acknowledged.
All Critical, High, and Medium severity findings were fixed by the Neverland team. Seven of the eight Low findings were fixed; one (non-compliant ERC-721 totalSupply) was acknowledged. The Composable Security retest verified the fixes between August 14-22, 2025.
For full per-finding detail, see the original report PDF on Composable Security's GitHub.
Team & approval
Disclaimer
This audit is not an endorsement and does not constitute investment advice. Zealynx reviewed the codebase at the commits listed in section 02 over the engagement window. Findings are limited to issues identified within that scope and do not preclude the existence of other vulnerabilities. Subsequent code changes are not covered by this report unless the engagement is explicitly extended.