Self-repaying loan reward receiver persists across veNFT transfers
The self-repaying loan logic stored the reward receiver as a fixed address rather than dynamically reading the current veNFT owner. After a transfer, the new owner's rewards paid off the previous owner's loan.
Description
Neverland's self-repaying loan feature routes a portion of a user's veNFT rewards back into their outstanding loan position. The implementation stored the reward receiver as a fixed address at the time the loan was opened, rather than dynamically resolving the current owner of the veNFT.
When the veNFT was transferred to a new owner, accrued rewards on that NFT continued to flow to the original owner's loan, paying it off using the new owner's accrued value.
Impact
A new owner unknowingly funds the previous owner's debt repayment. Trades and sales of veNFTs become unfair without an off-chain disclosure of the embedded loan obligation.
Recommendation
Resolve the reward receiver dynamically from the current ownerOf(tokenId) rather than caching the address at loan-open time. Alternatively, prevent veNFT transfers while a self-repaying loan is active.
Composable Security ID: NRL-6c19a5e-M01. Neverland Money: Fixed. Composable Security: Fix verified during retest.