Inability to delegate claim permissions by users
Users had no way to delegate reward-claim permission to a third party (a keeper bot, a custodian, or an automation contract). All claim transactions had to come directly from the veNFT owner, limiting the protocol's composability.
Description
The reward claim path required the call to come from the veNFT owner directly. There was no delegation surface allowing the owner to authorize another address (keeper, automation contract, custodian) to claim on their behalf, which is a common requirement for institutional users and gas-efficiency keeper patterns.
Impact
Reduced composability for users who want keepers, automation, or custody arrangements. Forced manual claims by the owner address for every position.
Recommendation
Add a delegation registry that lets a veNFT owner authorize specific addresses to claim on their behalf, with revocation. Emit events on delegate/revoke for off-chain indexing.
Composable Security ID: NRL-6c19a5e-M03. Neverland Money: Fixed. Composable Security: Fix verified during retest.