DustLock NFT can be transferred to address 0
The DustLock NFT transfer path did not reject address(0) as a recipient, allowing a user to accidentally send a veNFT to the burn address (different from the controlled-burn flow) and permanently lose access to the locked position.
Description
ERC-721 implementations typically reject transfers to address(0) (since that address represents "burned"). The DustLock implementation permitted such a transfer through a code path that did not run the same validation. A user who mistakenly used address(0) as recipient would lose access to the locked position with no recovery.
Impact
Accidental permanent loss of veNFT positions through a UX or scripting mistake. No security-critical impact directly, but a foot-gun.
Recommendation
Reject to == address(0) in all transfer paths. If burns are meaningful for the protocol, route them through an explicit burn function with the appropriate accounting cleanup.
Composable Security ID: NRL-6c19a5e-L02. Neverland Money: Fixed. Composable Security: Fix verified during retest.