Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
F-2025-0009·input-validation

DustLock NFT can be transferred to address 0

FixedlendingmonadveToken
TL;DR

The DustLock NFT transfer path did not reject address(0) as a recipient, allowing a user to accidentally send a veNFT to the burn address (different from the controlled-burn flow) and permanently lose access to the locked position.

Severity
LOW
Impact
MEDIUM
Likelihood
LOW
Method
MManual review
CAT.
Complexity
LOW
Exploitability
LOW
02Section · Description

Description

ERC-721 implementations typically reject transfers to address(0) (since that address represents "burned"). The DustLock implementation permitted such a transfer through a code path that did not run the same validation. A user who mistakenly used address(0) as recipient would lose access to the locked position with no recovery.

03Section · Impact

Impact

Accidental permanent loss of veNFT positions through a UX or scripting mistake. No security-critical impact directly, but a foot-gun.

04Section · Recommendation

Recommendation

Reject to == address(0) in all transfer paths. If burns are meaningful for the protocol, route them through an explicit burn function with the appropriate accounting cleanup.

Composable Security ID: NRL-6c19a5e-L02. Neverland Money: Fixed. Composable Security: Fix verified during retest.

Status
Fixed
Fix commit
816c394500f1
Fix date
2025-08-22
F-2025-0009