Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
F-2025-0010·standards-compliance

Non-compliant ERC-721 totalSupply implementation

AcknowledgedlendingmonadveToken
TL;DR

The totalSupply implementation diverged from the ERC-721 standard's expected behavior, which could mislead indexers, analytics tools, and integrators that rely on the standard contract.

Severity
LOW
Impact
LOW
Likelihood
LOW
Method
MManual review
CAT.
Complexity
LOW
Exploitability
LOW
02Section · Description

Description

The ERC-721 standard does not define totalSupply directly — it is part of the optional IERC721Enumerable extension. The DustLock implementation exposed a totalSupply function whose behavior did not match the conventional meaning (count of currently existing tokens). Indexers, analytics, and integrators that rely on the conventional meaning would misread the value.

03Section · Impact

Impact

Off-chain integrations may surface incorrect supply numbers, leading to user confusion and incorrect downstream analytics.

04Section · Recommendation

Recommendation

Either implement the full IERC721Enumerable extension to make totalSupply standards-compliant, or rename the function to make its semantics explicit (e.g., lockedSupply, activeVeNftCount).

Composable Security ID: NRL-6c19a5e-L03. Neverland Money: Acknowledged. Composable Security: Acknowledged.

F-2025-0010