Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
F-2025-0013·access-control

Missing ownership validation in reward claiming leads to accidental token loss

FixedlendingmonadveToken
TL;DR

A reward claim path did not strictly validate ownership of the veNFT being claimed against. Combined with the missing delegation surface (M-03), this created scenarios where rewards could land in the wrong account.

Severity
LOW
Impact
MEDIUM
Likelihood
MEDIUM
Method
MManual review
CAT.
Complexity
LOW
Exploitability
MEDIUM
02Section · Description

Description

A reward claim path did not strictly validate that the caller owned the veNFT being claimed against. In practice this rarely produced exploitation given the rest of the call graph, but it created a class of "accidental token loss" scenarios in which automation or integration code triggered a claim that landed in an unintended address.

03Section · Impact

Impact

Accidental loss of accrued rewards through unintended claim destinations. Low likelihood under normal flows; higher in keeper or automation patterns.

04Section · Recommendation

Recommendation

Validate ownerOf(tokenId) == msg.sender on every reward-claim path. Once the M-03 delegation surface is in place, expand the check to include authorized delegates.

Composable Security ID: NRL-6c19a5e-L06. Neverland Money: Fixed. Composable Security: Fix verified during retest.

Status
Fixed
Fix commit
816c394500f1
Fix date
2025-08-22
F-2025-0013