Missing ownership validation in reward claiming leads to accidental token loss
A reward claim path did not strictly validate ownership of the veNFT being claimed against. Combined with the missing delegation surface (M-03), this created scenarios where rewards could land in the wrong account.
Description
A reward claim path did not strictly validate that the caller owned the veNFT being claimed against. In practice this rarely produced exploitation given the rest of the call graph, but it created a class of "accidental token loss" scenarios in which automation or integration code triggered a claim that landed in an unintended address.
Impact
Accidental loss of accrued rewards through unintended claim destinations. Low likelihood under normal flows; higher in keeper or automation patterns.
Recommendation
Validate ownerOf(tokenId) == msg.sender on every reward-claim path. Once the M-03 delegation surface is in place, expand the check to include authorized delegates.
Composable Security ID: NRL-6c19a5e-L06. Neverland Money: Fixed. Composable Security: Fix verified during retest.