MEXC DeFi Yield Products Flagged for Security Gaps Across Ethereum and L2 Networks
A confidential assessment by a senior DeFi security researcher has rated MEXC's on-chain yield platform at 6 out of 10 on an overall risk scale, classifying it as medium-high risk. The platform manages over $5 billion in user capital across Ethereum Mainnet, Optimism, Arbitrum, zkSync Era, and Polygon zkEVM through products including liquidity mining, staking, and cross-chain yield portals. Auditors identified critical vulnerabilities including re-entrancy flaws in reward-claim contracts, a single-point oracle dependency, and an unaudited custom Merkle proof verifier in the bridge layer. Governance concerns were also raised, as the proxy admin key is held by a single hot wallet and the governance timelock stands at just 24 hours, below industry standards. Researchers warned that a worst-case combination of oracle manipulation and bridge proof spoofing could put up to $200 million in user funds at risk, and recommended multi-sig governance, composite oracles, and expanded smart-contract test coverage as priority fixes.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in