Security Audit Flags Critical Upgrade and Access Control Risks in Binance Staked ETH
A security audit of Binance Staked ETH (BETH), a liquid staking protocol with approximately $10.17 billion in total value locked, identified significant vulnerabilities across reentrancy, access control, and upgradeability. Auditors found that critical functions such as validator set management, emergency pause, and contract upgrades are controlled by a single Binance hot-wallet address without multi-signature or timelock protections. The proxy admin being the same as the owner address means a compromised wallet could instantly replace the smart contract implementation with malicious code, earning a severity score of 9 out of 10. Narrower reentrancy risks were also identified in the claimRewards() function and the L2 bridge finalization process, where external calls occur before state updates are completed. The audit assigned an overall composite risk score of 7, noting that the protocol's large TVL significantly amplifies the potential impact of any exploit.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in