Security Review Flags Critical Governance Vulnerabilities in Binance Staked ETH
A senior DeFi security research team published a governance attack-surface review of Binance Staked ETH (BETH), a liquid-staking token controlling over $9 billion in assets across Ethereum and Layer 2 networks. Auditors identified eight vulnerabilities, including two rated critical: the UUPS proxy upgrade mechanism could allow a compromised multisig to deploy malicious contract logic capable of minting unlimited BETH, and a single bridge admin address could enable unauthorized token minting on Layer 2 chains without burning on Layer 1. Additional high-severity findings include a 48-hour timelock with no minimum delay for critical functions, over 70% of voting power concentrated in Binance-controlled wallets, and owner-only pause functions that could be used to freeze user assets before a malicious upgrade. Researchers also flagged a medium-severity issue allowing any address to submit governance proposals without a minimum stake requirement, creating potential denial-of-service risks. The review was based on publicly available Solidity source code, verified bytecode, published audit reports, and the protocol's governance process.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in