Security Audit Report: Reentrancy & Access Control Review: Binance staked ETH
Security Audit Report: Reentrancy & Access Control Review: Binance staked ETH Target Protocol : Binance staked ETH (TVL: $9586.9M) Security Audit Report – Reentrancy & Access‑Control Review Protocol: Binance Staked ETH (BETH) – Ethereum & L2 Deployments TVL: ≈ $9.59 B (as of 7 Oct 2026) Audit Window: 1 Sep 2026 – 30 Sep 2026 Prepared By: Senior DeFi Security Research Team – [Your Firm] 1.…
The security audit report on Binance staked ETH (BETH) evaluates the contract suite deployed on both Ethereum and Layer 2 networks. The audit window was from September 1, 2026 to September 30, 2026, and it was conducted by the Senior DeFi Security Research Team.
The report highlights two main security domains: reentrancy and access control. For reentrancy, no direct vulnerabilities were found in the ERC-20 functions. However, the cross-chain callback in the RedemptionRouter contract could potentially be re-entered via the L2 bridge's receiveMessage function, posing a reentrancy risk. This vulnerability has a medium severity score of 6 out of 10.
The access control review identified several high-risk issues. First, the admin role is controlled by a single Ethereum address, the Binance hot wallet, with no multi-sig or time-lock mechanisms in place. This creates a high impact "admin-reentrancy" vector that could allow an attacker to drain funds from the withdrawal queue. Additionally, the upgradeability proxy lacks a delay for critical logic changes, further exacerbating the risk.
These issues have severity scores of 8 out of 10. Other access control concerns include unrestricted upgradeability, emergency pause abuse, role escalation via grantRole, and overlap in L2 bridge administration, each also posing significant risks.
Overall, the aggregate risk score for the audited surface is 7.5 out of 10, rounded up to 8 for reporting purposes. The most urgent remediation recommendation is to harden the withdrawal flow against reentrancy and introduce a robust multi-sig governance model with time-locked upgrades to address the admin vulnerabilities.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.