{
  "id": 12484812,
  "title": "Security Audit Report: Reentrancy & Access Control Review: Binance staked ETH",
  "url": "https://urgent.news/2026/10/06/security-audit-report-reentrancy-access-control-review-binance-staked",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T22:34:26.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/dannydoes_2abdf9c/security-audit-report-reentrancy-access-control-review-binance-staked-eth-4ako"
  },
  "original_language": "en",
  "account": "The Binance staked ETH (BETH) liquid‑staking wrapper contract was reviewed for reentrancy and access‑control vulnerabilities. The protocol runs on Ethereum mainnet and L2 roll‑ups (Arbitrum, Optimism) and has a total value locked (TVL) of approximately $10.05 billion, representing around 5 million BETH tokens.\n\nThe audit identified several key concerns:\n\n1. **Deposit & Withdrawal Reentrancy**: The `StakingPool.deposit()` function sends a wrapped ETH token (WETH) to the caller before updating internal state. This can allow malicious ERC‑777 tokens to create a re‑entrancy loop, potentially inflating the BETH supply and diluting all holders.\n\n2. **Withdrawal Reentrancy (Pull‑Payment Pattern)**: The `StakingPool.withdraw(uint256 amount)` function updates the internal balance after emitting a withdrawal request. Without a nonReentrant guard, an attacker can re‑enter the function via a malicious fallback, draining deposits before the balance is reduced.\n\n3. **Reward Distribution Reentrancy**: The `RewardDistributor.claimRewards(address to)` function calls an external ERC‑777 token's `transfer()` before updating the last claimed block. If the external token is malicious, this can cause double‑spending and minting excess BETH.\n\n4. **Unrestricted Upgrade Proxy**: The `AdminProxy.upgradeTo(address newImplementation)` function only allows the owner role (shared with Binance Centralized Operations and a single emergency address) to upgrade the contract. Compromise of the emergency address could enable a malicious actor to replace the contract with exploitable code.\n\n5. **L2 Bridge Out Reentrancy**: The `BridgeHandler.bridgeOut(address token, uint256 amount)` function lacks access control, allowing any user to invoke it. This could lead to a cross‑chain replay attack, potentially resulting in asset loss.\n\n6. **Unrestricted Governance Calls**: The `Governance.propose(address target, bytes calldata data)` function executes any proposal without checking whether the target contract is whitelisted. A compromised governance could call arbitrary addresses, allowing state changes not intended by the developers.\n\n7. **Over‑Privileged Reward Rate Setting**: The `StakingPool.setRewardRate(uint256 newRate)` function is accessible only to the default admin role, which is granted to both the BCO multi‑sig and a “reward‑oracle” address. If the oracle is compromised, the reward rate could be set to an arbitrarily high value, inflating BETH holdings.\n\nOverall, the audit gave the BETH contracts a moderate security posture (Risk Score = 5/10). While the core architecture follows best practices like checks‑effects‑interactions and OpenZeppelin’s `AccessControl`, the identified issues could be exploited under specific conditions such as compromised validator keys, malicious L2 bridges, or governance capture. The audit recommends prioritizing remediation of the high‑severity findings (P1–P2) to protect the integrity of the staking ecosystem before any further TVL growth.",
  "summary": "Security Audit Report: Reentrancy & Access Control Review: Binance staked ETH Target Protocol : Binance staked ETH (TVL: $10051.5M) Security Audit Report Reentrancy & Access‑Control Review – Binance Staked ETH (BETH) Date: 6 Oct 2026 Prepared by: [Your Name] – Senior DeFi Security Researcher & Smart‑Contract Auditor 1. Executive Summary Item Detail Protocol Binance Staked ETH (BETH) – a…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "Security Audit Report: Reentrancy & Access Control Review: Portal",
        "url": "https://urgent.news/2026/10/06/security-audit-report-reentrancy-access-control-review-portal",
        "published": "2026-10-06T23:37:12.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}