{
  "id": 12737072,
  "title": "Security Audit Report: Reentrancy & Access Control Review: Binance staked ETH",
  "url": "https://urgent.news/2026/10/07/security-audit-report-reentrancy-access-control-review-binance-staked",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T23:37:46.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/dannydoes_2abdf9c/security-audit-report-reentrancy-access-control-review-binance-staked-eth-1f0j"
  },
  "original_language": "en",
  "account": "The security audit report on Binance staked ETH (BETH) evaluates the contract suite deployed on both Ethereum and Layer 2 networks. The audit window was from September 1, 2026 to September 30, 2026, and it was conducted by the Senior DeFi Security Research Team.\n\nThe report highlights two main security domains: reentrancy and access control. For reentrancy, no direct vulnerabilities were found in the ERC-20 functions. However, the cross-chain callback in the RedemptionRouter contract could potentially be re-entered via the L2 bridge's receiveMessage function, posing a reentrancy risk. This vulnerability has a medium severity score of 6 out of 10.\n\nThe access control review identified several high-risk issues. First, the admin role is controlled by a single Ethereum address, the Binance hot wallet, with no multi-sig or time-lock mechanisms in place. This creates a high impact \"admin-reentrancy\" vector that could allow an attacker to drain funds from the withdrawal queue. Additionally, the upgradeability proxy lacks a delay for critical logic changes, further exacerbating the risk. These issues have severity scores of 8 out of 10. Other access control concerns include unrestricted upgradeability, emergency pause abuse, role escalation via grantRole, and overlap in L2 bridge administration, each also posing significant risks.\n\nOverall, the aggregate risk score for the audited surface is 7.5 out of 10, rounded up to 8 for reporting purposes. The most urgent remediation recommendation is to harden the withdrawal flow against reentrancy and introduce a robust multi-sig governance model with time-locked upgrades to address the admin vulnerabilities.",
  "summary": "Security Audit Report: Reentrancy & Access Control Review: Binance staked ETH Target Protocol : Binance staked ETH (TVL: $9586.9M) Security Audit Report – Reentrancy & Access‑Control Review Protocol: Binance Staked ETH (BETH) – Ethereum & L2 Deployments TVL: ≈ $9.59 B (as of 7 Oct 2026) Audit Window: 1 Sep 2026 – 30 Sep 2026 Prepared By: Senior DeFi Security Research Team – [Your Firm] 1.…",
  "key_points": [
    "No reentrancy vulnerabilities found in ERC-20 functions",
    "Cross-chain callback in RedemptionRouter contract poses medium severity reentrancy risk",
    "Admin role controlled by single Ethereum address with high impact vulnerabilities"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "Security Audit Report: Reentrancy & Access Control Review: Venus Core Pool",
        "url": "https://urgent.news/2026/10/08/security-audit-report-reentrancy-access-control-review-venus-core-pool",
        "published": "2026-10-08T02:50:44.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}