{
  "id": 12769492,
  "title": "Security Audit Report: Reentrancy & Access Control Review: Venus Core Pool",
  "url": "https://urgent.news/2026/10/08/security-audit-report-reentrancy-access-control-review-venus-core-pool",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-08T02:50:44.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/dannydoes_2abdf9c/security-audit-report-reentrancy-access-control-review-venus-core-pool-113e"
  },
  "original_language": "en",
  "account": "The Venus Core Pool is the central liquidity-pool contract suite that supports the Venus ecosystem on Ethereum and its L2 roll-ups. It accepts deposits of various ERC-20 assets, mints vTokens (interest-bearing representations), distributes accrued interest, handles withdrawals, and coordinates with the Comptroller for market entry/exit, collateral factors, and liquidation logic.\n\nThe review focused on reentrancy safety and access-control hygiene across core contracts such as VToken.sol, Comptroller.sol, InterestRateModel.sol, Timelock.sol, AdminProxy.sol, and related libraries. The codebase follows patterns introduced by Compound and has been hardened with multiple releases. However, several critical and high-severity issues were found that could allow an attacker to steal user funds, escalate privileges, or bypass timelock constraints.\n\nThe contract suite receives a Risk Score of 7/10, indicating a high level of risk. The primary risks stem from re-entrancy-prone external calls and inadequate role separation for critical governance functions.",
  "summary": "Security Audit Report: Reentrancy & Access Control Review: Venus Core Pool Target Protocol : Venus Core Pool (TVL: $1295.9M) Security Audit Report – Reentrancy & Access‑Control Review Protocol: Venus Core Pool (Ethereum & L2) – TVL ≈ $1.30 B Audit Window: 2024‑10‑01 → 2024‑10‑07 Prepared by: Senior DeFi Security Researcher – XYZ Audits Date: 2024‑10‑08 1. Executive Summary The Venus Core Pool is…",
  "key_points": [
    "Venus Core Pool contracts reviewed for security vulnerabilities",
    "Reentrancy and access control issues identified in key contracts",
    "Risk Score of 7/10 indicates high level of security risk"
  ],
  "editors_take": "The Venus Core Pool's high risk score indicates that its reentrancy and access control vulnerabilities could enable attackers to steal user funds or escalate privileges, undermining ecosystem trust.",
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "Security Audit Report: Reentrancy & Access Control Review: Binance staked ETH",
        "url": "https://urgent.news/2026/10/07/security-audit-report-reentrancy-access-control-review-binance-staked",
        "published": "2026-10-07T23:37:46.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}