
BendDAO audit
A private security review of BendDAO (NFT lending), conducted with Code4rena and completed on 19th June 2024. 0xSimao disclosed 8 findings: 4 high severity and 4 medium.
Scope
The code was audited at commit 117ef61.
Findings
High
- Mismatch between yield amount deposited in shares calculation and getAccountYieldBalance()
- Bad debt is never handled which places insolvency risks on BendDAO
- Users cannot unstake from YiedlETHStakingEtherfi.sol, because YieldAccount.sol is incompatible with ether.fi's WithdrawRequestNFT.sol
- Anyone can get the NFT collateral token after an Auction without bidding due to missing check on msg.sender
Medium
- Unhandled request invalidation by the owner of Etherfi will lead to stuck debt
- Major insolvency risk in LiquidationLogic::executeCrossLiquidateERC721() due to not setting a maximum liquidation price
- It's impossible to retrieve collected fines from the yield staking contract
- Borrower can prevent yield position repayment and closure by the bot
The report