defirisk.co
rubric v1.7.0

ecrecover zero-address return unchecked

Beefy Finance's assessment for RD-F-019 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

No ecrecover usage found in BeefyVaultV7, BeefyVaultV7Factory, or BeefyWrapper source inspection. BIFI token is ERC20Upgradeable (standard OZ 4.9.3) without direct ecrecover calls. LayerZero bridge adapter uses LZ signature framework, not raw ecrecover.

Sources #

  • GitHub
    BeefyVaultV7.solBeefyVaultV7.sol — no ecrecover usageretrieved 2026-05-16
  • Etherscan
    BIFI Token EtherscanBIFI token Ethereum 0xb1f1ee126e9c96231cc3d3fad7c08b4cf873b1f1 — ERC20Upgradeable, no direct ecrecoverretrieved 2026-05-16

Methodology #

Determine whether any `ecrecover` call result is used without a `!= address(0)` guard.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol beefy factor RD-F-019 score green collected_at 2026-05-16 13:10:30