https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/1572fc1e-1730-4e4a-8ce4-276ee07f1ea4.jpg

0xRaz

Security Researcher

Contact Me

High

12

Total

Medium

7

Total

$6.08K

Total Earnings

#761 All Time

8x

Payouts

regular

1x

Top 10

regular

3x

Top 25

regular

4x

Top 50

All

Sherlock

Cantina

CodeHawks

Jul '25

Mellow Flexible Vaults

Mellow Flexible Vaults

4.44 USDC • 1 total finding • Sherlock • 0xRaz

#40

medium

Misuse of Fenwick Tree Index in DepositQueue.cancelDepositRequest()

May '25

mystic-monorepo

mystic-monorepo

196.52 USDC • 1 total finding • Cantina • 0xRaz

#17

high

Finding not yet public.

Feb '25

Core Contracts

Core Contracts

266.18 usdc • 9 total findings • CodeHawks • 0xrazb

#81

high

Wrong amount is minted to user when they deposit into the lending pool

high

Attackers can get most of RAACToken rewards by withdrawing dust amount from StabilityPool multiple times

high

RToken is Not Interest Bearing Due to Broken Liquidity Index Calculation

high

Incorrect Debt Scaling Leading to Protocol Solvency Risk

medium

Incorrect Return Values and Double Scaling in `RToken.burn` Function Leads to Denial of Service

medium

Liquidation Cannot Be Closed Even With Healthy Position Due To Strict Debt Check

medium

There is no logic checking for RAACNFT price staleness before minting it

medium

No check for sequencer uptime can lead to Zeno auctions being executed at lower prices or may result in incomplete auctions

medium

Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations

Jan '25

daao-contracts

daao-contracts

220.5 USDC • 4 total findings • Cantina • 0xRaz

#25

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

Plaza Finance

Plaza Finance

0.87 USDC • 1 total finding • Sherlock • 0xRaz

#97

medium

Auction can be DoSed through bid manipulation leading to guaranteed FAILED_POOL_SALE_LIMIT state

Dec '24

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

0.18 OP • 1 total finding • Sherlock • 0xRaz

#66

high

USDA/USDT Redemption Price Manipulation Due to User-Controlled Price Parameters

Sep '24

infinitypools

infinitypools

5,395.77 USDC • 1 total finding • Cantina • 0xRaz

#9

high

Finding not yet public.

Royco Protocol

Royco Protocol

0.16 USDC • 1 total finding • Cantina • 0xRaz

#75

high

Finding not yet public.