https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_2.png

Mrmatrixxx

Security Researcher

D.K.P

Contact Me

High

5

Total

Medium

14

Total

$525.00

Total Earnings

#1503 All Time

5x

Payouts

regular

3x

Top 50

All

Sherlock

Code4rena

CodeHawks

Mar '25

PinLink: RWA-Tokenized DePIN Marketplace

PinLink: RWA-Tokenized DePIN Marketplace

0.05 USDC • Sherlock • Mrmatrixxx

#91

Feb '25

Yieldoor

Yieldoor

0.09 USDC • 1 total finding • Sherlock • Mrmatrixxx

#28

medium

Incorrect Token Deduction in Withdrawal (Logical Error)

Core Contracts

Core Contracts

482.16 usdc • 23 total findings • CodeHawks • kalii

#47

high

`GaugeController` does not send funds to FeeCollector disrupting fees distribution and causing loss of funds

high

Users can borrow more assets than they have deposited as collateral

high

RToken is Not Interest Bearing Due to Broken Liquidity Index Calculation

high

Gauge rewards are not transferred to gauge when distributeRewards() is called

high

Voting Power Snapshot Missing

medium

Missing Vote Frequency Control in GaugeController

medium

veRaac Token Constraint MAX_TOTAL_SUPPLY Can Be Bypassed. Vulnerability Disrupts Protocol Functionality and Undermines Governance Quorum.

medium

There is no logic checking for RAACNFT price staleness before minting it

medium

Workingsupply would always be overwritten in boostcontroller.sol impacting reward calculations

medium

Emergency revoke in RAACReleaseOrchestrator will freeze revoked RAAC tokens in orchestrator

medium

`veRAACToken::_updateBoostState` function sets individual user voting power instead of system-wide totals

medium

Token Accounting Mismatch Between tick() and mintRewards() in RAACMinter

medium

Incorrect Period Transition Logic in Reward Distribution

medium

Delegated Boost Persists Even If veRAAC Is Withdrawn/Reduced

medium

[L-1] Inaccurate boost calculations in `veRAACToken` due to wrong input parameter

medium

Incorrect boost calculation in `BoostController#_calculateBoost()` can be exploited to gain an unfair advantage in reward distribution

medium

Missing Predecessor Check in `executeEmergencyAction()` function

low

Limited veRaac Token Supply Triggers DoS, Hampering Proper Governance Participation.

low

Emergency Timelock Bypass: No Enforced 1-Day Delay for Emergency Actions

low

Lack of enforcement of the `MAX_TOTAL_LOCKED_AMOUNT`

low

Boost Delegation Allows Invalid Recipients on BoostController

low

Incorrect Timestamp Tracking in RAACHousePrice contract

low

`emergencyUnlockEnabled` Is Never Used, Rendering “Emergency Unlock” Ineffective

Dec '24

Lambo.win

Lambo.win

5.26 USDC • 1 total finding • Code4rena • MrMatrix

#34

medium

Accumulated ETH in the LamboVEthRouter will be irretrievable

Nov '24

Concrete

Concrete

37.65 USDC • Code4rena • MrMatrix

#78