Fragmetric is a decentralized liquid restaking program deployed on the Solana blockchain, enabling users to deposit SOL or supported tokens into the protocol and receive minted receipt tokens in return. Once deposited into the Fragmetric fund account, user funds are staked into various restaking vaults to generate rewards. Quantstamp was tasked with a time-boxed review of Fragmetric's third iteration of their restaking contracts. Specifically, the fund, normalization, pricing, staking, restaking, reward, and swap modules were reviewed to identify deviations from the project specification, potential vulnerabilities, and proper integrations with external protocols. All external protocols and the Solv program wrapper were considered out of scope for this review. Due to the constrained time available for this review and the large size of the codebase, the audit team was unable to perform a comprehensive audit of the codebase. Therefore, uncaught bugs or vulnerabilities may remain in the code. Fragmetric's codebase underwent substantial expansion and feature development. The protocol introduced significant new functionality, including enhanced fund configuration options (such as disabling receipt token transfers, fund operations, and token removal), pegged supported token capabilities, comprehensive restaking vault reward management with harvest thresholds and commission rates, and a 1:1 receipt token wrapping/unwrapping system. The team implemented a new token swap strategy framework with validation, expanded the reward system to include admin-created user accounts with delegation support and revenue account management, and integrated multiple new pricing sources, including Pegged Token, Solv BTC Vault, Sanctum Multi Validator Stake Pool, and Virtual Vault concepts. Performance optimizations were made through pricing value caching and account data access via offset rather than full deserialization, while new third-party integrations were added for Solv BTC Vault operations, Sanctum Multi Validator services, and Orca DEX liquidity pools. Following the review, the audit team noted that the code quality remained high, largely adhering to best practices, and no significant security vulnerabilities were identified. However, the areas of centralization require clear documentation and user awareness. Users must understand and accept these trust assumptions when interacting with the protocol. **Fix Review Update:** In the recent code updates, FRAG-1 has been fixed by enhancing the user reward pool synchronization process to mitigate potential denial-of-service risks. FRAG-2 has also been successfully fixed, with the client implementing a more secure reward account system to prevent unauthorized account creation. FRAG-3 has been acknowledged, with the client planning to transition fund manager authority to a multi-signature committee as part of their governance roadmap. Additionally, suggestions S1, S3, and S4 have been addressed and resolved, while S2 has been acknowledged with clarification on naming conventions. After the initial review and before the fix commits, the Fragmetric team added code changes that are considered out of scope and were not reviewed by the audit team. Specifically, the out-of-scope commits range from `6cdcfdc77da1819d813ca83f9f80a5a0a4cb71cc ` to `e85268f5c10077a96a9de019cc327f5bd9bc3db5 `. Following the initial review, only the fix commits listed in the finding updates were reviewed to ensure the fix corrected the issue.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | 1 | - | - | - | 1 |
Acknowledged | - | - | - | - | 0 |
Fixed | 2 | - | - | - | 2 |
| Total | 3 | 0 | 0 | 0 | 3 |
| # | File Name |
|---|---|
| 1 | Scope not recorded here: see the report |