Summary
100% of all REPORTED Findings have been addressed
- 8Acknowledged
- 7Risk Accepted
- 31Solved
- 46All Findings
- Critical0
- High0
- Medium3
- 2Risk A.
- 1Solved
- Low10
- 5Risk A.
- 5Solved
- Informational33
- 8Ack.
- 25Solved
Summary#
XMAQUINA team engaged Halborn to conduct a security assessment on their smart contracts beginning on September 15th 2026 and ending on September 21st, 2026. The assessment scope was limited to the smart contracts provided to Halborn. Commit hashes and additional details are available in the Scope section of this report.
The reviewed contracts form the RCM Protocol, which runs regulated primary issuance of tokenised notes against SPV interests on Base: KYC-verified investors subscribe USDC to an offering series, receive CMTAT-based notes once the underlying is acquired, and redeem them pro rata at a declared liquidity event. One escrow and one note deploy per series as a mutually pointing pair, and three fleet-wide singletons handle deployment, eligibility and disclosure. The escrow holds two liability pools, a subscription refund pool and a redemption payout pool, against a single USDC balance, and keeping those pools from drawing on each other is the design's own stated point of greatest concern. Operational roles sit under one role-admin key with the upgrader kept under the default admin, the singletons are UUPS proxies and the series pair sits behind two beacons with no timelock, and the repository carries a team-maintained register of accepted residuals and known issues that was validated in this assessment and is not re-reported here.
ASSESSMENT SUMMARY#
Halborn was provided with 5 days for this engagement and assigned 1 full-time security engineer to assess the security of the smart contracts in scope. The assigned engineer possesses deep expertise in blockchain and smart contract security, including hands-on experience with multiple blockchain protocols.
The objective of this assessment is to:
Identify potential security vulnerabilities within the smart contracts.
Verify that the smart contract functionality operates as intended.
In summary, Halborn identified several areas for improvement to reduce the likelihood and impact of security risks, which were partially addressed by the XMAQUINA team. The main recommendations were:
Require every eligibility write to carry an expiry set ahead of the current time, and require any reinstatement following a revocation to carry a fresh expiry so that a new review is visible on-chain.Reject conversion to oversubscribed mode when any recorded deposit falls below the new pro-rata floor.Bound each terminal refund to the balance not already owed to other subscribers so that the excess reserve remains covered after a swept series is cancelled
Scope#
Findings Overview#
# | Title | Severity | Score | Status |
|---|---|---|---|---|
HAL-01 | A revoked wallet can be listed again with its old expiry, leaving no on chain sign that a fresh review occurred | Medium | 5.0 | Risk Accepted09/24/2026 |
HAL-02 | An exact fill deposit below the minimum receives a zero allocation once the series is converted to oversubscribed | Medium | 5.0 | Risk Accepted09/24/2026 |
HAL-03 | Cancelling a swept series lets the first allocated depositor consume the cash reserved for other subscribers' refunds | Medium | 5.0 | Solved09/24/2026 |
HAL-04 | A holder can jump the payout order in a partially funded pool by moving notes into an earlier listed wallet | Low | 3.1 | Risk Accepted09/24/2026 |
HAL-05 | Factory role set is written once and every future series inherits it after a key rotation | Low | 2.5 | Solved09/24/2026 |
HAL-06 | Fee recipients can be set to another series' contracts, stranding the cash fee in a foreign escrow | Low | 2.5 | Risk Accepted09/24/2026 |
HAL-07 | The escrow assumes a plain six decimal settlement asset and its ledgers desynchronise under any other token behaviour | Low | 2.5 | Risk Accepted09/24/2026 |
HAL-08 | A settlement asset blacklist on the off ramp makes the sweep permanently impossible | Low | 2.5 | Risk Accepted09/24/2026 |
HAL-09 | Settlement asset that lands outside the payout pool is permanently stranded once allocation is fixed | Low | 2.5 | Solved09/24/2026 |
HAL-10 | Notes sent to the escrow's own address can never be retired and lock a matching share of the payout pool | Low | 2.5 | Solved09/24/2026 |
HAL-11 | The unclaimed notes view reports the whole book as owed on a cancelled series | Low | 2.5 | Solved09/24/2026 |
HAL-12 | A backstop freeze on the zero address halts every transfer and every claim delivery on the note | Low | 2.5 | Solved09/24/2026 |
HAL-13 | The claim path resolves the terms hash through a protocol specific engine call rather than the standard document interface the note stores | Low | 2.5 | Risk Accepted09/24/2026 |
HAL-14 | The payout pool is credited before the tokens arrive, so a short delivery records a liability the escrow cannot pay | Informational | 1.7 | Acknowledged09/24/2026 |
HAL-15 | The lens recomputes outstanding supply instead of reading the escrow's accessor for it | Informational | 1.7 | Solved09/24/2026 |
HAL-16 | Closing redemption before any burn removes the only correction window for a wrong settlement basis | Informational | 1.7 | Solved09/24/2026 |
HAL-17 | A series can name its own escrow as the off ramp, so the sweep moves nothing and notes are issued against money that never left | Informational | 1.3 | Solved09/24/2026 |
HAL-18 | The factory accepts a role set that collides the admin with an operational role, and every series creation then fails | Informational | 1.3 | Solved09/24/2026 |
HAL-19 | In kind deliveries lose the transfer tax and the exchanging holder receives fewer notes than agreed | Informational | 1.3 | Solved10/05/2026 |
HAL-20 | Fallback buffers and the heartbeat step accept a one second value, which defeats the protections the zero check exists for | Informational | 1.0 | Solved09/24/2026 |
HAL-21 | The note's decimals are not validated against the settlement asset, so a wrong value misrepresents every balance for the life of the series | Informational | 1.0 | Solved09/24/2026 |
HAL-22 | A subscription end near the maximum timestamp overflows the deadline arithmetic and disables the permissionless fallback | Informational | 1.0 | Solved09/24/2026 |
HAL-23 | Cancelling notes during settlement, rolling back and declaring again raises every remaining holder's payout rate | Informational | 1.0 | Acknowledged09/24/2026 |
HAL-24 | An eligibility entry can be written with a practically infinite expiry, contradicting the no immortal entries rule | Informational | 1.0 | Acknowledged09/24/2026 |
HAL-25 | Interface documentation for claim delivery still describes the removed lock up freeze | Informational | 0.8 | Solved09/24/2026 |
HAL-26 | Deposit, claim and redemption each signal ineligibility differently despite the interface promise | Informational | 0.8 | Solved09/24/2026 |
HAL-27 | Interface text for issuance points at a mechanism the token replaced | Informational | 0.8 | Solved09/24/2026 |
HAL-28 | The identity policy header states that the scale back gate is unbuilt when two of its three call sites are live | Informational | 0.8 | Solved09/24/2026 |
HAL-29 | Burn NatSpec still describes the frozen shortfall release removed with the lock up | Informational | 0.8 | Solved09/24/2026 |
HAL-30 | The lens header claims every read is guarded by the escrow when two note reads are not, and safety rests on call order | Informational | 0.8 | Solved09/24/2026 |
HAL-31 | The implied upper bound on the overage cap scales with the square of the hardcap and provides no sanity check | Informational | 0.6 | Solved09/24/2026 |
HAL-32 | The parameter freeze holds by the absence of setters, not by the predicate that claims to define it | Informational | 0.6 | Solved09/24/2026 |
HAL-33 | A reused library address from a previous build passes the deployment check and runs stale logic on every series | Informational | 0.6 | Acknowledged09/24/2026 |
HAL-34 | The operations role map omits the document engine as a fifth contract that grants roles | Informational | 0.6 | Solved09/24/2026 |
HAL-35 | Five mutators still succeed on a terminal series that INV-12 does not list | Informational | 0.6 | Solved09/24/2026 |
HAL-36 | Phase transition and engine change events do not record who acted | Informational | 0.6 | Acknowledged09/24/2026 |
HAL-37 | Integrator documentation misstates which parameters move after open and cites a validator that does not exist | Informational | 0.6 | Solved09/24/2026 |
HAL-38 | The specification's pointer swap principle names two examples that are frozen in code | Informational | 0.6 | Solved09/24/2026 |
HAL-39 | The compromise response table routes every recovery through a key that has no response row of its own | Informational | 0.6 | Solved09/24/2026 |
HAL-40 | The deploy checklist states that RCMNote.forcedTransfer() reverts from the admin when it succeeds | Informational | 0.6 | Solved09/24/2026 |
HAL-41 | Clawback accepts the note's own address as destination, unlike every other destination setter | Informational | 0.6 | Acknowledged09/24/2026 |
HAL-42 | An oversized settlement amount overflows the payout arithmetic and stalls every redemption until the declaration is rolled back | Informational | 0.5 | Solved09/24/2026 |
HAL-43 | A series can be created with another series' escrow as its off ramp, stranding the swept raise in the wrong custody pool | Informational | 0.5 | Solved09/24/2026 |
HAL-44 | No floor on the certified completion date lets claims open in the issuance block | Informational | 0.5 | Acknowledged09/24/2026 |
HAL-45 | The escrow and admin role collision checks run only at initialisation and a later grant reestablishes what they reject | Informational | 0.5 | Solved09/24/2026 |
HAL-46 | Duplicate wallets in one registry batch are accepted and the last row silently wins | Informational | 0.5 | Acknowledged09/24/2026 |
Disclaimer#
Halborn strongly recommends conducting a follow-up assessment of the project either within six months or immediately following any material changes to the codebase, whichever comes first. This approach is crucial for maintaining the project’s integrity and addressing potential vulnerabilities introduced by code modifications.
