{"investigation":{"slug":"raga-finance","entity_name":"Raga Finance","trust_score":42,"severity_base":null,"score_modifier":0,"confidence":0.55,"status":"published","content_type":"investigation","summary":"Raga Finance is a DeFi yield optimization protocol launched in 2024 and deployed on Berachain and Hyperliquid, offering automated cross-chain vaults for earning yield on ETH, BTC, and stablecoins. A pre-launch security audit by QuillAudits uncovered 16 smart contract vulnerabilities — including critical flaws enabling permanent loss of user funds, a non-functional emergency panic function, and an open-access vault address setter — constituting the protocol logic incident flagged for review. The protocol has been flagged by ZachXBT, and while the development team reportedly remediated all identified vulnerabilities, the severity and breadth of pre-launch flaws raise meaningful questions about engineering process and ongoing risk.","sections":[{"content":"Raga Finance is a decentralized finance (DeFi) yield optimization platform that automates complex on-chain strategies through structured vault products. The platform enables one-click deposits and withdrawals, with vaults categorized by risk tier (low, medium, high). As of 2025, it is live on two chains: Berachain and Hyperliquid. On Berachain, the protocol offers auto-compounding vaults including Infrared Strategy vaults and BeraPaw vaults, both of which compound earned rewards back into the underlying strategy. On Hyperliquid, Raga operates a delta-neutral vault (rHYPE-DN) that holds user funds in USDT0 on hyperEVM while simultaneously managing short HYPE positions on HyperCore to capture funding rates with reduced directional exposure. The protocol was originally founded in September 2023 under the name Nexus Network before rebranding to Raga Finance. The co-founder and CEO is Mayank Raj, who previously worked at Persistence Labs and KPMG India and holds an MBA from IIM Ahmedabad. The platform targets both crypto-native users and DeFi newcomers seeking automated yield exposure across multiple ecosystems.","heading":"Protocol Overview","sources":[{"url":"https://docs.raga.finance/","name":"docs.raga.finance","type":"other","credibility":3},{"url":"https://www.raga.finance/","name":"raga.finance","type":"other","credibility":3},{"url":"https://docs.raga.finance/technical-documentation/hyperliquid-vault","name":"docs.raga.finance","type":"other","credibility":3},{"url":"https://medium.com/@office_39642/cross-chain-conversations-with-mayank-raj-simplifying-defi-exploring-raga-finances-innovations-d5a7c549573a","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"A security audit conducted by QuillAudits on Raga Finance's Berachain smart contracts — completed over approximately six days by two auditors — uncovered 16 vulnerabilities prior to mainnet deployment. Eight critical findings were documented in detail. The most severe included: (1) Fee Mismanagement in deposit(): accumulated protocol fees were mistakenly re-staked rather than routed to the treasury, rendering them inaccessible. (2) Permanent Fund Lock Post-EmergencyWithdraw: the emergency withdrawal logic did not account for idle (uninvested) balances, meaning users could not redeem valid shares after an emergency withdraw was triggered — a complete denial of service for affected vault participants. (3) Treasury Fee Loss During withdrawAll(): when the emergency withdrawAll() function was called, all assets including accrued fees were transferred back to the vault, bypassing the treasury entirely and resulting in zero fee payment during emergencies. (4) Inflated totalAssets Metric: unclaimed fees artificially inflated the reported total vault assets, causing unfair share pricing and creating a potential denial-of-service for the last users attempting withdrawal. (5) Missing Access Control on setVault(): the setVault() function lacked any authorization check, meaning any external address could replace the vault contract address and redirect user funds to a malicious contract. (6) Non-Functional Panic Logic: a modifier conflict (whenNotPaused blocking execution of a function that required whenPaused) rendered the panic() emergency function completely inoperable — the protocol had no functioning kill switch. (7) Flawed Swap Formula in InfraredStrategy: a mathematical error in the _calculateSwapAmount() function produced suboptimal liquidity positioning and reduced user yields. (8) Mint Function DoS via Dust Attack: an attacker could permanently disable the mint() function by depositing a dust amount (e.g., 1000 wei) when the vault held no shares, causing subsequent mint calculations to use an inflated denominator that made new deposits practically impossible. The Raga Finance team reportedly implemented all recommended fixes prior to public launch. An independent audit was also conducted by a researcher identified as Tejas.","heading":"Protocol Logic Incident — Smart Contract Vulnerabilities","sources":[{"url":"https://www.quillaudits.com/case-studies/quillaudits-secures-raga-finance","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/leaderboard/raga-finance","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://docs.raga.finance/technical-documentation/audits","name":"docs.raga.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"Raga Finance has been flagged by ZachXBT, the pseudonymous on-chain investigator known for documenting exploits, scams, and protocol failures across the crypto ecosystem. ZachXBT publishes findings through his Telegram channel (@investigations) and X account (@zachxbt). The specific nature of ZachXBT's flag on Raga Finance — whether related to the smart contract vulnerabilities, the team's background, fundraising practices, or another concern — could not be independently verified through available public sources at the time of this investigation. The flag is documented here as a material signal but should be treated as low-confidence pending disclosure of the underlying basis. ZachXBT's prior investigations have covered both pre-exploit warnings and post-incident analysis of DeFi protocols, rug pulls, and alleged insider misconduct.","heading":"ZachXBT Flag","sources":[{"url":"https://t.me/s/investigations","name":"t.me","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","credibility":3}],"severity":"medium"},{"content":"Raga Finance's Hyperliquid vault uses an off-chain oracle system that manages fund movements between the hyperEVM smart contract layer and the HyperCore perpetuals layer. This architecture introduces centralization risk: the off-chain oracle triggers fund transfers and position management without user intervention, and its security is not governed by on-chain logic alone. The protocol also uses an epoch-based approach for processing deposits and withdrawals, meaning users face a time delay between requesting and receiving funds — a known liquidity risk in vault architectures. The Berachain vaults interact with third-party protocols including Infrared Finance and BeraPaw, introducing layered smart contract dependency risk. Raga Finance runs a pre-deposit vault product designed to accept user capital before a target ecosystem launches, with the stated goal of deploying liquidity at ecosystem launch. Pre-deposit structures carry elevated risk because user funds are held in escrow with limited deployed utility during the waiting period, and protocol failures during this phase could prevent timely redemption. The platform also runs an incentive campaign on Galxe, offering loyalty points through social engagement quests — a common pattern in early-stage DeFi protocols that may attract users primarily seeking airdrop speculation rather than organic yield demand.","heading":"Product Architecture and Operational Risk","sources":[{"url":"https://docs.raga.finance/technical-documentation/hyperliquid-vault","name":"docs.raga.finance","type":"other","credibility":3},{"url":"https://docs.raga.finance/strategies/predeposits","name":"docs.raga.finance","type":"other","credibility":3},{"url":"https://docs.raga.finance/technical-documentation/auto-compounding-vaults-berachain","name":"docs.raga.finance","type":"other","credibility":3},{"url":"https://app.galxe.com/quest/RagaFinance","name":"app.galxe.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The identified co-founder and CEO of Raga Finance is Mayank Raj, who is based in Dubai, UAE. Mayank Raj holds an MBA from the Indian Institute of Management Ahmedabad (2018–2020) and has prior professional experience at Persistence Labs, KPMG India, and LetsEndorse. The company was initially operated under the name Nexus Network, which was started in September 2023, before rebranding as Raga Finance. The broader team composition is not publicly disclosed in available sources. There is no record of venture capital fundraising by Raga Finance itself; the single tracked investment on record at ICO Analytics and CryptoRank is an outbound investment of $1,000,000 into Bloctopus (formerly LZero), a seed-stage infrastructure project, in April 2025 — suggesting Raga Finance was acting as a venture investor, not a recipient of disclosed external funding. Raga Finance has no publicly disclosed regulatory registrations, exchange licenses, or legal entity filings identified in this investigation.","heading":"Team and Corporate Background","sources":[{"url":"https://ae.linkedin.com/in/mayank-raj","name":"ae.linkedin.com","type":"other","credibility":3},{"url":"https://medium.com/@office_39642/cross-chain-conversations-with-mayank-raj-simplifying-defi-exploring-raga-finances-innovations-d5a7c549573a","name":"medium.com","type":"other","credibility":3},{"url":"https://icoanalytics.org/funds/raga-finance/","name":"icoanalytics.org","type":"other","credibility":3},{"url":"https://cryptorank.io/funds/raga-finance/rounds","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Raga Finance engaged QuillAudits to perform a smart contract audit of its Berachain vaults. The audit identified 16 vulnerabilities and the development team reportedly resolved all findings before public launch. In addition to the QuillAudits engagement, Raga Finance commissioned an independent audit from a researcher identified only as Tejas, also covering the Berachain contracts. Two additional audits were conducted on the Hyperliquid contracts: one covering the main smart contract and one specifically covering the oracle component. Audit reports are referenced in the protocol's documentation with links to PDF reports hosted on a GitHub repository, though the specific audit dates are not published in the public documentation. The presence of four distinct audits across two chains is a positive indicator of security diligence. However, the breadth and severity of pre-audit vulnerabilities — particularly the open setVault() access control failure and the non-functional panic() emergency mechanism — suggest that foundational security practices were not applied during initial contract development. The remediation of all findings prior to public launch partially mitigates this concern, but the absence of a public post-mortem or transparency report limits independent verification.","heading":"Audit Status and Remediation","sources":[{"url":"https://www.quillaudits.com/case-studies/quillaudits-secures-raga-finance","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://docs.raga.finance/technical-documentation/audits","name":"docs.raga.finance","type":"other","credibility":3},{"url":"https://www.quillaudits.com/leaderboard/raga-finance","name":"quillaudits.com","type":"other","credibility":3}],"severity":"medium"},{"content":"No regulatory actions, SEC or CFTC filings, OFAC sanctions, or government enforcement records have been identified against Raga Finance or its principals at the time of this investigation. Mayank Raj does not appear in any public enforcement database reviewed. The protocol does not disclose a legal jurisdiction, regulatory registration, or terms of service that reference applicable financial law. Raga Finance operates in a sector — automated DeFi yield optimization — that regulators in multiple jurisdictions have begun examining for potential classification as investment contracts or collective investment schemes. The absence of disclosed legal structure is consistent with many early-stage DeFi protocols but represents a latent compliance risk, particularly as the protocol targets retail users across jurisdictions with divergent crypto regulations.","heading":"Regulatory and Compliance Posture","sources":[{"url":"https://www.raga.finance/","name":"raga.finance","type":"other","credibility":3},{"url":"https://docs.raga.finance/","name":"docs.raga.finance","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-09","event":"Raga Finance founded under the name Nexus Network by Mayank Raj and co-founders.","source":""},{"date":"2024-01","event":"Project rebrands from Nexus Network to Raga Finance and begins developing cross-chain yield vault product.","source":""},{"date":"2025-01-21","event":"Co-founder and CEO Mayank Raj participates in a public AMA discussing Raga Finance's cross-chain DeFi yield product and upcoming launch on Movement mainnet.","source":""},{"date":"2025-02","event":"Berachain mainnet launches. Raga Finance deploys vaults on Berachain including Infrared and BeraPaw auto-compounding strategies.","source":""},{"date":"2025-03","event":"Raga Finance opens USDC, USDT, DAI, and USDe vault deposits to users.","source":""},{"date":"2025-04","event":"Raga Finance makes a $1,000,000 seed investment in Bloctopus (formerly LZero), an infrastructure project, alongside Hivemind and the Ethereum Foundation.","source":""},{"date":"2025-06","event":"QuillAudits publishes a case study documenting the results of the Raga Finance Berachain smart contract audit, which identified 16 vulnerabilities including critical issues with fund safety, access control, and emergency logic. All findings are reported as resolved.","source":""},{"date":"2025-07","event":"Raga Finance Hyperliquid delta-neutral vault (rHYPE-DN) launches, deploying user funds in USDT0 on hyperEVM with short HYPE positions on HyperCore.","source":""}],"sources_used":[{"url":"https://docs.raga.finance/","name":"docs.raga.finance","type":"other","archive_url":"http://web.archive.org/web/20260612041842/https://docs.raga.finance/","credibility":3,"archive_timestamp":"2026-06-12T04:18:42+00:00"},{"url":"https://www.raga.finance/","name":"raga.finance","type":"other","archive_url":"http://web.archive.org/web/20260606022154/https://www.raga.finance/","credibility":3,"archive_timestamp":"2026-06-06T02:21:54+00:00"},{"url":"https://docs.raga.finance/technical-documentation/hyperliquid-vault","name":"docs.raga.finance","type":"other","archive_url":"http://web.archive.org/web/20260612041252/https://docs.raga.finance/technical-documentation/hyperliquid-vault","credibility":3,"archive_timestamp":"2026-06-12T04:12:52+00:00"},{"url":"https://medium.com/@office_39642/cross-chain-conversations-with-mayank-raj-simplifying-defi-exploring-raga-finances-innovations-d5a7c549573a","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.quillaudits.com/case-studies/quillaudits-secures-raga-finance","name":"quillaudits.com","type":"other","archive_url":"http://web.archive.org/web/20260611074021/https://www.quillaudits.com/case-studies/quillaudits-secures-raga-finance","credibility":3,"archive_timestamp":"2026-06-11T07:40:21+00:00"},{"url":"https://www.quillaudits.com/leaderboard/raga-finance","name":"quillaudits.com","type":"other","archive_url":"http://web.archive.org/web/20260829051820/https://www.quillaudits.com/leaderboard/raga-finance","credibility":3,"archive_timestamp":"2026-08-29T05:18:20+00:00"},{"url":"https://docs.raga.finance/technical-documentation/audits","name":"docs.raga.finance","type":"other","archive_url":"http://web.archive.org/web/20260414152901/https://docs.raga.finance/technical-documentation/audits","credibility":3,"archive_timestamp":"2026-04-14T15:29:01+00:00"},{"url":"https://t.me/s/investigations","name":"t.me","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","archive_url":"http://web.archive.org/web/20260711020137/https://en.wikipedia.org/wiki/ZachXBT","credibility":3,"archive_timestamp":"2026-07-11T02:01:37+00:00"},{"url":"https://docs.raga.finance/strategies/predeposits","name":"docs.raga.finance","type":"other","archive_url":"http://web.archive.org/web/20260612051119/https://docs.raga.finance/strategies/predeposits","credibility":3,"archive_timestamp":"2026-06-12T05:11:19+00:00"},{"url":"https://docs.raga.finance/technical-documentation/auto-compounding-vaults-berachain","name":"docs.raga.finance","type":"other","archive_url":"http://web.archive.org/web/20260414154837/https://docs.raga.finance/technical-documentation/auto-compounding-vaults-berachain","credibility":3,"archive_timestamp":"2026-04-14T15:48:37+00:00"},{"url":"https://app.galxe.com/quest/RagaFinance","name":"app.galxe.com","type":"other","archive_url":"https://web.archive.org/web/20260829174849/https://app.galxe.com/quest/RagaFinance","credibility":3,"archive_timestamp":"2026-08-29T17:48:49+00:00"},{"url":"https://ae.linkedin.com/in/mayank-raj","name":"ae.linkedin.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:blocked","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://icoanalytics.org/funds/raga-finance/","name":"icoanalytics.org","type":"other","archive_url":null,"credibility":3,"archive_error":"error:invalid-host-resolution","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptorank.io/funds/raga-finance/rounds","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260830032327/https://cryptorank.io/funds/raga-finance/rounds","credibility":3,"archive_timestamp":"2026-08-30T03:23:27+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:20.224551+00:00","updated_at":"2026-08-30T03:54:58.987173+00:00"}}