Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[L1] Truth Network | Truth Protocol | May2025

Date:

May 30, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Truth Network team for the collaborative engagement that enabled the execution of this Blockchain Protocol Security Assessment.

Truth Network integrates prediction markets into media platforms through their Truth Protocol blockchain system, allowing audiences to make predictions on future outcomes across sports, politics, finance, and entertainment. Truth Protocol is a Substrate-based blockchain infrastructure (forked from Zeitgeist) that provides the foundational layer for creating, managing, and resolving prediction markets with transparency and security. The system handles market creation, oracle reporting, token economics, dispute resolution, and regulatory compliance, serving as the trust layer behind consumer-facing applications. This security audit examines Truth Protocol's implementation to ensure it provides a secure and reliable foundation for Truth Network's prediction market ecosystem.

Document

NameBlockchain Protocol Review and Security Analysis Report for Truth Network
Audited BySofiane Akermoun
Approved ByNino Lipartiia
Websitehttps://truth-network.io/→
Changelog19/05/2025 - Preliminary Report
Changelog30/05/2025 - Final Report
PlatformTruth Network, Substrate
LanguageRust
TagsL1, Substrate, Rust
Methodologyhttps://hackenio.cc/blockchain_methodology→
  • Document

    Name
    Blockchain Protocol Review and Security Analysis Report for Truth Network
    Audited By
    Sofiane Akermoun
    Approved By
    Nino Lipartiia
    Changelog
    19/05/2025 - Preliminary Report
    Changelog
    30/05/2025 - Final Report
    Platform
    Truth Network, Substrate
    Language
    Rust
    Tags
    L1, Substrate, Rust

Review Scope

Repositoryhttps://github.com/Truth-Protocol-Foundation/truth-network-node/→
Commit35d3c820b5f3e48fcdca8a30dc359caee1761a66

Audit Summary

2Total Findings
2Resolved
0Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • Each major component has its own README.md file that explains its purpose and functionality, with the prediction-markets README providing a good overview of market types and available dispatches.

  • While core functionality is generally well-documented, there's noticeable variation in documentation quality across the codebase, particularly for transaction functions that use cryptographic signatures.

  • The documentation is primarily oriented towards technical implementation details, with less emphasis on conceptual explanations or architectural diagrams that would help newcomers understand the overall system design.

Code quality

  • The code demonstrates advanced Rust skills and very good usage of the Substrate framework, following ecosystem best practices and leveraging framework features effectively.

  • The codebase is well-organized into focused pallets with clear responsibilities and logical separation of concerns, enabling better maintainability and future extensibility.

  • The code implements thorough error checking with specific, descriptive error types, extensive validation checks before state changes, and proper propagation of errors through the call stack, ensuring robust operation even under unexpected conditions.

  • Project Implements comprehensive benchmarking for optimal resource allocation and accurate transaction fee calculation.

Architecture quality

  • The project leverages Substrate as its core architectural framework, providing inherent benefits like consensus mechanisms, networking capabilities, and runtime upgradability.

  • The system features a sophisticated governance structure with distinct access control mechanisms - from privileged admin functions requiring committee approval to market creator operations requiring whitelisting, ensuring proper authority distribution across the network.

  • The protocol implements a sophisticated incentive structure with bonding requirements, fee distribution mechanisms, and conditional slashing penalties to align participant behaviors with network integrity.

  • The codebase is organized into specialized pallets (prediction-markets, court, neo-swaps, etc.), creating clear boundaries between different protocol domains while enabling necessary interactions between components.

Test coverage

Code coverage analysis shows reasonable test coverage for the audited assets:

  • The prediction-market-primitives crate demonstrates adequate test coverage at 63.3%

  • The pallet prediction-markets shows room for improvement with 51.69% test coverage

System Overview

Truth Protocol is a Substrate-based prediction market platform integrating multiple trading mechanisms and cross-chain functionality. The system's modular architecture consists of specialized pallets working together to create a comprehensive prediction market ecosystem. The core system components include:

  • prediction-markets pallet: The central module implementing market lifecycle management from creation through reporting to resolution. Features both standard extrinsics and cryptographically signed variants enabling relayer-based interactions for improved UX while maintaining security.

  • market-commons pallet: Provides foundational data structures and shared functionality used across the system, including market types, period definitions, and common utilities.

  • neo-swaps pallet: Implements automated market maker (AMM) functionality for prediction markets with customizable swap fees, providing constant product liquidity pools for outcome asset trading. Supports both regular and signed transactions for pool operations like joining, exiting, and withdrawing fees.

  • order-book pallet: Offers traditional order-book trading functionality as an alternative to AMM pools, allowing users to place limit orders with specific prices rather than relying on automated pricing mechanics.

  • hybrid-router pallet: Acts as an intelligent routing layer that optimizes trade execution by splitting orders between pools and order books to achieve the best possible price for traders.

  • eth-asset-registry pallet: Manages registration and metadata of Ethereum-based assets within the Truth Protocol ecosystem, enabling external assets to be utilized in markets.

  • court pallet: Implements the arbitration system for handling disputes when market outcomes are contested, with juror selection and management of the dispute resolution process.

  • global-disputes pallet: Provides an escalation path for disputes that cannot be resolved through standard mechanisms, offering a final resolution layer.

  • authorized pallet: Manages privileged operations and access controls, particularly for authorized markets with specialized reporting mechanisms.

The system features multi-tiered transaction processing with both standard and signed transaction variants across most modules. Security is ensured through bonding requirements, cryptographic verification, and carefully controlled state transitions between market phases. Truth Protocol uses AURA for block production and GRANDPA for block finalization, which is a standard hybrid consensus approach in the Substrate ecosystem.

Risks

The Sudo pallet grants a single root account unlimited control over critical protocol functions, bypassing governance and creating a centralized authority that contradicts blockchain's decentralization principles and requires users to trust the root key holder.

Findings

F-2025-1041Fund Lock and Market Deadlock in Trusted Markets with Unresponsive Oracle
Status
fixed
Severity

Medium
F-2025-1041Balanced Test Coverage with Opportunities for Refinement
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2025-1041Fund Lock and Market Deadlock in Trusted Markets with Unresponsive Oracle
fixed

Medium
F-2025-1041Balanced Test Coverage with Opportunities for Refinement
fixed

Observation
1-2 of 2 findings

Findings like these can secure your blockchain.

Appendix 1. Severity Definitions

Severity

Description

Critical
Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.

High
High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.

Medium
Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.

Low
Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.
  • Severity

    Critical

    Description

    Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.

    Severity

    High

    Description

    High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.

    Severity

    Medium

    Description

    Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.

    Severity

    Low

    Description

    Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.

Appendix 2. Scope

The scope of the project includes the following components from the provided repository:

Scope Details

Repositoryhttps://github.com/Truth-Protocol-Foundation/truth-network-node/→
Commit35d3c820b5f3e48fcdca8a30dc359caee1761a66
WhitepaperN/A

Components in Scope

Cryptography and Keys:

  • Cryptography Libraries

  • Keys Generation

  • Keystore storage

Runtime & Pallets:

  • Runtime implementation review

  • prediction-markets implementation review

  • Market management and operation

  • Dispute handling and resolution

  • Storage and events

  • Permissions and admin, centralization risks assessment

  • Bridge interface and process lift

  • Review of changes compared to Zeitgeist

  • Assess prediction-market-primitives implementation

  • Attack scenarios analysis (Weight, race, stack, DoS, state implosion, access control bypass...)

RPC:

  • RPC implementation review

  • Attack scenarios analysis (defaults, DoS, overflows, ..)

Substrate client configuration review:

  • Genesis review

  • Consensus

  • Substrate FRAME pallets usage review

  • Standard attacks review (replay, malleability,...)

Substrate fork review:

  • Review of all code changes and missing updates since Substrate clone date

Weights & Benchmarks:

  • Weight values & benchmarks review

Assets in Scope

Crate pallets
prediction-markets - Crate pallets › prediction-markets
Crate primitives
prediction-market - Crate primitives › prediction-market
Crate runtime - Crate runtime
Dependencies - Dependencies

Disclaimer