Introduction
We express our gratitude to the Truth Network team for the collaborative engagement that enabled the execution of this Blockchain Protocol Security Assessment.
Truth Network integrates prediction markets into media platforms through their Truth Protocol blockchain system, allowing audiences to make predictions on future outcomes across sports, politics, finance, and entertainment. Truth Protocol is a Substrate-based blockchain infrastructure (forked from Zeitgeist) that provides the foundational layer for creating, managing, and resolving prediction markets with transparency and security. The system handles market creation, oracle reporting, token economics, dispute resolution, and regulatory compliance, serving as the trust layer behind consumer-facing applications. This security audit examines Truth Protocol's implementation to ensure it provides a secure and reliable foundation for Truth Network's prediction market ecosystem.
Document | |
|---|---|
| Name | Blockchain Protocol Review and Security Analysis Report for Truth Network |
| Audited By | Sofiane Akermoun |
| Approved By | Nino Lipartiia |
| Website | https://truth-network.io/→ |
| Changelog | 19/05/2025 - Preliminary Report |
| Changelog | 30/05/2025 - Final Report |
| Platform | Truth Network, Substrate |
| Language | Rust |
| Tags | L1, Substrate, Rust |
| Methodology | https://hackenio.cc/blockchain_methodology→ |
Document
- Name
- Blockchain Protocol Review and Security Analysis Report for Truth Network
- Audited By
- Sofiane Akermoun
- Approved By
- Nino Lipartiia
- Website
- https://truth-network.io/→
- Changelog
- 19/05/2025 - Preliminary Report
- Changelog
- 30/05/2025 - Final Report
- Platform
- Truth Network, Substrate
- Language
- Rust
- Tags
- L1, Substrate, Rust
- Methodology
- https://hackenio.cc/blockchain_methodology→
Review Scope | |
|---|---|
| Repository | https://github.com/Truth-Protocol-Foundation/truth-network-node/→ |
| Commit | 35d3c820b5f3e48fcdca8a30dc359caee1761a66 |
Review Scope
- Commit
- 35d3c820b5f3e48fcdca8a30dc359caee1761a66
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
Each major component has its own README.md file that explains its purpose and functionality, with the prediction-markets README providing a good overview of market types and available dispatches.
While core functionality is generally well-documented, there's noticeable variation in documentation quality across the codebase, particularly for transaction functions that use cryptographic signatures.
The documentation is primarily oriented towards technical implementation details, with less emphasis on conceptual explanations or architectural diagrams that would help newcomers understand the overall system design.
Code quality
The code demonstrates advanced Rust skills and very good usage of the Substrate framework, following ecosystem best practices and leveraging framework features effectively.
The codebase is well-organized into focused pallets with clear responsibilities and logical separation of concerns, enabling better maintainability and future extensibility.
The code implements thorough error checking with specific, descriptive error types, extensive validation checks before state changes, and proper propagation of errors through the call stack, ensuring robust operation even under unexpected conditions.
Project Implements comprehensive benchmarking for optimal resource allocation and accurate transaction fee calculation.
Architecture quality
The project leverages Substrate as its core architectural framework, providing inherent benefits like consensus mechanisms, networking capabilities, and runtime upgradability.
The system features a sophisticated governance structure with distinct access control mechanisms - from privileged admin functions requiring committee approval to market creator operations requiring whitelisting, ensuring proper authority distribution across the network.
The protocol implements a sophisticated incentive structure with bonding requirements, fee distribution mechanisms, and conditional slashing penalties to align participant behaviors with network integrity.
The codebase is organized into specialized pallets (prediction-markets, court, neo-swaps, etc.), creating clear boundaries between different protocol domains while enabling necessary interactions between components.
Test coverage
Code coverage analysis shows reasonable test coverage for the audited assets:
The
prediction-market-primitivescrate demonstrates adequate test coverage at 63.3%The pallet
prediction-marketsshows room for improvement with 51.69% test coverage
System Overview
Truth Protocol is a Substrate-based prediction market platform integrating multiple trading mechanisms and cross-chain functionality. The system's modular architecture consists of specialized pallets working together to create a comprehensive prediction market ecosystem. The core system components include:
prediction-markets pallet: The central module implementing market lifecycle management from creation through reporting to resolution. Features both standard extrinsics and cryptographically signed variants enabling relayer-based interactions for improved UX while maintaining security.
market-commons pallet: Provides foundational data structures and shared functionality used across the system, including market types, period definitions, and common utilities.
neo-swaps pallet: Implements automated market maker (AMM) functionality for prediction markets with customizable swap fees, providing constant product liquidity pools for outcome asset trading. Supports both regular and signed transactions for pool operations like joining, exiting, and withdrawing fees.
order-book pallet: Offers traditional order-book trading functionality as an alternative to AMM pools, allowing users to place limit orders with specific prices rather than relying on automated pricing mechanics.
hybrid-router pallet: Acts as an intelligent routing layer that optimizes trade execution by splitting orders between pools and order books to achieve the best possible price for traders.
eth-asset-registry pallet: Manages registration and metadata of Ethereum-based assets within the Truth Protocol ecosystem, enabling external assets to be utilized in markets.
court pallet: Implements the arbitration system for handling disputes when market outcomes are contested, with juror selection and management of the dispute resolution process.
global-disputes pallet: Provides an escalation path for disputes that cannot be resolved through standard mechanisms, offering a final resolution layer.
authorized pallet: Manages privileged operations and access controls, particularly for authorized markets with specialized reporting mechanisms.
The system features multi-tiered transaction processing with both standard and signed transaction variants across most modules. Security is ensured through bonding requirements, cryptographic verification, and carefully controlled state transitions between market phases. Truth Protocol uses AURA for block production and GRANDPA for block finalization, which is a standard hybrid consensus approach in the Substrate ecosystem.
Risks
The Sudo pallet grants a single root account unlimited control over critical protocol functions, bypassing governance and creating a centralized authority that contradicts blockchain's decentralization principles and requires users to trust the root key holder.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2025-1041 | Fund Lock and Market Deadlock in Trusted Markets with Unresponsive Oracle | fixed | Medium | |
| F-2025-1041 | Balanced Test Coverage with Opportunities for Refinement | fixed | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required. |
High | High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category. |
Medium | Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively. |
Low | Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system. |
Severity
- Critical
Description
- Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.
Severity
- High
Description
- High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.
Severity
- Medium
Description
- Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.
Severity
- Low
Description
- Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.
Appendix 2. Scope
The scope of the project includes the following components from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/Truth-Protocol-Foundation/truth-network-node/→ |
| Commit | 35d3c820b5f3e48fcdca8a30dc359caee1761a66 |
| Whitepaper | N/A |
Scope Details
- Commit
- 35d3c820b5f3e48fcdca8a30dc359caee1761a66
- Whitepaper
- N/A
Components in Scope
Cryptography and Keys:
Cryptography Libraries
Keys Generation
Keystore storage
Runtime & Pallets:
Runtime implementation review
prediction-markets implementation review
Market management and operation
Dispute handling and resolution
Storage and events
Permissions and admin, centralization risks assessment
Bridge interface and process lift
Review of changes compared to Zeitgeist
Assess prediction-market-primitives implementation
Attack scenarios analysis (Weight, race, stack, DoS, state implosion, access control bypass...)
RPC:
RPC implementation review
Attack scenarios analysis (defaults, DoS, overflows, ..)
Substrate client configuration review:
Genesis review
Consensus
Substrate FRAME pallets usage review
Standard attacks review (replay, malleability,...)
Substrate fork review:
Review of all code changes and missing updates since Substrate clone date
Weights & Benchmarks:
Weight values & benchmarks review