Introduction
We express our gratitude to the Truth Network team for the collaborative engagement that enabled the execution of this dApp Security Assessment.
SI Predict represents a significant evolution in sports media, aligning with the growing trend of interactive and participatory fan experiences. By integrating prediction markets into the sports viewing experience, Sports Illustrated and Galactic are positioning themselves at the forefront of this emerging sector .
Document | |
|---|---|
| Name | dApp Code Review and Security Analysis Report for Truth Network |
| Audited By | Adedolapo Olayinka-Adeyemi |
| Approved By | Stephen Ajayi |
| Website | https://truth-network.io/→ |
| Changelog | 20/05/2025 - Preliminary Report |
| Changelog | 04/06/2025 - Final Report |
| Platform | Prediction Market |
| Language | TypeScript |
| Tags | Code Review, dApp Audit |
| Methodology | https://hackenio.cc/dApp_methodology→ |
Document
- Name
- dApp Code Review and Security Analysis Report for Truth Network
- Audited By
- Adedolapo Olayinka-Adeyemi
- Approved By
- Stephen Ajayi
- Website
- https://truth-network.io/→
- Changelog
- 20/05/2025 - Preliminary Report
- Changelog
- 04/06/2025 - Final Report
- Platform
- Prediction Market
- Language
- TypeScript
- Tags
- Code Review, dApp Audit
- Methodology
- https://hackenio.cc/dApp_methodology→
Review Scope | |
|---|---|
| Repository | https://github.com/Galactic-Media-Management/prediction-market-apps→ |
| Initial Commit | 9f3bdff06a38c9400640776a094ce37db3891519 |
| Final Commit | 07cd98732937cb7654ca71ab4d6e2976867a3b4f |
Review Scope
- Initial Commit
- 9f3bdff06a38c9400640776a094ce37db3891519
- Final Commit
- 07cd98732937cb7654ca71ab4d6e2976867a3b4f
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
The documentation for the Prediction Market monorepo is well-structured and developer-friendly. It clearly outlines the architecture (apps, packages, and config layers), includes practical setup and infrastructure commands, and provides helpful development workflows using pnpm and Turborepo. It emphasizes consistency through shared configs and demonstrates good practices for scalable, modular app development.
Code quality
The codebase is well-structured, leveraging a clean monorepo setup with clear separation of concerns across backend, frontend, and shared packages. Configuration and tooling are thoughtfully organized, supporting scalable development.
However, during our review, we identified several critical quality issues:
Access Control Gaps: Inadequate authorization checks across sensitive endpoints, potentially exposing user or system-level data.
Logical Flaws: Business logic inconsistencies in prediction handling and transaction flows, which could lead to incorrect or exploitable outcomes.
Missing Validations: Insufficient input validation, increasing the risk of invalid data entering the system.
Error Handling Weaknesses: Several areas lack robust error management, reducing system reliability under edge-case scenarios.
While the structural foundation is solid, the implementation requires significant attention to security, logical correctness, and defensive coding practices to ensure production readiness.
System Overview
The Prediction Market project is a full-stack decentralized application (DApp) designed to facilitate interactive prediction experiences, likely in contexts such as sports or live events. The system is organized as a monorepo managed using Turborepo and built with modern technologies like NestJS, Next.js, and pnpm.
Core Components
API Layer (
api) A backend application built with NestJS, handling business logic, API endpoints, and integrations with services like PostgreSQL and AWS (via LocalStack).Frontend DApp (
web) A Next.js application serving the user interface for end-users to engage with prediction markets in real-time.Shared Packages Modular packages such as
@repo/types, @repo/logger, and@repo/utilspromote reusability and consistency across the codebase.UI Library (
@repo/ui) A component library based on shadcn/ui, providing standardized design components for the frontend.DevOps & Tooling Includes infrastructure scripts to manage local services (Postgres, LocalStack), as well as configuration packages for TypeScript, ESLint, and Jest, ensuring consistent development workflows.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2025-1043 | Insecure Direct Object Reference (IDOR) in Off-Ramp URL Signing | fixed | High | |
| F-2025-1043 | Insecure Direct Object Reference (IDOR) in PositionController | fixed | High | |
| F-2025-1042 | Missing Authorization on Market Resolution (IDOR) | fixed | High | |
| F-2025-1042 | Uncontrolled Premature Balance Release | fixed | High | |
| F-2025-1042 | Missing Input Validation in Liquidity Removal | fixed | High | |
| F-2025-1030 | Broken Access Control in Market Resolution | fixed | High | |
| F-2025-1029 | Insufficient Validation of Liquidity Amounts Leading to Negative Balances | fixed | High | |
| F-2025-1029 | Stored XSS via Un-sanitized heroDescription | fixed | High | |
| F-2025-1029 | Insecure Direct Object Reference (IDOR) in ClaimMarketDto | fixed | High | |
| F-2025-1028 | Insecure Default Configuration (Hardcoded Credentials) | fixed | High |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes the following:
Scope Details | |
|---|---|
| Repository | https://github.com/Galactic-Media-Management/prediction-market-apps→ |
| Initial Commit | 9f3bdff06a38c9400640776a094ce37db3891519 |
| Final Commit | 07cd98732937cb7654ca71ab4d6e2976867a3b4f |
Scope Details
- Initial Commit
- 9f3bdff06a38c9400640776a094ce37db3891519
- Final Commit
- 07cd98732937cb7654ca71ab4d6e2976867a3b4f