Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[PT] Truth Network | Prediction Market App | May2025

Date:

Jun 4, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Truth Network team for the collaborative engagement that enabled the execution of this dApp Security Assessment.

SI Predict represents a significant evolution in sports media, aligning with the growing trend of interactive and participatory fan experiences. By integrating prediction markets into the sports viewing experience, Sports Illustrated and Galactic are positioning themselves at the forefront of this emerging sector .

Document

NamedApp Code Review and Security Analysis Report for Truth Network
Audited ByAdedolapo Olayinka-Adeyemi
Approved ByStephen Ajayi
Websitehttps://truth-network.io/→
Changelog20/05/2025 - Preliminary Report
Changelog04/06/2025 - Final Report
PlatformPrediction Market
LanguageTypeScript
TagsCode Review, dApp Audit
Methodologyhttps://hackenio.cc/dApp_methodology→
  • Document

    Name
    dApp Code Review and Security Analysis Report for Truth Network
    Audited By
    Adedolapo Olayinka-Adeyemi
    Approved By
    Stephen Ajayi
    Changelog
    20/05/2025 - Preliminary Report
    Changelog
    04/06/2025 - Final Report
    Platform
    Prediction Market
    Language
    TypeScript
    Tags
    Code Review, dApp Audit

Review Scope

Repositoryhttps://github.com/Galactic-Media-Management/prediction-market-apps→
Initial Commit9f3bdff06a38c9400640776a094ce37db3891519
Final Commit07cd98732937cb7654ca71ab4d6e2976867a3b4f

Protect your dApp with insights like these.

Audit Summary

54Total Findings
52Resolved
2Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

The documentation for the Prediction Market monorepo is well-structured and developer-friendly. It clearly outlines the architecture (apps, packages, and config layers), includes practical setup and infrastructure commands, and provides helpful development workflows using pnpm and Turborepo. It emphasizes consistency through shared configs and demonstrates good practices for scalable, modular app development.

Code quality

The codebase is well-structured, leveraging a clean monorepo setup with clear separation of concerns across backend, frontend, and shared packages. Configuration and tooling are thoughtfully organized, supporting scalable development.

However, during our review, we identified several critical quality issues:

  • Access Control Gaps: Inadequate authorization checks across sensitive endpoints, potentially exposing user or system-level data.

  • Logical Flaws: Business logic inconsistencies in prediction handling and transaction flows, which could lead to incorrect or exploitable outcomes.

  • Missing Validations: Insufficient input validation, increasing the risk of invalid data entering the system.

  • Error Handling Weaknesses: Several areas lack robust error management, reducing system reliability under edge-case scenarios.

While the structural foundation is solid, the implementation requires significant attention to security, logical correctness, and defensive coding practices to ensure production readiness.

System Overview

The Prediction Market project is a full-stack decentralized application (DApp) designed to facilitate interactive prediction experiences, likely in contexts such as sports or live events. The system is organized as a monorepo managed using Turborepo and built with modern technologies like NestJS, Next.js, and pnpm.

Core Components

  • API Layer (api) A backend application built with NestJS, handling business logic, API endpoints, and integrations with services like PostgreSQL and AWS (via LocalStack).

  • Frontend DApp (web) A Next.js application serving the user interface for end-users to engage with prediction markets in real-time.

  • Shared Packages Modular packages such as @repo/types, @repo/logger, and @repo/utils promote reusability and consistency across the codebase.

  • UI Library (@repo/ui) A component library based on shadcn/ui, providing standardized design components for the frontend.

  • DevOps & Tooling Includes infrastructure scripts to manage local services (Postgres, LocalStack), as well as configuration packages for TypeScript, ESLint, and Jest, ensuring consistent development workflows.

Findings

F-2025-1043Insecure Direct Object Reference (IDOR) in Off-Ramp URL Signing
Status
fixed
Severity

High
F-2025-1043 Insecure Direct Object Reference (IDOR) in PositionController
Status
fixed
Severity

High
F-2025-1042Missing Authorization on Market Resolution (IDOR)
Status
fixed
Severity

High
F-2025-1042Uncontrolled Premature Balance Release
Status
fixed
Severity

High
F-2025-1042Missing Input Validation in Liquidity Removal
Status
fixed
Severity

High
F-2025-1030Broken Access Control in Market Resolution
Status
fixed
Severity

High
F-2025-1029Insufficient Validation of Liquidity Amounts Leading to Negative Balances
Status
fixed
Severity

High
F-2025-1029Stored XSS via Un-sanitized heroDescription
Status
fixed
Severity

High
F-2025-1029Insecure Direct Object Reference (IDOR) in ClaimMarketDto
Status
fixed
Severity

High
F-2025-1028Insecure Default Configuration (Hardcoded Credentials)
Status
fixed
Severity

High
Code
―
Title
Status
Severity
F-2025-1043Insecure Direct Object Reference (IDOR) in Off-Ramp URL Signing
fixed

High
F-2025-1043 Insecure Direct Object Reference (IDOR) in PositionController
fixed

High
F-2025-1042Missing Authorization on Market Resolution (IDOR)
fixed

High
F-2025-1042Uncontrolled Premature Balance Release
fixed

High
F-2025-1042Missing Input Validation in Liquidity Removal
fixed

High
F-2025-1030Broken Access Control in Market Resolution
fixed

High
F-2025-1029Insufficient Validation of Liquidity Amounts Leading to Negative Balances
fixed

High
F-2025-1029Stored XSS via Un-sanitized heroDescription
fixed

High
F-2025-1029Insecure Direct Object Reference (IDOR) in ClaimMarketDto
fixed

High
F-2025-1028Insecure Default Configuration (Hardcoded Credentials)
fixed

High
1-10 of 54 findings

Uncover findings like these to secure your project.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following:

Scope Details

Repositoryhttps://github.com/Galactic-Media-Management/prediction-market-apps→
Initial Commit9f3bdff06a38c9400640776a094ce37db3891519
Final Commit07cd98732937cb7654ca71ab4d6e2976867a3b4f

Assets in Scope

apps
api
.env.example - apps › api › .env.example
.eslintrc.js - apps › api › .eslintrc.js
.prettierrc.js - apps › api › .prettierrc.js
docker
init.sql - apps › api › docker › init.sql
init-events.sql - apps › api › docker › init-events.sql
init-queries.sql - apps › api › docker › init-queries.sql
localstack
init
init-s3.sh - apps › api › docker › localstack › init › init-s3.sh
init-sqs.sh - apps › api › docker › localstack › init › init-sqs.sh
scripts
clear-sqs-queues.sh - apps › api › docker › localstack › scripts › clear-sqs-queues.sh
scripts
clear-database.sh - apps › api › docker › scripts › clear-database.sh
docker-compose.yml - apps › api › docker-compose.yml
dockerfile - apps › api › dockerfile
jest.config.ts - apps › api › jest.config.ts
nest-cli.json - apps › api › nest-cli.json
package.json - apps › api › package.json

Disclaimer