Scope
Each audit covers, at minimum:- The asset prediction market contracts (round lifecycle, commit-reveal, settlement, payouts)
- The factory and registry contracts
- The oracle integration and signature verification path
- The tournament contracts (bracket commitment, reveal, scoring, payout)
- Access control, pause behavior, and admin role boundaries
Reports
Initial security review
Audit report for the v1 asset prediction contracts. Published upon completion.
Tournament contract review
Audit report for the full-bracket tournament contracts. Published upon completion.
What an audit is and is not
An audit is a strong, independent set of expert eyes on the code. It is not a guarantee of bug-free software — no audit is. We treat audits as one layer of defense, alongside:- Internal review and adversarial testing
- A continuously monitored test deployment that mirrors production
- A live bug bounty program (see Bug bounty)
- Real-time on-chain anomaly monitoring
- A documented incident response playbook
