> For the complete documentation index, see [llms.txt](https://funarchy.gitbook.io/funarchy/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://funarchy.gitbook.io/funarchy/pm-threat-modeling/test-result-dashboard/opinion-test-result.md).

# Opinion Test Result

| Configuration | Trading Mechanism | Oracle & Data | Governance | Operation |
| ------------- | ----------------- | ------------- | ---------- | --------- |
| ✅             | ⚠️                | ⚠️            | -          | ✅         |

### Analysis stage

<details>

<summary>Configuration</summary>

✅  Ambiguous Resolution Criteria

✅  Manual Oracle Delay

✅  Extend market resolution time

</details>

<details>

<summary>Trading Mechanism</summary>

✅ Signature Replay Attacks

✅ Matching Engine Logic Errors

❌ State Inconsistency

&#x20;**-**   Slippage & Sandwich Attacks

&#x20;**-**   Permanent Loss

&#x20;\-   Fee bypass

</details>

<details>

<summary>Oracle &#x26; Data</summary>

✅ Single Data Source Dependency

✅ Oracle Data Validation Logic Insufficiency

❌  Missing Oracle Authentication

&#x20;**-**   UI Latency Desynchronization

&#x20;**-**   UI–Oracle Price Mismatch

&#x20;**-**  Short-Horizon Settlement Price Manipulation

&#x20;**-**  Equality Boundary Settlement Precision Risk

</details>

<details>

<summary>Governance</summary>

&#x20;**-**   Whale Cartel Attack

&#x20;**-**   Dispute Mechanism Abuse

</details>

<details>

<summary>Operation</summary>

✅  Owner's Privilege too High

✅  DoS via Unrestricted Shared State Manipulation

✅  Calculation Logic Error

</details>

### Risk Summary&#x20;

#### Trading Mechanism

* Using Hybrid CLOB causes state asynchronous issues between on-chain and off-chain.

#### Oracle & Data

* A malicious operator can inject malicious results through the resolve account without going through AI, causing damage to users.

***

### Risk Analysis

#### Trading Mechanism

**State inconsistency in Hybrid CLOB**

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FhWhBhSdOKiWpVeT6Pphx%2Fimage.png?alt=media&amp;token=f4208da7-ad5b-4f78-b7cd-04584ec8bcff" alt=""><figcaption></figcaption></figure>

* Opinion currently uses a Hybrid CLOB, where orders are executed off-chain and then aggregated for processing on-chain.

  The root cause is that, due to the nature of this Hybrid CLOB, there is a delay in order execution time between off-chain and on-chain. This results in vulnerabilities caused by statelessness.

#### Oracle & Data

**Missing Oracle Authentication**

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FnuaSVCgosjBnlWLGNRob%2Fimage.png?alt=media&amp;token=444d8196-2bac-4265-b051-dcd615e017d2" alt=""><figcaption><p>&#x3C;Resolver Transaction></p></figcaption></figure>

* Opinion currently uses AI as a resolver.<br>

  Actually, on-chain verification revealed that only the status after the EOA account called the reportpayout conclusion function could be confirmed. Furthermore, because it was a simple EOA account, it was impossible to determine whether it was an AI or a human. Ultimately, general users cannot verify whether the data used to resolve the market is accurate or whether the EOA account is being used by an AI or a human.<br>

  Thus, a malicious operator could inject malicious results through the resolver account, bypassing the AI, and harm users.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://funarchy.gitbook.io/funarchy/pm-threat-modeling/test-result-dashboard/opinion-test-result.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
