> For the complete documentation index, see [llms.txt](https://funarchy.gitbook.io/funarchy/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://funarchy.gitbook.io/funarchy/pm-threat-modeling/test-result-dashboard/polymarket-test-results.md).

# Polymarket Test Results

## Test Threat Modeling

| Configuration | Trading Mechanism | Oracle & Data | Governance | Operation |
| ------------- | ----------------- | ------------- | ---------- | --------- |
| ✅             | ⚠️                | ⚠️            | ⚠️         | ✅         |

### Analysis stage

<details>

<summary>Configuration</summary>

✅  Ambiguous Resolution Criteria

✅  Manual Oracle Delay

✅  Extend market resolution time

</details>

<details>

<summary>Trading Mechanism</summary>

✅ Signature Replay Attacks

✅ Matching Engine Logic Errors

❌ State Inconsistency

&#x20;**-**   Slippage & Sandwich Attacks

&#x20;**-**   Permanent Loss

&#x20;\-   Fee bypass

</details>

<details>

<summary>Oracle &#x26; Data</summary>

❌ Single Data Source Dependency

✅ Oracle Data Validation Logic Insufficiency

❌  Missing Oracle Authentication

✅ UI Latency Desynchronization

✅ UI–Oracle Price Mismatch

✅ Short-Horizon Settlement Price Manipulation

✅ Equality Boundary Settlement Precision Risk

</details>

<details>

<summary>Governance</summary>

❌  Whale Cartel Attack

✅  Dispute Mechanism Abuse

</details>

<details>

<summary>Operation</summary>

✅  Owner's Privilege too High

✅  DoS via Unrestricted Shared State Manipulation

✅  Calculation Logic Error

</details>

### Risk Summary&#x20;

#### Trading Mechanism

* Using Hybrid CLOB causes state asynchronous issues between on-chain and off-chain.

#### Oracle & Data

* By creating a single point of failure at the single API dependencies, data disruptions can disrupt market conclusions and delay settlement
* Users who trust their own API and make transactions may suffer financial losses if their conclusions differ from Chainlink

#### **Governance**

* In UMA Governance, whales can collude to manipulate voting results and thus market outcomes

***

### Risk analysis

#### Trading Mechanism

**State inconsistency in Hybrid CLOB**

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FgkhZzpCyBE43IgWaeQDR%2Fimage.png?alt=media&amp;token=40774f25-58d3-49bd-b410-a9e43a539cdf" alt=""><figcaption></figcaption></figure>

* Polymarket currently uses a Hybrid CLOB, where orders are executed off-chain and then aggregated for processing on-chain.

  The root cause is that, due to the nature of this Hybrid CLOB, there is a delay in order execution time between off-chain and on-chain. This results in vulnerabilities caused by statelessness.

#### **Oracle & Data**

**Single Data Source Dependency**

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FtqxdlpKEM3Weshiv3bfx%2Fimage.png?alt=media&amp;token=ac83b536-c26c-4546-befb-b3f05d02d9a6" alt=""><figcaption></figcaption></figure>

* Currently, Polymarket is retrieving 15-minute market results data through a single API. \
  \
  The root cause of the single API dependency problem is that the data source, which is the core of market conclusions, is tied to a centralized single point of failure. This structure results in the immediate collapse of the conclusion data in the event of a server downtime or API failure. This data collapse triggers the UMA dispute resolution system, resulting in prolonged delays in conclusions. \
  \
  This results in the funds of users who entered the market expecting rapid capital turnover in the 15-minute market being frozen for a long period of time.

**Missing Oracle Authentication**

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FYaFRi4WWYFXJaLBV1jwV%2Fimage.png?alt=media&amp;token=3d2d8eb8-8d9f-41e8-92fe-cbda2e80197f" alt="" width="563"><figcaption></figcaption></figure>

* Polymarket's 15-minute markets retrieve market conclusion data via Chainlink oracles, but the market data displayed in the Polymarket UI is time-lagged and inconsistent with this Chainlink data, which uses its own API.\
  \
  Despite using Chainlink as a source for market conclusions, it provides UI data to users through its own API, resulting in time lags and inconsistencies between the ofiicial Chainlink results and the data displayed to users. Many users have become aware of this issue and expressed their dissatisfaction with the Polymarket 15-minute market, but Polymarket has taken no action.\
  \
  Thus, users who trust their own API and make transactions may suffer financial losses due to different conclusions from Chainlink.

### **Governance**

**Whale Cartel Attack**

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FFksYYKiBApLJDxYp2Hzr%2Fimage.png?alt=media&amp;token=41feabc5-d98b-472b-9640-28e33e9329ac" alt="" width="563"><figcaption><p>&#x3C;UMA Governance voting result></p></figcaption></figure>

* Currently, Polymarket uses UMA as governance in case of disputes.\
  \
  The root cause of UMA's Optimistic Oracle system lies in its structural vulnerability, which allows attackers to manipulate the outcome by amassing governance voting power and controlling a majority of votes, using economic incentives like voting rewards and market manipulation.\
  In fact, in the past Polymarket case, despite a 96% market consensus, a whale mobilized 30% of the total voting power, producing an unexpected outcome. However, Polymarket has not taken any action despite this attack.\
  \
  Thus, while demonstrating the failure of UMA's economic security design principles, it also shifts the cost of systemic risk to prediction market participants by forcing them to accept manipulated outcomes without a countermeasure mechanism.

#### **Operation**


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://funarchy.gitbook.io/funarchy/pm-threat-modeling/test-result-dashboard/polymarket-test-results.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
