> For the complete documentation index, see [llms.txt](https://funarchy.gitbook.io/funarchy/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://funarchy.gitbook.io/funarchy/pm-threat-modeling/test-result-dashboard/trueo-test-result.md).

# Trueo Test Result

| Configuration | Trading Mechanism | Oracle & Data | Governance | Operation |
| ------------- | ----------------- | ------------- | ---------- | --------- |
| ✅             | ⚠️                | ✅             | ✅          | ⚠️        |

### Analysis stage

<details>

<summary>Configuration</summary>

✅  Ambiguous Resolution Criteria

✅  Manual Oracle Delay

✅  Extend market resolution time

</details>

<details>

<summary>Trading Mechanism</summary>

✅  Signature Replay Attacks

✅  Matching Engine Logic Errors

❌  State Inconsistency

&#x20;**-**   Slippage & Sandwich Attacks

&#x20;**-**   Permanent Loss

&#x20;\-   Fee bypass

</details>

<details>

<summary>Oracle &#x26; Data</summary>

✅  Single Data Source Dependency

✅  Oracle Data Validation Logic Insufficiency

✅  Missing Oracle Authentication

&#x20;**-**   UI Latency Desynchronization

&#x20;**-**   UI–Oracle Price Mismatch

&#x20;**-**  Short-Horizon Settlement Price Manipulation

&#x20;**-**  Equality Boundary Settlement Precision Risk

</details>

<details>

<summary>Governance</summary>

✅  Whale Cartel Attack

✅  Dispute Mechanism Abuse

</details>

<details>

<summary>Operation</summary>

❌  Owner's Privilege too High

✅  DoS via Unrestricted Shared State Manipulation

✅  Calculation Logic Error

</details>

### Risk Summary

#### Trading Mechanism

* Using Hybrid CLOB causes state asynchronous issues between on-chain and off-chain.

#### Operation

* If the owner's authority is stolen, it can be dangerous for the entire market.

***

### Risk Analysis

#### Trading Mechanism

**State inconsistency in Hybrid CLOB**

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FUYwikL285nmGCrcMBjg9%2Fimage.png?alt=media&amp;token=4494ae79-fcab-4581-9e27-37fcb5ee242d" alt=""><figcaption></figcaption></figure>

* Trueo currently uses a Hybrid CLOB, where orders are executed off-chain and then aggregated for processing on-chain.

  The root cause is that, due to the nature of this Hybrid CLOB, there is a delay in order execution time between off-chain and on-chain. This results in vulnerabilities caused by statelessness.

#### Operation

**Owner's Privilege too High**

{% code expandable="true" %}

```solidity
    function setPaused(bool _paused) external pauserOnly {
        // Ensure we're actually changing the state before we do anything
        if (_paused == paused) {
            return;
        }
        if (paused) {
            require(msg.sender == ITruthMarketManager(owner()).owner(), "Only Protocol DAO can unpause");
        }
        ...
    }
    function proposeResolution(uint256 _outcome) external onlyOwner;

    function raiseDispute() external onlyOwner;

    function resolveMarketByCouncil(uint256 _outcome) external onlyOwner;

    function resetMarketByCouncil(bool _returnToOpenForResolution) external onlyOwner;

    function raiseEscalatedDispute() external onlyOwner;

    function resolveMarketByEscalation(uint256 _outcome) external onlyOwner;

    function resetMarketByEscalation() external onlyOwner;

    function setYesNoTokenCap(uint256 _yesNoTokenCap) external onlyOwner;

    function setEndOfTrading(uint256 _endOfTrading) external onlyOwner;

    function setFirstChallengePeriod(uint256 _firstChallengePeriod) external onlyOwner;

    function setSecondChallengePeriod(uint256 _secondChallengePeriod) external onlyOwner;
```

{% endcode %}

* Currently, all powers in TrueMarket, including result manipulation, market resets, time manipulation, and dispute bans, are concentrated in the Owner.<br>

  If the Owner's key is stolen, it can be used to block disputes, distorting market results. Furthermore, the market can be paused, tying up funds in the market.<br>

  Thus, if Trueo's owner authority is not divided, the Owner's private key could be stolen or maliciously used to harm general users.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://funarchy.gitbook.io/funarchy/pm-threat-modeling/test-result-dashboard/trueo-test-result.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
