Skip to main content

Permissions + Threat Notes

HISTORICAL - describes the abandoned tournament / forecast-AMM design

This page documents the pre-migration architecture (TournamentManager, matchday-gated trading, on-chain ForecastMarket AMM). None of it exists in the current system: tournaments were replaced by instant 1v1 prestige-ladder battles, prediction markets are off-chain parimutuel in non-redeemable in-game currency, and the contract suite is Charter v2 + the Uniswap v4 venue. For current rules see the Platform Rules page; for current architecture see the repo's docs/architecture/ and my-dapp-contracts/docs/ARCHITECTURE.md.

  • Privileged actions should be owned by a multisig with clear operational SOPs.
  • A dedicated Guardian role should be able to pause both token and forecasting flows during incidents.
  • Backend signer compromise is a critical risk; treat automation keys as production-tier secrets.
  • MEV and slippage risk exists across all three AMM domains; enforce user slippage bounds and monitor sandwich patterns.
  • Oracle risk primarily affects fallback forecast resolution and TWAP-dependent checks; deterministic TournamentManager results are preferred.
  • Document pause criteria, incident runbooks, and all privileged-call audit trails.