<- ALL CASE STUDIES
Phage Security x Trepa

Trepa

Lifting critical invariants on-chain ahead of mainnet. 15 findings across the Anchor program and resolver backend, 14 fixed and verified.

SOLANA + TS/RS BACKENDPREDICTION GAMEAPR 2026
TOTAL FINDINGS
15
HIGH RESOLVED
2 / 2
MEDIUM RESOLVED
6 / 6
DURATION
5 days

About the client

Trepa is a Solana-based short-horizon forecasting game (Flash Pools) where every player pays the same fixed entry fee and submits a numeric price estimate for an asset, starting with Bitcoin.

After settlement, each player's error is compared to the field median: closer estimates win their entry back and share a prize pool funded from losers' entries (after a platform take), with accuracy-weighted splits subject to per-round profit caps.

Players also earn a precision score and can qualify for streak mechanics, with a portion of the take flowing to a streak accumulator.

"Communication, coordination, and the overall audit process were excellent. The team presented well-structured findings and consistently supported their conclusions with detailed logs and reproducible tests."

"Their willingness to go beyond the defined scope made me realize their strong commitment to quality and added significant value to us."

LEON MEKA, LEAD DEVELOPER AT TREPA

The team on this audit

Pyro
Pyro
LEAD RESEARCHER

Lead Security Researcher at Sherlock. Over 100 audits performed and 500+ bugs found.

YanecaB
YanecaB
RESEARCHER

A promising Security Researcher. In the space for ~1 year, and showing remarkable results.

Kyan
Kyan
RESEARCHER

Specializes in Solana smart contracts. #1 cumulative ranking on Solana Audit Arena.

Ishwar Kumar
Ishwar Kumar
RESEARCHER

Strong AppSec background, active in bug bounties. Experienced in Web2 audits, primarily TypeScript.

Zuhaibmohd
Zuhaibmohd
RESEARCHER

Independent EVM + Solana Security Researcher. 50+ protocol reviews, 300+ impactful vulnerabilities.

High severity issues

H-01

Backend oracle finalizes pools with a stale price from a capped aggregate-trades page

IMPACT

The 120-second BTCUSDT lookup was capped at 1000 rows by the data provider, returning the oldest page instead of the newest. The stale page-tail price fed straight into pool resolution, producing wrong winners and a valid Merkle root for an economically incorrect outcome.

FIX

Replaced the wide window query with a direct nearest-before lookup (endTime: outcomeMs - 1, limit: 1) and added a drift bound, eliminating the truncation class entirely.

H-02

Streak reward claim transaction binding bypass enables double payout

IMPACT

The submit endpoint trusted the client-supplied streak_reward_id without verifying it matched the signed transaction. An attacker could swap the reward ID after signing to mark a different reward claimed in the DB while the chain executed the original payout, leaving the original reward repeatedly claimable and draining the streak pool.

FIX

The signed proof is now bound to a context object containing streak_reward_id and wallet_address. The submit endpoint re-verifies that context before updating is_claimed, so swapping the reward ID after signing now fails verification.

Plus 6 medium and 7 low severity findings. All documented in the full report.

Why Phage Security

Trepa's protocol splits its logic between a minimal Anchor program and a heavy backend, so it needed researchers comfortable on both sides of that boundary. We lifted the critical invariants on-chain and made every money-moving flow idempotent. Trepa shipped fixes for 14 of 15 findings within the remediation window, ready for mainnet.