The Polymarket CTF Exchange v2 is a Conditional Tokens Framework (CTF) trading protocol that enables operator-controlled order matching for binary outcome markets. The system is composed of three subsystems: an exchange that matches signed orders and settles trades, a set of adapter contracts that bridge between the exchange's collateral token and the CTF, and a collateral layer that wraps USDC and USDC.e into a unified PolymarketCollateralToken (PMCT). Off-chain infrastructure handles order collection, matching, and submission, while on-chain contracts enforce settlement correctness, fee validation, and access control. The exchange is centered on the `CTFExchange` contract, which inherits from a chain of mixin contracts, the most important ones being: `Trading` for order matching and settlement, `Fees` for fee receiver management, and rate validation and `Signatures` for preapproved and regular signature verification across four signer types (`EOA`, `POLY_PROXY`, `POLY_GNOSIS_SAFE` and `POLY_1271`). The exchange supports three order matching flows: - **COMPLEMENTARY** matches a BUY taker against SELL makers (or vice versa) on the same outcome token, settling with direct peer-to-peer transfers. - **MINT** matches a BUY taker against BUY makers on COMPLEMENTARY outcomes (e.g. YES and NO), pooling collateral in the exchange and minting both outcome tokens for distribution. - **MERGE** matches a SELL taker against SELL makers, collecting both outcome tokens and merging them back into collateral. When a single `matchOrders()` call includes COMPLEMENTARY makers together with one or more non-COMPLEMENTARY makers, that mixed flow is supported. For example, a BUY YES taker can match SELL YES makers through the COMPLEMENTARY transfer path while also matching BUY NO makers through MINT in the same call. There is also an all COMPLEMENTARY shortcut when every maker is COMPLEMENTARY. A single call does not support matching unrelated orders such as MINT and MERGE together. The permissioned and permissionless on-ramps are the two main entry points into the onboarding liquidity to the CTF exchange. Together they control which and how many stablecoins users and partners can wrap into PMCT and unwrap again into USDC and USDC.e, with permissionless flows and a permissioned path for balancing the underlying stablecoin supply. PMCT itself serves as the shared collateral token across the system, abstracting over USDC and USDC.e so the exchange and its surrounding infrastructure can operate on a single asset. The adapter layer sits between the exchange and the CTF to make CTF settlement compatible with PMCT. It converts between PMCT and the USDC.e collateral required by the CTF and supports both regular CTF markets and negative risk markets (multi-outcome) through separate adapters. Compared with CTF Exchange v1, v2 adds preapproval, delayed user pause, builder/metadata fields, and PMCT adapter-based collateral flow, while removing nonce-based cancellation and older fill-style execution paths. These updates improve flexibility and gas efficiency, but also increase reliance on operator and off-chain matching logic, and led to regressions identified in this report, including removed complement-market validation in non-complementary matching (POL-EX-4) and unchecked arithmetic overflow behavior in settlement math (POL-EX-5). The audit found no high severity issues, with one medium severity finding three low severity findings and one informational severity finding identified. The medium severity finding, POL-EX-1, is that inconsistent supplied fill inputs in the COMPLEMENTARY settlement path can overcharge or underfill takers because status updates are not tied to actual executed transfers. The test suite comprises 227 tests across 23 test suites. It includes integration tests that exercise full `matchOrders()` flows with balance assertions, adapter-specific matching tests, and gas snapshot benchmarks across all flow types and different maker counts.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | - | - | - | - | 0 |
Acknowledged | - | - | - | - | 0 |
Fixed | 4 | 1 | - | - | 5 |
| Total | 4 | 1 | 0 | 0 | 5 |
| # | File Name |
|---|---|
| 1 | Scope not recorded here: see the report |