Skip to content

Contracts & Audits

Everything GoMarket settles is on Solana, and every address below is independently verifiable. Nothing here requires trusting the backend — it never signs and never holds user funds.

ProgramIDPurposeDeployment
High Market (AMM)4Pe4r9FpaAtdU2fkyVLgNSKqhULXs6udKvDZf7Wm1yVELMSR prediction marketsMainnet
High Market Parlay3iZaRuW8D3kTneUb96rCe29hGYNmdpVMxiyW9YPd1oZAGoCombo multi-leg slipsDevnet
Markets (CLOB)GoFTc9SFqn2E5Z9UZ8reQL5NUSr8kNL7f5o2kXnqCmCBOrder-book settlementDevnet — unaudited

Verify any of them on Solscan or Solana Explorer.

The AMM is the only venue live on mainnet today. The CLOB and the parlay program run on devnet, and the CLOB’s audit has not started yet — see Audits. → Two Venues

Admin authority is a Squads V4 multisig. No single key can move funds or change program configuration.

AccountAddress
Multisig VaultGbCWm6q8KQdXvMSNTUAdT7yoT7yCmDTKiGfMRHDyRaXN
Multisig AccountCaqM2md2dWvfmMedtNTSRNQFm6zbBTWMQo6P7rFusYiS

This is what “the backend never signs” means concretely: market creation, resolution, cancellation, config changes and treasury movements are all multisig proposals, not API calls.

User collateral lives in per-market vault PDAs, derived from the market itself:

Vault seeds = ["vault", market_pda]

The program is the only authority over that vault. Winners claim directly on-chain (claim_winnings on the AMM, redeem on the CLOB) — the backend cannot pay, withhold, or redirect a payout. It indexes events such as SharesPurchased and MarketResolved for display only.

GoCombo stakes go into a single program-owned USDC vault:

Vault seeds = ["parlay_vault"]

Solvency is enforced on-chain, not operationally: total outstanding exposure can never exceed 80% of the vault balance, and admin withdrawals are capped at the unreserved remainder and timelocked 48 hours. → Vault & Solvency

Tournaments are the one place the model is deliberately split:

  • Off-chain: scoring and leaderboard computation.
  • On-chain: custody. Entry fees are escrowed in the Squads V4 multisig vault, and payouts are USDC transfers requiring multisig approval.

So the ranking is computed by the backend, but no payout happens on a single key’s say-so.

All engagements are with Zokyo.

ScopeDateStatus
High Market program (AMM)25 May 2026✅ Complete
High Market Parlay17 June 2026✅ Complete
Markets program (CLOB)—🕐 Scheduled — starting soon

Completed reports are published in Zokyo’s public GitHub repository.

The parlay audit shaped the risk controls documented in the GoCombo section. Parlay legs are priced from a one-hour time-weighted average rather than a spot price, with an explicit staleness guard: the untraded tail may be at most half the window, so a single trade can’t set the average.

That is the same accumulator the CLOB maintains. → CLOB Markets as Legs

  1. Find the market PDA — ["market", market_id: u64 LE] under the venue’s program.
  2. Check its owner to confirm which venue it belongs to. Both programs name the struct Market, so the Anchor discriminator is identical and won’t tell them apart.
  3. Derive the vault at ["vault", market_pda] and read its balance. That is the collateral actually backing the market.
  4. Derive the outcome mints at ["yes_mint", market_pda] and ["no_mint", market_pda], and check supply against the vault — the pair is fully collateralised by construction.
EnvironmentAPINotes
Productionhttps://prod-api.gomarket.io
Devhttps://dev-api.gomarket.io

Each has its own database. A market or tournament created against one is not visible on the other — a common source of “where did my market go.”

A legacy https://api.gomarket.io also exists.