Islamic Finance Principles Assessment
Riba — Does Forta involve interest?
Forta's core design does not rely on interest-bearing lending or fixed-return instruments. Revenue comes from subscription fees for threat-intelligence feeds and Firewall usage, and staking rewards are variable and activity-linked rather than fixed. For Muslim investors, the protocol's income and reward mechanics are structurally closer to permissible fee-for-service and profit-sharing models than to riba.
Assessment: Moderate Riba
Score: 69.1/100
Our methodology examines 10 criteria to evaluate how well Forta avoids interest-based mechanisms.
Forta generates revenue through subscription fees for its alert/data feeds and Firewall service, explicitly described as demand-driven rather than treasury-subsidized. These fees reward developers and node operators producing detection data, and flow into a Foundation-controlled treasury whose exact composition is not fully disclosed beyond holding a large share (~41%) of native FORT tokens. There is no evidence of the treasury holding conventional interest-bearing instruments, and no lending/borrowing function exists in the base protocol itself, though an unrelated third-party site ("finforta.com") advertising interest rates could not be confirmed as affiliated with Forta Network.
Staking rewards are distributed proportionally based on a staker's share in a given Scanner Pool or bot, funded by network fee revenue and node incentive pools rather than fixed token emissions. The official site cites an "estimated" ~7% yield, language suggesting a variable, performance-linked figure tied to actual network usage rather than a guaranteed interest rate. This activity-dependent structure, where returns fluctuate with real demand for security services, is more consistent with a profit-sharing arrangement than with riba-based fixed lending returns, though the precise rate-setting mechanics are not fully detailed in available documentation.
Gharar — How much uncertainty does Forta involve?
Forta carries comparatively low uncertainty for a DeFi-adjacent project, given its named leadership, institutional backers, and multiple independent audits. Some ambiguity remains around treasury composition and long-term governance concentration. On balance, the disclosed information is substantial enough that gharar concerns are moderate rather than severe.
Assessment: Moderate Gharar (Material Uncertainty)
Score: 66.1/100
Our methodology examines 15 criteria including team transparency, audit quality, and governance.
Forta is not an anonymous project: it was incubated by OpenZeppelin, a security firm operating since 2015, and is governed by a named Council including the CEO/CTO of OpenZeppelin, UMA's co-founder, Celestia's general counsel, and Nethermind's founder. It raised $23M from a16z, Coinbase Ventures, and Blockchain Capital. Code is open-source on GitHub with public documentation. This level of named accountability and transparency substantially reduces informational uncertainty compared to typical anonymous-team crypto projects, though treasury asset composition beyond token holdings is not fully itemized.
Forta has been audited repeatedly and by recognized firms: OpenZeppelin's Protocol Audit (February 2022), Consensys Diligence's Delegated Staking audit (November 2022), MixBytes' slashing-mechanism review (September 2022), Dedalo's airdrop/web/scan-node assessments (2022), and OpenZeppelin's Staking Vault audit (March 2024). Findings, including a resolved medium-severity issue where the slashing process could theoretically be reverted, were addressed. This is a well-documented audit history for the sector, meaning the gharar concern here is low; risk disclosure around staking lock-ups (via non-transferable "inactive" ERC-1155 shares) is also reasonably clear.
Maysir — Does Forta involve gambling or speculation?
Forta's function is security monitoring, not wagering on price movements or chance-based outcomes. Its value derives from real usage by dozens of protocols requiring threat detection, distinguishing it from speculative or zero-sum instruments. The primary maysir-adjacent risk lies not in the protocol's design but in ordinary secondary-market trading behavior common to most listed tokens.
Assessment: Moderate Maysir (High Risk)
Score: 66.5/100
Our methodology examines 11 criteria to determine whether Forta is a gambling instrument or a genuine economic tool.
Forta provides a genuine service: real-time detection of rug pulls, phishing, exploits, and anomalous behavior across DeFi, NFT, governance, and bridge activity, protecting over 40 major protocols and roughly half of top-30 DeFi TVL. Node operators and bot developers are compensated for producing useful security data, and subscribers pay fees for consuming that intelligence. This fee-for-service model, tied to measurable, productive output rather than chance or pure price speculation, is structurally distinct from gambling and supports a maysir-light characterization of the core protocol.
Weighing the evidence, Forta's protocol-level activity — staking, fee generation, governance voting on concrete proposals like FP-8's supply cap — reflects utility-driven engagement rather than gambling mechanics. The main caution is that, like most liquid tokens, FORT can be traded speculatively on secondary markets independent of its underlying utility; such trading behavior by third parties is not determinative of the protocol's own design or ruling. Combined with a VC-heavy initial distribution that may encourage short-term flipping by early insiders once vesting unlocks occur, this warrants some investor caution, though it does not make the protocol itself a maysir instrument.
The Full 27-Point Screening
1. Legitimacy (4 criteria)
| Criterion | Score | Analysis |
|---|
| Team Transparency | 85/100 | Team and governance council members are named, credentialed and traceable, incubated publicly by OpenZeppelin. |
| Fraud & Scam Risk | 78/100 | No fraud, hack, or rug-pull indicators against Forta itself are reported; the project's own function is fraud detection for others. |
| Use Case Legitimacy | 90/100 | Forta provides a documented, widely-used real-time security monitoring service across dozens of major protocols. |
| Ethical Practices | 85/100 | The protocol's own design is security/threat-detection infrastructure with no haram-industry orientation; any misuse by protected third parties is not attributable to Forta's own design. |
Summary: Forta is a credibly-backed, named-team security infrastructure project incubated by OpenZeppelin with no fraud or rug-pull indicators found against it.
2. Project Operations (9 criteria)
| Criterion | Score | Analysis |
|---|
| Core Protocol Business | 90/100 | The base protocol's core business is blockchain security monitoring, a neutral, non-prohibited sector. |
| Transaction Fees | 78/100 | Subscription/data fees reward bot developers and were adopted via community governance rather than functioning as interest extraction. |
| Treasury Assets | 65/100 | Treasury is known to hold a large share of native FORT tokens, but full treasury composition and any interest-bearing holdings are not disclosed in sources. |
| Revenue Model | 82/100 | Revenue comes from subscription and Firewall usage fees tied to real demand, not interest-based lending. |
| Transparency | 88/100 | Code is open-source on GitHub, documentation is extensive, and multiple audit reports are publicly linked. |
| Governance | 55/100 | Governance operates through community-voted proposals and a named council, but the Foundation retains over 40% of token supply, indicating real centralisation. |
| Launch Fairness | 30/100 | Token distribution shows heavy backer/VC/insider allocation (over 60% combined) against only a 2.9–4% public airdrop. |
| Token Distribution | 35/100 | Distribution data confirms concentration among backers, core contributors and OpenZeppelin, with multi-year vesting for insiders. |
| Speculation/Utility Ratio | 65/100 | Documented utility functions (staking, fees, governance) suggest utility relevance, but sources provide no data comparing trading/speculative activity to actual usage. |
Summary: The base protocol is a decentralized threat-detection network with open-source code and fee-based rewards, but launch and distribution were heavily weighted toward VCs and insiders rather than the broader community.
3. Financial Health (4 criteria)
| Criterion | Score | Analysis |
|---|
| Protocol Revenue | 82/100 | Protocol revenue is fee-based from real usage rather than riba-style lending income. |
| Financial Status | 62/100 | Broad adoption and VC backing are documented, but no formal financial statements or stability metrics are given. |
| Interest Assessment | 82/100 | The base protocol's documented function is security monitoring with no lending/borrowing at the protocol level; an unrelated third-party lending page found in search could not be confirmed as part of Forta. |
| Audit Quality | 88/100 | Multiple named audit firms (OpenZeppelin, Consensys Diligence, MixBytes, Dedalo) with specific dates and largely-resolved findings are documented. |
Summary: Forta generates fee-based revenue from real usage and has been audited multiple times by named firms, though full treasury composition and financial stability details remain undisclosed.
4. Token Economics (5 criteria)
| Criterion | Score | Analysis |
|---|
| Token Purpose | 85/100 | FORT is documented as a functional utility/governance token used for staking, fees and voting, not a meme asset. |
| Governance Rights | 80/100 | Holders vote on concrete Forta Improvement Proposals with documented outcomes (fee adoption, minting removal). |
| Rewards Distribution | 60/100 | Staking rewards are share-proportional and fee-funded, described as "estimated" yield, but the precise rate-setting mechanism is not detailed. |
| Speculation Controls | 60/100 | Multi-year vesting cliffs and a hard supply cap provide some speculation mitigation, though no other controls are described. |
| Asset Backing | 55/100 | The token is not asset-backed; value is inferred to derive from network utility and governance rights rather than any explicit backing statement. |
Summary: FORT functions as a genuine utility and governance token with a capped supply and vesting-based anti-speculation elements, though its precise reward-rate mechanics are not fully detailed.
5. Staking Mechanism (5 criteria)
| Criterion | Score | Analysis |
|---|
| Mechanism Type | 68/100 | Delegated staking via documented smart contracts with share tokens and a lock-up/withdrawal period is described in official sources. |
| Islamic Contract Classification | 42/100 (low evidence) | Sources describe reward-sharing mechanics but never discuss or classify the staking arrangement under any Islamic contract type, leaving its classification unresolved. |
| Rewards Structure | 55/100 | Rewards are tied to stake share and network fee revenue (suggesting variability), but an "estimated" fixed-sounding percentage figure is also quoted, creating ambiguity. |
| Documentation | 85/100 | Staking mechanics, audits, and terms are documented across official docs and third-party audit reports. |
| Shariah Alignment | 50/100 (low evidence) | No source addresses Shariah alignment directly; the presence of slashing, lock-ups and an "estimated" reward rate leaves core gharar/riba questions unexamined in these materials. |
Summary: Forta offers a documented, audited delegated-staking system with lock-ups and slashing, but the sources do not address its Islamic contract classification or resolve associated gharar questions.
Overall Assessment: Forta appears to be a legitimate, utility-driven security protocol with reasonable transparency and audit coverage, but insider-weighted distribution and unresolved Shariah classification of its staking rewards remain open questions.