Islamic Finance Principles Assessment
Riba — Does PolySwarm involve interest?
PolySwarm's design does not rely on lending, borrowing, or fixed-interest instruments; income flows from marketplace fees and ICO-funded development rather than interest-bearing products. However, the staking mechanism's reward structure, which scales partly with stake size, introduces ambiguity that Muslim investors should weigh carefully. On balance, the protocol's revenue model itself appears free of overt riba.
Assessment: Moderate Riba
Score: 67.2/100
Our methodology examines 10 criteria to evaluate how well PolySwarm avoids interest-based mechanisms.
PolySwarm's revenue derives from ICO proceeds (allocated per the whitepaper to protocol development and modest office expenses) and ongoing marketplace bounty fees paid by users submitting files for analysis. There is no disclosed lending, borrowing, or interest-bearing treasury instrument in the sources reviewed. The company treasury funds programs like NectarNet, but no detail on treasury asset composition (e.g., holding of interest-bearing securities or cash-equivalents) is provided. As presented, the core revenue model is fee-for-service rather than interest-based income, though the absence of treasury disclosure leaves a minor transparency gap rather than a confirmed riba violation.
Engines earn NCT based on verdict accuracy, and telemetry providers earn based on tenure and staked amount, funded from daily fee pools and treasury allocations rather than a fixed interest schedule. This variable, performance-linked structure is closer to a permissible service/wage arrangement than to interest. However, because rewards partly scale with stake size rather than purely verified work, the underlying contract nature (service reward versus return on capital) is not fully resolved in available documentation. The whitepaper explicitly frames fees as discouraging speculation and rewarding honest participation, supporting a non-riba interpretation, but the stake-size component warrants continued scrutiny.
Gharar — How much uncertainty does PolySwarm involve?
PolySwarm carries a moderate degree of uncertainty, driven mainly by undisclosed audit status and ambiguous staking mechanics rather than by anonymity or vague purpose. The project's team, use case, and enterprise partnerships are well documented, which reduces gharar considerably. The absence of a verifiable smart-contract audit and unclear staking terms, however, are real and should not be minimized.
Assessment: Moderate Gharar (Material Uncertainty)
Score: 50.7/100
Our methodology examines 15 criteria including team transparency, audit quality, and governance.
The team is fully named and verifiable: CEO Steve Bassi, co-founders Ben Schmidt and Nick Davis, CTO Paul Makowski, and CCO Steve Laskowski, most with credentialed backgrounds tracing to Narf Industries and work for DARPA, the NSA, DHS, the US Navy, and eBay. An advisory board including a former Intel Security CIO is disclosed. Enterprise integrations (Microsoft, Verizon, eBay, CrowdStrike, SentinelOne, Splunk) support the project's legitimacy as a working cybersecurity marketplace. This level of named accountability substantially lowers gharar relative to anonymous or purpose-vague projects.
No named, dated third-party smart-contract security audit—such as a full CertiK, Trail of Bits, or Halborn report—could be found for PolySwarm/NCT; the only CertiK material located is a Skynet monitoring listing, not an audit. This is an unaudited-protocol gap and must be named plainly as a gharar concern for any investor. Additionally, lock-up periods, slashing conditions, and custody arrangements for staked NCT are not detailed in available sources, leaving practical risk terms unclear. Current usage also appears thin, with roughly $849K in 24h volume and only 62 active users over 7 days reported.
Maysir — Does PolySwarm involve gambling or speculation?
PolySwarm's core mechanism—paying engines for accurate malware verdicts—is a productive, work-based activity rather than a wagering scheme. Speculation exists insofar as NCT trades freely on secondary markets, as with any listed token. The protocol's own design discourages pure speculation, which supports a favorable reading, though market-level trading behavior remains a separate concern.
Assessment: Moderate Maysir (High Risk)
Score: 62.6/100
Our methodology examines 11 criteria to determine whether PolySwarm is a gambling instrument or a genuine economic tool.
PolySwarm channels staked NCT into a genuine service: competing threat-detection engines analyze real files and URLs, and payment is tied directly to verdict accuracy, creating a market for verifiable cybersecurity work. Telemetry providers are similarly rewarded for contributing useful data. This is analogous to a paid expert-consensus or bounty system rather than a bet on random outcomes. The whitepaper explicitly designs fees to "economically discourage speculation" by rewarding accuracy and redistributing fees to value-adding participants, reinforcing that the protocol's intended function is productive rather than chance-based.
Despite the protocol's productive design, NCT is a freely traded token subject to ordinary market speculation once listed on exchanges, and current trading activity (modest volume, low active-user counts) suggests speculative interest may currently outweigh operational usage. This speculative secondary-market behavior is common to nearly all tokens and is not unique to PolySwarm's own design, so it should not be treated as decisive against the protocol itself. Still, investors should recognize that today's market activity reflects more trading interest than deep marketplace engagement.
The Full 27-Point Screening
1. Legitimacy (4 criteria)
| Criterion | Score | Analysis |
|---|
| Team Transparency | 85/100 | Founders and key executives are named with verifiable, credentialed security-industry backgrounds traceable to specific prior employers. |
| Fraud & Scam Risk | 72/100 | No hack, rug-pull, or regulatory action against the project is documented, and the team is shown defending its own ICO against third-party scammers rather than perpetrating fraud. |
| Use Case Legitimacy | 85/100 | Sources describe a functioning cyber-threat-intelligence marketplace with cited enterprise integrations, indicating genuine utility rather than pure hype. |
| Ethical Practices | 90/100 | The protocol's own design is a cybersecurity threat-detection marketplace with no exposure to a prohibited industry. |
Summary: PolySwarm is led by named, credentialed cybersecurity professionals with traceable government and industry track records and no documented fraud or rug-pull history.
2. Project Operations (9 criteria)
| Criterion | Score | Analysis |
|---|
| Core Protocol Business | 90/100 | The base protocol's core business is cybersecurity threat intelligence, a permissible sector. |
| Transaction Fees | 72/100 | Fees are collected on spam-prone transactions and redistributed to active contributing participants rather than extracted as interest-like rent. |
| Treasury Assets | 45/100 (low evidence) | Sources mention a company treasury funding rewards but give no detail on the treasury's asset composition, so interest-bearing holdings cannot be ruled in or out. |
| Revenue Model | 72/100 | Revenue comes from ICO proceeds allocated to development and from marketplace fees, with no interest-based revenue described. |
| Transparency | 45/100 | Detailed public documentation and a whitepaper exist, but no explicit statement of open-source code was found in the sources. |
| Governance | 25/100 | The whitepaper explicitly grants PolySwarm Pte. Ltd. sole discretion over portions of token allocation, indicating centralized rather than decentralized governance. |
| Launch Fairness | 45/100 | The token was distributed via a 2018 ICO with full immediate release and no vesting, but a majority went to presale investors rather than a broad fair launch. |
| Token Distribution | 35/100 | Documented allocation shows 60% to presale investors and 23% to the team/experts, leaving a comparatively small public-sale share, indicating concentration. |
| Speculation/Utility Ratio | 55/100 | The project shows genuine marketplace utility and enterprise use, but small reported trading/user volumes suggest speculative trading still plays a meaningful role. |
Summary: The protocol is a decentralized threat-intelligence marketplace with fee redistribution to active participants, but token distribution was presale-heavy and governance is centralized in the operating company.
3. Financial Health (4 criteria)
| Criterion | Score | Analysis |
|---|
| Protocol Revenue | 72/100 | Protocol revenue is generated from marketplace fees and token-sale proceeds rather than any interest-based source described in the sources. |
| Financial Status | 35/100 | Reported activity metrics (small daily volume and very low active-user counts) point to a small, currently subdued project rather than a robust, stable one. |
| Interest Assessment | 78/100 | The base protocol's only capital mechanism is work-based staking on verdicts/telemetry, with no lending or borrowing function described. |
| Audit Quality | 15/100 | No named, dated third-party smart-contract security audit report for PolySwarm/NCT appears in the sources; the CertiK page found is a monitoring listing, not an audit. |
Summary: Revenue comes from marketplace fees and token-sale proceeds with no protocol-level lending, but the project shows modest current market activity and no confirmed third-party smart-contract audit was found.
4. Token Economics (5 criteria)
| Criterion | Score | Analysis |
|---|
| Token Purpose | 85/100 | NCT is used functionally for marketplace bounties, fees, and staking rather than serving as a speculative meme token by design. |
| Governance Rights | N/A | NCT is explicitly documented as a utility token with no governance-rights feature, and this absence is neutral for a marketplace-access token rather than a compliance concern. |
| Rewards Distribution | 78/100 | Rewards are variable, tied to verdict accuracy, provider tenure, and stake weighting, drawn from reward pools rather than a fixed guaranteed rate. |
| Speculation Controls | 60/100 | The whitepaper explicitly states the fee/reward design aims to discourage pure speculation by rewarding honest participation, though market-wide speculative trading is not separately controlled. |
| Asset Backing | 55/100 | The token's value is tied to marketplace utility and fee flows, but no disclosed reserve of assets backing it was found in the sources. |
Summary: NCT is a functional utility token with variable, performance-based rewards and some explicit anti-speculation intent, though its asset backing is utility rather than any disclosed reserve.
5. Staking Mechanism (5 criteria)
| Criterion | Score | Analysis |
|---|
| Mechanism Type | 55/100 | A native staking mechanism for engines and telemetry providers is described, but lock-up terms and custody details are not specified in the sources. |
| Islamic Contract Classification | 45/100 | Rewards are tied partly to work performed (verdict accuracy, telemetry contribution) but also scale with the amount staked, leaving the contract's classification between service-reward and stake-based return unresolved. |
| Rewards Structure | 65/100 | Reward pools are explicitly described as variable, driven by performance, tenure and stake weighting rather than a fixed rate. |
| Documentation | 50/100 | The whitepaper describes reward formulas at a technical level, but comprehensive risk/lock-up disclosure is not evident in the sources. |
| Shariah Alignment | 42/100 | The stake-weighted component of rewards leaves an unresolved question about whether the mechanism is a pure task-reward or partly a return on capital, which is a live Shariah consideration. |
Summary: PolySwarm has a native, non-consensus staking mechanism tying rewards to verdict accuracy and stake weighting, but lock-up, custody and its precise Islamic-contract classification remain undocumented or unresolved in the sources.
Overall Assessment: PolySwarm presents as a genuine, transparently-led cybersecurity utility project with a reasonable fee and reward design, but centralized governance, concentrated initial distribution, an unconfirmed audit trail, and an unresolved staking-classification question leave several Shariah-relevant gaps that the sources do not fully close.