H1 2025 Web3 Security Report$3.1B in losses, DeFi hit hardest, AI threats on the rise
Read the full report
  • Hacken
  • Audits
  • bitunix
  • [PT] Bitunix | Web+API | Apr2025

Audit name:

[PT] Bitunix | Web+API | Apr2025

Date:

Jun 12, 2025

Table of Content

Introduction
Audit Summary
System Overview
Findings
Appendix 1. Severity Definitions
Appendix 2. Scope
Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Bitunix  team for the collaborative engagement that enabled the execution of this Pentest.Bitunix team for the collaborative engagement that enabled the execution of this dApp Security Assessment.

Bitunix is ​​a global cryptocurrency derivatives trading platform founded in November 2021. The company is registered in Singapore and has expanded its presence in the Middle East. Future plans include opening branches in the Philippines, Japan, and the UK.

Since its official launch in October 2022, Bitunix has attracted over 1,000,000 registered users and generated a combined daily trading volume of over $1 billion on the platform. Importantly, Bitunix received its US MSB license in December 2022, Canada MSB license in January 2024, and Philippines VASP license in February 2024. Additionally, the company is currently in the process of obtaining licenses in other countries.

Document

NamePentest and Security Analysis Report for Bitunix
Audited By Bogdan Bodisteanu
Approved ByStephen Ajayi
Websitebitunix.com
Changelog15/05/2025 - Preliminary Report
Changelog05/06/2025 - Final Report
LanguageNuxt.js,Vue.js
PlatformWEB, API
TagsPentest, Black-Box
Methodologyhttps://hackenio.cc/dApp_methodology
  • Document

    Name
    Pentest and Security Analysis Report for Bitunix
    Audited By
    Bogdan Bodisteanu
    Approved By
    Stephen Ajayi
    Website
    bitunix.com
    Changelog
    15/05/2025 - Preliminary Report
    Changelog
    05/06/2025 - Final Report
    Language
    Nuxt.js,Vue.js
    Platform
    WEB, API
    Tags
    Pentest, Black-Box

Protect your dApp with insights like these.

Audit Summary

3Total Findings
2Resolved
1Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

System Overview

Real-Time Trading Interface:

Trade across spot and derivatives markets with live market data, depth charts, and real-time order execution. The platform ensures low latency and high accuracy for order placement and trade management.

Comprehensive Account Dashboard:

Users gain centralized access to portfolio overviews, transaction and trade history, PnL summaries, asset balances, and fee analytics—all in a responsive and intuitive dashboard layout.

Advanced Security Measures:

The platform enforces secure authentication via two-factor authentication (2FA), email/SMS verifications, session timeout policies, and granular API key permissions to protect user assets and data.

Modern, Responsive UI:

The interface offers multi-language support, customizable layouts, price alerts, execution notifications, and seamless interaction on desktop and tablet devices, ensuring a smooth user experience.

Findings

Code
Title
Status
Severity
F-2025-1015Original IP Adresses
fixed

Medium
F-2025-1040User Enumeration via Password Reset Endpoint
fixed

Observation
F-2025-1015Missing HTTP Strict Transport Security (HSTS) Header
accepted

Observation
1-3 of 3 findings

Uncover findings like these to secure your project.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

Assets in Scope

bitunix.com - bitunix.com
api.bitunix.com - api.bitunix.com

Disclaimer