The Hacken 2025 Yearly Security ReportCovers major Web3 breaches, their root causes, prevention insights, and key regulatory trends for 2026.
Learn more

Audit name:

[PT] CoinDepo | Web+API | Jun2025

Date:

Jul 22, 2025

Table of Content

Introduction
Audit Summary
System Overview
Findings
Appendix 1. Severity Definitions
Appendix 2. Scope
Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the CoinDepo team for the collaborative engagement that enabled the execution of this Pentest.

CoinDepo is a centralized crypto-earning platform launched in 2021. It allows you to deposit major cryptocurrencies and stablecoins into interest-bearing (staking/savings) accounts, offering attractive annual yields ranging from 12 % to 24 %—with stablecoins typically at the higher end

Document

NamePentest and Security Analysis Report for CoinDepo
Audited By Bogdan Bodisteanu
Approved ByStephen Ajayi
Websitecoindepo.com
Changelog23/06/2025 - Preliminary Report
Changelog31/07/2025 - Final Report
PlatformWeb Application & API
LanguagePython , Angular
Methodologyhttps://hackenio.cc/dApp_methodology
  • Document

    Name
    Pentest and Security Analysis Report for CoinDepo
    Audited By
    Bogdan Bodisteanu
    Approved By
    Stephen Ajayi
    Website
    coindepo.com
    Changelog
    23/06/2025 - Preliminary Report
    Changelog
    31/07/2025 - Final Report
    Platform
    Web Application & API
    Language
    Python , Angular

Review Scope

Web Applicationcoindepo.com,
APIapp.coindepo.com
  • Review Scope

    Web Application
    coindepo.com,
    API
    app.coindepo.com

Protect your dApp with insights like these.

Audit Summary

7Total Findings
6Resolved
1Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

System Overview

Earn passive income by depositing crypto or stablecoins.

🔹 Flexible Term Accounts: Withdraw anytime, with interest paid daily, weekly, or monthly.

🔹 Fixed Term Accounts: Lock assets for up to 12 months for higher returns.

🔹 Interest Rates: Up to 24% APR on stablecoins, and up to 18% on cryptocurrencies.

🔹 Compound Interest: Option to reinvest interest for increased yield.

KYC & Compliance

Identity verification required before using interest services.

Compliance with EU regulations, GDPR, and anti-money laundering (AML) standards.

Upcoming Services

Planned features under development:

Crypto Credit Card — use earned interest as a credit line.

Unsecured Crypto Loans — small loans without collateral.

Instant Swaps — swap assets directly within the platform.

EU Fiat Integration — deposit and withdraw in EUR via SEPA.

COINDEPO Token (CDT) — loyalty token for extra benefits (launch expected 2025).

Findings

Code
Title
Status
Severity
F-2025-1098Unauthorized Deposit Plan Creation Leading to Balance Manipulation
fixed

Critical
F-2025-1285IDOR via Username Parameter allows complete account takeover (ATO) [DualDefense]
fixed

Critical
F-2025-1088Exposed Hardcoded Credentials
fixed

High
F-2025-1111Insecure Implementation of Secret Parameter in Account Confirmation and Password Reset Flows
fixed

Medium
F-2025-1094Improper Trust of X-Forwarded-For and X-Forwarded-Host
fixed

Medium
F-2025-1111Exposure of Administrative Endpoints
fixed

Observation
F-2025-1093User Enumeration via Registration Endpoint
accepted

Observation
1-7 of 7 findings

Uncover findings like these to secure your project.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

Scope Details

Web Applicationcoindepo.com
APIapp.coindepo.com
Whitepaperhttps://hackenio.cc/hacken-methodologies

Disclaimer