Introduction
We express our gratitude to the NonKYC team for the collaborative engagement that enabled the execution of this Pentest.
NonKYC.io is committed to providing a secure and intuitive platform tailored for trading small and mid-cap digital assets. Striving to ensure an efficient experience while protecting users and their data. NonKYC was designed entirely from the ground up by a team of experienced crypto engineers. This approach provides long-term scalability and a strong foundation for future growth.
Document | |
|---|---|
| Name | Mobile Application Security Assessment Report for NonKYC |
| Audited By | Igor Samoilenko |
| Approved By | Stephen Ajayi |
| Website | https://nonkyc.io/→ |
| Changelog | 30/07/2025 - Preliminary Report |
| Platform | Android |
| Language | Kotlin |
| Tags | Mobile application |
| Methodology | https://hackenio.cc/pentest_methodology→ |
Document
- Name
- Mobile Application Security Assessment Report for NonKYC
- Audited By
- Igor Samoilenko
- Approved By
- Stephen Ajayi
- Website
- https://nonkyc.io/→
- Changelog
- 30/07/2025 - Preliminary Report
- Platform
- Android
- Language
- Kotlin
- Tags
- Mobile application
- Methodology
- https://hackenio.cc/pentest_methodology→
Review Scope | |
|---|---|
| APK URL | https://nonkyc.io/download/latestAPK→ |
| Version | 1.0.7 |
Review Scope
- Version
- 1.0.7
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
System Overview
Founded in 2023, NonKyc.io is committed to providing a secure and intuitive platform tailored for trading small and mid-cap digital assets.
We strive to ensure an efficient experience while protecting users and their data.
NonKyc Exchange = Deposit, Trade, and Withdraw. Not your keys, Not your Coins, we don't beg for liquidity !
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2025-1196 | Race Condition in Market Order Allows Over-Spending Beyond Account Balance | fixed | Critical | |
| F-2025-1197 | Account Takeover via Password Reset and OTP Brute-Forcing | fixed | High | |
| F-2025-1196 | Lack of Brute Force Protection on Login Endpoint | fixed | Low | |
| F-2025-1195 | User Enumeration via Differentiated Registration Error Responses | fixed | Low | |
| F-2025-1195 | Sensitive Information Stored in Plaintext Within App Sandbox | fixed | Low | |
| F-2025-1195 | Sensitive Information Leaked in Android System Logs | fixed | Low | |
| F-2025-1195 | Sensitive Information Visible in App Switcher Screenshots | fixed | Low | |
| F-2025-1196 | Third-Party Keyboards Allowed for Sensitive Input Fields | accepted | Observation | |
| F-2025-1196 | Lack of Code Obfuscation | fixed | Observation | |
| F-2025-1196 | Application Can Be Launched on Rooted Device and Emulator | fixed | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes the following:
Scope Details | |
|---|---|
| Platform | Android |
| URL | https://nonkyc.io/download/latestAPK→ |
| Version | 1.0.7 |
Scope Details
- Platform
- Android
- Version
- 1.0.7