Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[PT] NonKyc.io | Android | Jul2025

Date:

Aug 22, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the NonKYC team for the collaborative engagement that enabled the execution of this Pentest.

NonKYC.io is committed to providing a secure and intuitive platform tailored for trading small and mid-cap digital assets. Striving to ensure an efficient experience while protecting users and their data. NonKYC was designed entirely from the ground up by a team of experienced crypto engineers. This approach provides long-term scalability and a strong foundation for future growth.

Document

NameMobile Application Security Assessment Report for NonKYC
Audited ByIgor Samoilenko
Approved ByStephen Ajayi
Websitehttps://nonkyc.io/→
Changelog30/07/2025 - Preliminary Report
PlatformAndroid
LanguageKotlin
TagsMobile application
Methodologyhttps://hackenio.cc/pentest_methodology→

Review Scope

APK URLhttps://nonkyc.io/download/latestAPK→
Version1.0.7

Protect your dApp with insights like these.

Audit Summary

10Total Findings
9Resolved
1Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

System Overview

Founded in 2023, NonKyc.io is committed to providing a secure and intuitive platform tailored for trading small and mid-cap digital assets.

We strive to ensure an efficient experience while protecting users and their data.

NonKyc Exchange = Deposit, Trade, and Withdraw. Not your keys, Not your Coins, we don't beg for liquidity !

Findings

F-2025-1196Race Condition in Market Order Allows Over-Spending Beyond Account Balance
Status
fixed
Severity

Critical
F-2025-1197Account Takeover via Password Reset and OTP Brute-Forcing
Status
fixed
Severity

High
F-2025-1196Lack of Brute Force Protection on Login Endpoint
Status
fixed
Severity

Low
F-2025-1195User Enumeration via Differentiated Registration Error Responses
Status
fixed
Severity

Low
F-2025-1195Sensitive Information Stored in Plaintext Within App Sandbox
Status
fixed
Severity

Low
F-2025-1195Sensitive Information Leaked in Android System Logs
Status
fixed
Severity

Low
F-2025-1195Sensitive Information Visible in App Switcher Screenshots
Status
fixed
Severity

Low
F-2025-1196Third-Party Keyboards Allowed for Sensitive Input Fields
Status
accepted
Severity

Observation
F-2025-1196Lack of Code Obfuscation
Status
fixed
Severity

Observation
F-2025-1196Application Can Be Launched on Rooted Device and Emulator
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2025-1196Race Condition in Market Order Allows Over-Spending Beyond Account Balance
fixed

Critical
F-2025-1197Account Takeover via Password Reset and OTP Brute-Forcing
fixed

High
F-2025-1196Lack of Brute Force Protection on Login Endpoint
fixed

Low
F-2025-1195User Enumeration via Differentiated Registration Error Responses
fixed

Low
F-2025-1195Sensitive Information Stored in Plaintext Within App Sandbox
fixed

Low
F-2025-1195Sensitive Information Leaked in Android System Logs
fixed

Low
F-2025-1195Sensitive Information Visible in App Switcher Screenshots
fixed

Low
F-2025-1196Third-Party Keyboards Allowed for Sensitive Input Fields
accepted

Observation
F-2025-1196Lack of Code Obfuscation
fixed

Observation
F-2025-1196Application Can Be Launched on Rooted Device and Emulator
fixed

Observation
1-10 of 10 findings

Uncover findings like these to secure your project.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following:

Scope Details

PlatformAndroid
URLhttps://nonkyc.io/download/latestAPK→
Version1.0.7

Disclaimer