The Hacken 2025 Yearly Security ReportCovers major Web3 breaches, their root causes, prevention insights, and key regulatory trends for 2026.
Learn more

Audit name:

[PT] Ourbit | iOS App | Sep2025

Date:

Sep 25, 2025

Table of Content

Introduction
Audit Summary
System Overview
Findings
Appendix 1. Severity Definitions
Appendix 2. Scope
Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Ourbit team for the collaborative engagement that enabled the execution of this Pentest.

Ourbit for iOS ("Ourbit: Buy Bitcoin & Crypto") is the exchange’s official mobile app for buying, selling, and managing digital assets in a centralized trading environment. It focuses on a simple, user-friendly experience while giving access to core exchange features - spot markets today, with the broader Ourbit platform highlighting futures, frequent listings, and a “one-stop” approach to crypto trading.

Document

NamePentest and Security Analysis Report for Ourbit
Audited By
Approved By
Websitehttps://www.ourbit.com/
Changelog11/09/2025 - Preliminary Report
Changelog25/09/2025 -Final Report
PlatformiOS
LanguageSwift
TagsMobile Application
Methodologyhttps://hackenio.cc/pentest_methodology

Protect your dApp with insights like these.

Audit Summary

5Total Findings
1Resolved
4Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

System Overview

Ourbit for iOS is the mobile frontend to the Ourbit exchange, built to make account access and trading fast on the go. The app streamlines signup and signin with passkeys and Face ID, surfaces live market data and charts, and keeps your portfolio, watchlists, and price alerts close at hand - including Lock Screen updates via Live Activities. Push notifications keep you in the loop, while localization and a clean UI reduce exchange level complexity.

Inside the app, the primary flows center on getting users trading quickly and safely: creating or importing an account, securing it with biometrics, depositing crypto using address/QR workflows, and executing spot buy/sell orders for popular assets.

Findings

Code
Title
Status
Severity
F-2025-1280Bypassable jailbreak detection
fixed

Low
F-2025-1281Missing Certificate Pinning
accepted

Observation
F-2025-1280Insecure network configuration via NSAllowsArbitraryLoads (ATS Disabled)
accepted

Observation
F-2025-1280Dart Observatory exposed in production via NSBonjourServices
accepted

Observation
F-2025-1280Debug Information Present in Release Build
accepted

Observation
1-5 of 5 findings

Uncover findings like these to secure your project.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following:

Assets in Scope

iOS Ourbit Application - iOS Ourbit Application

Disclaimer

Ourbit audit by Hacken