Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[PT] Pionex | iOS | Oct2024

Date:

Nov 25, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Pionex team for the collaborative engagement that enabled the execution of this İOS mobile application security analysis.

Document

NameiOS Application Security Analysis Report for Pionex
Audited ByEce Orsel
Approved ByStephen Ajayi
Websitehttps://www.pionex.com/→
Changelog30/10/2024 - Preliminary Report
Changelog25/11/2024 - Final Report
PlatformiOS
LanguageSwift
Methodologyhttps://hackenio.cc/pentest_methodology→

Review Scope

Identifierorg.pionex
Version/Build3.0.6/30006006
Retest Version/Build3.0.8/30008012
  • Review Scope

    Identifier
    org.pionex
    Version/Build
    3.0.6/30006006
    Retest Version/Build
    3.0.8/30008012

Protect your dApp with insights like these.

Audit Summary

8Total Findings
6Resolved
2Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Threat Modeling and Attack Scenarios

As part of the security assessment for the iOS mobile application, this threat modeling report analyzes potential vulnerabilities specific to mobile app architecture, including insecure data storage, reverse engineering risks, and improper session management. The objective is to identify possible attack vectors, assess the associated risks, and recommend mitigations to enhance the application's security posture, safeguarding it against adversarial threats and ensuring the protection of sensitive user data and app functionality.

1\. Insecure Data Storage : Sensitive information (e.g., tokens, credentials) may be stored in insecure locations such as NSUserDefaults, exposing it to attackers with physical access or access via malware.

  • Potential Impact: If compromised, attackers can retrieve sensitive user data, leading to privacy violations, account takeovers, or other unauthorized actions.

2.Jailbreak Detection Bypass: iOS apps often include jailbreak detection to prevent running on compromised devices, but poorly implemented detection can be easily bypassed.

  • Potential Impact: Running the app on a jailbroken device can bypass security controls, allowing attackers to manipulate the app, access sensitive data, or disable key security features.

3.Insecure Code and Binary Protection: Lack of binary obfuscation or secure code signing makes it easier for attackers to decompile and understand the app's internal logic.

  • Potential Impact: Attackers can modify the app’s behavior, such as bypassing payment systems, altering functionality, or exploiting vulnerabilities in the code.

4.Insufficient Cryptography: Weak or improperly implemented cryptographic algorithms (e.g., hardcoded keys, weak encryption) leave sensitive data vulnerable to decryption.

  • Potential Impact: Attackers can decrypt sensitive data such as passwords or personal information, leading to data breaches or unauthorized access.

5.Insecure Application Logs: Logging sensitive information such as API responses or user data in the app’s logs can expose it to attackers with access to the device or the app’s logs.

  • Potential Impact: Attackers can extract sensitive information from logs, leading to account compromise or privacy violations.

6.Improper Certificate Pinning: Failure to implement certificate pinning leaves the app vulnerable to MitM attacks, where an attacker can intercept and manipulate data between the app and its server.

  • Potential Impact: Compromised communication allows attackers to steal sensitive information, manipulate transactions, or inject malicious data.

7.Insufficient TouchID/FaceID Protection: Inadequate implementation of biometric authentication can lead to unauthorized access if the biometric checks are bypassed or incorrectly verified.

  • Potential Impact: Attackers could bypass biometric authentication, gaining unauthorized access to sensitive app functions or user accounts.

8.Insecure Use of WebViews: WebViews embedded in the app can expose the app to client-side attacks like cross-site scripting (XSS) or insecure browser-based interactions.

  • Potential Impact: Attackers can execute malicious scripts or hijack sensitive user data through insecure WebView configurations.

9.Hardcoded Sensitive Data: Sensitive information, such as API keys, encryption keys, or tokens, may be hardcoded in the app's source code, which can be extracted through reverse engineering.

  • Potential Impact: Attackers can extract hardcoded secrets from the app’s binary, gaining access to backend services, sensitive user data, or performing unauthorized operations.

10\. Insecure Debugging Information: Debugging features left enabled in production builds may expose detailed system information, such as file paths, database queries, or application logic, which attackers can exploit.

  • Potential Impact: Attackers can exploit exposed debugging data to better understand the app’s architecture, identify weaknesses, and develop targeted attacks against the system.

11.Insecure Clipboard Handling: Sensitive data copied to the clipboard (e.g., passwords, tokens) can be accessed by other apps on the device, leading to data leakage.

  • Potential Impact: Attackers or malicious apps on the device can access clipboard data and extract sensitive information like authentication tokens, compromising accounts and user privacy.

Executive Summary

F-2024-6836 - Insecure Caching of API Responses in Cache.db File Leading to Sensitive Data Exposure: The application insecurely caches API responses in the cache.db file. Anyone with access to this file can obtain plaintext sensitive information like usernames, email addresses, and phone numbers.

F-2024-6832 - SSL Pinning Bypass: The SSL pinning mechanism is not effectively implemented, allowing attackers to perform man-in-the-middle (MITM) attacks. This could lead to interception and manipulation of secure communications, exposing sensitive data.

F-2024-6833 - Sensitive Data Exposure in iOS Snapshots: When the application is minimized, sensitive information displayed on the screen is captured in iOS snapshots. These snapshots can be accessed by anyone with physical access to the device, leading to potential data leakage.

F-2024-6835 - Lack of Jailbreak Detection Mechanism: The application lacks an effective mechanism to detect if it is running on a jailbroken device. This absence allows the app to operate without restrictions in compromised environments, increasing the risk of exploitation.

F-2024-6840 - Information Exposure via iOS Clipboard: The application handles clipboard data insecurely, which could lead to sensitive information being accessed by other applications or attackers monitoring clipboard content.

F-2024-6842 - Lack of Anti-Hook and Anti-Debug Mechanism: The application does not implement anti-hooking or anti-debugging mechanisms. This makes it vulnerable to code manipulation, reverse engineering, and bypassing of security controls.

F-2024-6834 - Sensitive Data Exposure Through Memory Dump: Sensitive information such as Google authentication keys, usernames, user phone numbers, passwords, and active authentication tokens can be extracted from the application's memory. This vulnerability allows attackers to retrieve sensitive data and potentially gain unauthorized access to the application.

F-2024-6843 - Background Screen Caching The application insecurely caches background screens without obscuring sensitive information. This allows attackers with device access to retrieve cached screens and obtain sensitive user data in plaintext.

System Overview

Pionex is a cryptocurrency exchange platform designed for both manual and automated trading, integrating several in-built trading bots directly into its system.

Primary APIs

Trading API:

  • Functionality: TFacilitates manual spot trading by enabling users to access real-time market data, manage account settings, and execute buy/sell orders across a diverse range of cryptocurrency pairs.

Bot Trading System:

  • Functionality: Pionex offers 18 automated trading bots, These bots can be configured to automate trades, allowing users to maximize their trading strategies in both stable and volatile markets. Users can trade using strategies like trailing buy/sell, leveraged grid, and smart trading​.

Assets Identification

  • User Data: Includes personal information, account balances, and trading history.

  • Authentication Credentials: API keys and secret tokens used to access and automate trading activities.

  • Financial Transactions: Data related to trade executions, order placements, and cancellations.

  • Market Data: Real-time and historical price information for over 350 cryptocurrency pairs, sourced from liquidity aggregators

Findings

F-2024-6840 Information Exposure via iOS Clipboard
Status
fixed
Severity

Low
F-2024-6836Insecure Caching of API Responses in Cache.db File Leading to Sensitive Data Exposure
Status
accepted
Severity

Low
F-2024-6834Sensitive Data Exposure Through Memory Dump
Status
accepted
Severity

Low
F-2024-6833Sensitive Data Exposure in iOS Snapshots
Status
fixed
Severity

Low
F-2024-6832SSL Pinnig Bypass
Status
fixed
Severity

Low
F-2024-6843Background Screen Caching
Status
fixed
Severity

Observation
F-2024-6842Lack of Anti-Hook and Anti-Debug Mechanism
Status
fixed
Severity

Observation
F-2024-6835 Lack of Jailbreak Detection Mechanism
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2024-6840 Information Exposure via iOS Clipboard
fixed

Low
F-2024-6836Insecure Caching of API Responses in Cache.db File Leading to Sensitive Data Exposure
accepted

Low
F-2024-6834Sensitive Data Exposure Through Memory Dump
accepted

Low
F-2024-6833Sensitive Data Exposure in iOS Snapshots
fixed

Low
F-2024-6832SSL Pinnig Bypass
fixed

Low
F-2024-6843Background Screen Caching
fixed

Observation
F-2024-6842Lack of Anti-Hook and Anti-Debug Mechanism
fixed

Observation
F-2024-6835 Lack of Jailbreak Detection Mechanism
fixed

Observation
1-8 of 8 findings

Uncover findings like these to secure your project.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following iOS platform from the provided repository:

Scope Details

Identifiercom.bitget.exchange.global
Version3.0.6/30006006
Whitepaperhttps://hackenio.cc/hacken-methodologies→

Assets in Scope

iOS - iOS

Disclaimer