Introduction
We express our gratitude to the THG AssetGuard Wallet team for the collaborative engagement that enabled the execution of this dApp Security Assessment.
THG AssetGuard Wallet is a secure, user-friendly cryptocurrency wallet designed specifically for the Hedera network.
Document | |
|---|---|
| Name | API Penetration Testing Report for THG AssetGuard |
| Audited By | |
| Approved By | |
| Changelog | 25/08/2025 |
| Platform | API |
| Tags | dApp, API |
| Methodology | https://hackenio.cc/dApp_methodology→ |
Document
- Name
- API Penetration Testing Report for THG AssetGuard
- Audited By
- Approved By
- Changelog
- 25/08/2025
- Platform
- API
- Tags
- dApp, API
- Methodology
- https://hackenio.cc/dApp_methodology→
Review Scope | |
|---|---|
| API | https://ew-wallet-backend.pub.prd.hashgraph-group.com→ |
Review Scope
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
System Overview
THG Wallet is a secure, user-friendly cryptocurrency wallet designed specifically for the Hedera network.
It allows seamless management of your HBAR, tokens, and NFTs.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2025-1236 | Open unencrypted HTTP port 15021 | fixed | Low | |
| F-2025-1236 | Improper handling of frequent requests leads to 429 Too Many Requests escalating into 500 Internal Server Error with debug disclosure | fixed | Low | |
| F-2025-1235 | Improper request path handling with ; leads to 500 Internal Server Error and debug information disclosure | fixed | Low | |
| F-2025-1235 | Improper domain handling in Origin header leading to 500 Internal Server Error | fixed | Low | |
| F-2025-1236 | Missing Security Headers | fixed | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes endpoints from the provided repository (api.yml):
Scope Details | |
|---|---|
| API | https://ew-wallet-backend.pub.prd.hashgraph-group.com/→ |
| Whitepaper | https://hackenio.cc/hacken-methodologies→ |
Scope Details