Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[PT] Tokenize Xchange | WEB | Dec2023

Date:

Jan 21, 2024

Table of Content

→Introduction
→Audit Summary
→Document Information
→System Overview
→Executive Summary
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Tokenize Xchange team for the collaborative engagement that enabled the execution of this Security Assessment.

Tokenize Xchange aims to become Asia’s leading digital assets exchange by providing a fiat to crypto gateway for users to access the easiest way to buy, sell and manage cryptocurrency.

titlecontent
Timeline21/12/2023 - 22/01/2024
Methodologyhttps://hackenio.cc/dApp_methodology→

    Protect your dApp with insights like these.

    Audit Summary

    Total10/10
    Security Score

    10/10

    Test Coverage

    \-

    Code Quality Score

    \-

    Documentation Quality Score

    \-

    0Total Findings
    0Resolved
    0Accepted
    0Mitigated

    The system users should acknowledge all the risks summed up in the risks section of the report

    Document Information

    This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.

    The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.

    Document

    NameDecentralized Application (dApp) Code Review and Security Analysis Report for Tokenize Xchange
    Audited ByFabio Noth
    Approved ByStephen Ajayi
    Websitehttps://tokenize.exchange/→
    Changelog22/01/2024 - Final Report
    • Document

      Name
      Decentralized Application (dApp) Code Review and Security Analysis Report for Tokenize Xchange
      Audited By
      Fabio Noth
      Approved By
      Stephen Ajayi
      Changelog
      22/01/2024 - Final Report

    System Overview

    Summary of Strengths

    Robust Validation Process:

    • The Tokenize web application boasts a strong validation process, ensuring that user inputs undergo thorough scrutiny. This not only enhances the overall user experience by preventing errors but also contributes to the security of the platform by filtering out potentially malicious or unauthorized data.

    Adherence to Request Security Parameters (HTTP-Headers):

    • One of the noteworthy strengths of the Tokenize web app is its meticulous adherence to request security parameters, particularly in the form of HTTP headers. By prioritizing and implementing strict security measures at the request level, the application fortifies itself against common web vulnerabilities, contributing significantly to the overall resilience of the system.

    Multi-Factor Authentication (MFA) Implementation:

    • The incorporation of Multi-Factor Authentication (MFA) is a key strength of the Tokenize web app. MFA adds an additional layer of security by requiring users to provide multiple forms of identification before gaining access. This not only safeguards user accounts from unauthorized access but also aligns with contemporary best practices for enhancing overall security in web applications.

    Executive Summary

    Summary of Weaknesses

    Lack of Transactional MFA Enforcement and Key Recovery Component (KRC):

    • The Tokenize web application exhibits a weakness by not mandating Multi-Factor Authentication (MFA) for executing transactions. This omission potentially exposes the platform to heightened security risks, as enforcing MFA for transactional activities is a widely recommended practice for ensuring the integrity of financial transactions. Additionally, the absence of a Key Recovery Component (KRC) for users may pose challenges in the event of lost or compromised credentials, leading to potential access issues.

    Possibility of Business Logic Attacks (BOLA):

    • The Tokenize web app is susceptible to a few instances of Business Logic Attacks (BOLA). This vulnerability could be exploited to manipulate the application's logic and potentially compromise the security and functionality of the system. Addressing and mitigating these weaknesses is crucial to prevent unauthorized actions and ensure the robustness of the overall platform.

    Incidents of Credential Leaks Discovered:

    • The Tokenize web application has experienced a few instances of credential leaks. This poses a significant threat to the security of user accounts and sensitive information. It is imperative to address and rectify these leaks promptly and to raise awareness among internal users about the importance of safeguarding credentials to prevent potential unauthorized access and data breaches.

    Appendix 1. Severity Definitions

    Severity

    Description

    Critical
    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    High
    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Medium
    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Low
    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
    • Severity

      Critical

      Description

      These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

      Severity

      High

      Description

      These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

      Severity

      Medium

      Description

      These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

      Severity

      Low

      Description

      These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

    Appendix 2. Scope

    The scope of the project includes the endpoints from the provided repository:

    Scope Details

    Type

    https://tokenize.exchange/→Web

    Disclaimer