Introduction
We express our gratitude to the Tokenize Xchange team for the collaborative engagement that enabled the execution of this Security Assessment.
Tokenize Xchange aims to become Asia’s leading digital assets exchange by providing a fiat to crypto gateway for users to access the easiest way to buy, sell and manage cryptocurrency.
| title | content |
|---|---|
| Timeline | 21/12/2023 - 22/01/2024 |
| Methodology | https://hackenio.cc/dApp_methodology→ |
Review Scope | |
|---|---|
| Web | https://tokenize.exchange/→ |
Review Scope
Audit Summary
10/10
\-
\-
\-
The system users should acknowledge all the risks summed up in the risks section of the report
Document Information
This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.
The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.
Document | |
|---|---|
| Name | Decentralized Application (dApp) Code Review and Security Analysis Report for Tokenize Xchange |
| Audited By | Fabio Noth |
| Approved By | Stephen Ajayi |
| Website | https://tokenize.exchange/→ |
| Changelog | 22/01/2024 - Final Report |
Document
- Name
- Decentralized Application (dApp) Code Review and Security Analysis Report for Tokenize Xchange
- Audited By
- Fabio Noth
- Approved By
- Stephen Ajayi
- Website
- https://tokenize.exchange/→
- Changelog
- 22/01/2024 - Final Report
System Overview
Summary of Strengths
Robust Validation Process:
The Tokenize web application boasts a strong validation process, ensuring that user inputs undergo thorough scrutiny. This not only enhances the overall user experience by preventing errors but also contributes to the security of the platform by filtering out potentially malicious or unauthorized data.
Adherence to Request Security Parameters (HTTP-Headers):
One of the noteworthy strengths of the Tokenize web app is its meticulous adherence to request security parameters, particularly in the form of HTTP headers. By prioritizing and implementing strict security measures at the request level, the application fortifies itself against common web vulnerabilities, contributing significantly to the overall resilience of the system.
Multi-Factor Authentication (MFA) Implementation:
The incorporation of Multi-Factor Authentication (MFA) is a key strength of the Tokenize web app. MFA adds an additional layer of security by requiring users to provide multiple forms of identification before gaining access. This not only safeguards user accounts from unauthorized access but also aligns with contemporary best practices for enhancing overall security in web applications.
Executive Summary
Summary of Weaknesses
Lack of Transactional MFA Enforcement and Key Recovery Component (KRC):
The Tokenize web application exhibits a weakness by not mandating Multi-Factor Authentication (MFA) for executing transactions. This omission potentially exposes the platform to heightened security risks, as enforcing MFA for transactional activities is a widely recommended practice for ensuring the integrity of financial transactions. Additionally, the absence of a Key Recovery Component (KRC) for users may pose challenges in the event of lost or compromised credentials, leading to potential access issues.
Possibility of Business Logic Attacks (BOLA):
The Tokenize web app is susceptible to a few instances of Business Logic Attacks (BOLA). This vulnerability could be exploited to manipulate the application's logic and potentially compromise the security and functionality of the system. Addressing and mitigating these weaknesses is crucial to prevent unauthorized actions and ensure the robustness of the overall platform.
Incidents of Credential Leaks Discovered:
The Tokenize web application has experienced a few instances of credential leaks. This poses a significant threat to the security of user accounts and sensitive information. It is imperative to address and rectify these leaks promptly and to raise awareness among internal users about the importance of safeguarding credentials to prevent potential unauthorized access and data breaches.
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes the endpoints from the provided repository:
Scope Details | Type |
|---|---|
| https://tokenize.exchange/→ | Web |
Scope Details
- https://tokenize.exchange/→
Type
- Web