Introduction
We express our gratitude to the XchangeOn team for the collaborative engagement that enabled the execution of this Pentest.
Document | |
|---|---|
| Name | Pentest and Security Analysis Report for XchangeOn |
| Audited By | Anton Korzhynskyi |
| Approved By | Stephen Ajayi |
| Website | https://xchangeon.io/→ |
| Changelog | 16/09/2025 |
| Platform | Android |
| Methodology | https://hackenio.cc/pentest_methodology→ |
Document
- Name
- Pentest and Security Analysis Report for XchangeOn
- Audited By
- Anton Korzhynskyi
- Approved By
- Stephen Ajayi
- Website
- https://xchangeon.io/→
- Changelog
- 16/09/2025
- Platform
- Android
- Methodology
- https://hackenio.cc/pentest_methodology→
Review Scope | |
|---|---|
| Mobile Application URL | https://webapp.diawi.com/install/UgTbKs→ |
| Version | 1.0.6 |
Review Scope
- Mobile Application URL
- https://webapp.diawi.com/install/UgTbKs→
- Version
- 1.0.6
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
System Overview
xChangeON is a centralized cryptocurrency exchange with automated arbitrage capabilities between multiple exchanges. The platform is designed to handle a large number of trading pairs and cryptocurrencies, enabling rapid detection of price discrepancies and instant trade execution. Its main focus is on maximizing user profits by quickly buying and selling assets based on price differences across different markets.
Architecturally, xChangeON is built around an AI gateway called Kraanti, which collects and analyzes data from over 30 integrated exchanges, including Binance, Kraken, KuCoin, and others. The system monitors more than 2,000 cryptocurrencies and over 1,000 trading pairs in real time, identifies arbitrage opportunities, and automatically executes trades. Order processing is significantly faster than many competitors, allowing near-instant reactions to market changes.
The platform’s functionality includes real-time market scanning, trading strategy formation, support for order management tools (stop-loss, take-profit), custom dashboards, portfolio analytics, and personalized recommendations. Various deposit and withdrawal methods are available, including bank cards, wire transfers, and cryptocurrency transactions.
Security is ensured through integration with Fireblocks, which provides cold and hot wallet storage, multi-party computation (MPC) for multi-signature transactions, and segregation of client assets. Identity verification is handled by Veriff, alongside data encryption, two-factor authentication, API protection, and 24/7 system monitoring.
The platform’s interface is designed for both experienced traders and beginners, offering intuitive navigation, quick registration, and full access to trading features immediately after account creation. Low trading and withdrawal fees make the service competitive in the market.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2025-1215 | User Enumeration via Password Reset Functionality | fixed | Low | |
| F-2025-1214 | Cleartext Traffic (HTTP) Allowed for 188.166.224.200 and http://support.xchangeon.io/login | fixed | Low | |
| F-2025-1214 | Cleartext Network Traffic Enabled in Android Application | fixed | Low | |
| F-2025-1214 | Unrestricted Clipboard Access to Sensitive Fields | fixed | Low | |
| F-2025-1213 | Insecure Screenshots of Sensitive Information | fixed | Low | |
| F-2025-1213 | Outdated Android Version Support | accepted | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes the following Android platform from the provided from customer:
Scope Details | |
|---|---|
| Mobile Application | https://webapp.diawi.com/install/UgTbKs→ |
| Version | 1.0.6 |
Scope Details
- Mobile Application
- https://webapp.diawi.com/install/UgTbKs→
- Version
- 1.0.6