Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[PT] XchangeOn | iOS Mobile App | Jul2025

Date:

Sep 16, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the XchangeOn team for the collaborative engagement that enabled the execution of this Pentest.

XchangeOn is a fast, secure, and user-centric cryptocurrency trading platform built for the next generation of digital finance. With robust identity verification powered by Veriff and advanced wallet security via Fireblocks, we ensure a seamless and compliant trading experience. Mission is to make digital asset trading simple, secure, and accessible. We envision a future where anyone can participate in the evolving FinTech landscape through innovation, trust, and transparency.

Document

NamePentest and Security Analysis Report for XchangeOn
Audited ByIgor Samoilenko
Approved ByStephen Ajayi
Websitehttps://xchangeon.ae/→
Changelog15/08/2025 - Preliminary Report
PlatformiOS
LanguageFlutter
TagsiOS
Methodologyhttps://hackenio.cc/pentest_methodology→

Review Scope

APP URLProvided via TestFlight
Version1.06
  • Review Scope

    APP URL
    Provided via TestFlight
    Version
    1.06

Protect your dApp with insights like these.

Audit Summary

6Total Findings
6Resolved
0Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

System Overview

XchangeOn is a comprehensive cryptocurrency trading platform designed to provide seamless digital asset trading services. The platform operates as a full-featured exchange offering spot trading capabilities across 100+ currencies and 30+ cryptocurrencies, including proprietary tokens like BFIC and BLove. The system features real-time order execution, advanced charting tools, portfolio management capabilities, and smart order routing to deliver institutional-quality trading experiences to retail users. XchangeOn incorporates a comprehensive KYC/verification system with multiple verification levels that determine trading limits and withdrawal capabilities, ensuring regulatory compliance while maintaining user accessibility. The platform supports instant funding through crypto wallets and various payment methods, quick withdrawals, and 24/7 customer support through ticketing and live chat systems. Operating under the legal framework of XchangeOn S.R.O, the exchange maintains strict compliance with anti-bribery policies, privacy regulations, and virtual asset listing standards while offering competitive fee structures and multi-channel customer engagement through web, mobile applications, and social media presence across major platforms.

Findings

F-2025-1215Sensitive Information Stored in Plaintext Within App Sandbox
Status
fixed
Severity

Low
F-2025-1215User Enumeration via Differentiated Error Responses
Status
fixed
Severity

Low
F-2025-1212Screenshots with Sensitive Data
Status
fixed
Severity

Low
F-2025-1215Third-Party Keyboards Allowed for Sensitive Input Fields
Status
fixed
Severity

Observation
F-2025-1213App Transport Security Configuration
Status
fixed
Severity

Observation
F-2025-1213Application Can Be Launched on Jailbroken Device
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2025-1215Sensitive Information Stored in Plaintext Within App Sandbox
fixed

Low
F-2025-1215User Enumeration via Differentiated Error Responses
fixed

Low
F-2025-1212Screenshots with Sensitive Data
fixed

Low
F-2025-1215Third-Party Keyboards Allowed for Sensitive Input Fields
fixed

Observation
F-2025-1213App Transport Security Configuration
fixed

Observation
F-2025-1213Application Can Be Launched on Jailbroken Device
fixed

Observation
1-6 of 6 findings

Uncover findings like these to secure your project.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following:

Scope Details

PlatformiOS
URLhttps://testflight.apple.com/→
Version1.0.6

Disclaimer