Home/Case studies/Kanga Exchange

Case study · Audit

Kanga Exchange: from intensive pentests to a 3-year strategic partnership

Crypto-asset security with MiCA and DORA compliance: exchange app pentests, Pentest as a Service, Hybrid Vulnerability Scanner and a MiCA RTS audit.

MiCA · DORAFinTech

Client

Kanga Exchange — one of the leaders of the cryptocurrency market, operating a crypto exchange and a network of brick-and-mortar exchange offices. Kanga Exchange is growing rapidly, offering a wide range of FinTech services in an environment where transactions are irreversible and the risk of hacker attacks is as high as it gets.

Challenge

Kanga takes an uncompromising approach to protecting user funds and platform stability. The goal of the engagement was to thoroughly verify the security of the entire ecosystem ahead of tightening EU regulatory requirements (MiCA), and then to move from one-off testing to continuous security monitoring and hybrid vulnerability scanning.

Scope of work

  • Phase I (3 months): intensive security and compliance testing — the first time at this scale for the client
  • Exchange and currency exchange web application: penetration testing of key functionality — transaction logic, wallets, deposit and withdrawal mechanisms, and user dashboards
  • Server infrastructure: verification of the configuration of servers running the exchange for resilience against DDoS attacks, takeover and data leakage
  • MiCA RTS to DORA audit: a specialized audit verifying compliance with the regulatory technical standards (RTS) of the MiCA (Markets in Crypto-Assets) Regulation in correlation with DORA requirements
  • Phase II (3 years): Pentest as a Service (PtaaS) — continuous pentesting instead of traditional annual tests; Hybrid Vulnerability Scanner as a Service — deployment of an advanced hybrid vulnerability scanner

How the engagement worked

Phase I — testing and compliance (3 months)The first stage of the engagement focused on in-depth technical and regulatory verification. Given the nature of the industry, the work had to be fast and precise; Critical and High findings were reported immediately and fixed by the Kanga Exchange development team, then verified through re-tests.
The partnership decisionThe trust built during the first phase, and the understanding that exchange security is a process rather than a one-time event, led to an expanded engagement — Kanga Exchange chose to adopt modern subscription-based services for a period of 3 years.
Pentest as a ServiceInstead of annual tests, a continuous model was introduced: our specialists constantly try to break the exchange’s defenses with every major code release, acting as “in-house ethical hackers.”
Hybrid Vulnerability ScannerAn advanced hybrid vulnerability scanner was launched: a solution that combines automated scanning (daily checks for known CVEs) with manual verification of results by our analysts, eliminating false positives and giving Kanga’s IT department a clear picture of its security posture.

Results and value for the client

The engagement delivered measurable benefits critical to the stability of a blockchain-based financial institution. Asset protection: eliminating critical vulnerabilities in the exchange’s business logic protected the platform from potential financial losses. Regulatory readiness (MiCA / DORA): the audit provided a roadmap for aligning systems with the rigorous EU requirements for crypto-asset service providers (CASPs). Continuous monitoring: moving to a continuous scanning model cut the mean time to detect new vulnerabilities (MTTD) from weeks to hours.

The partnership with Kanga Exchange has been exemplary. After completing the first phase and implementing the fixes, the client issued references for Remote Admin, recognizing our expert support on blockchain specifics and our flexible approach to the platform’s rapid growth.

Other projects

See more case studies

All projects →
AuditCritical infrastructure · public sector

DORA compliance audit for an institution of national importance

Audit planning and delivery: ICT risk, incidents, resilience testing and third-party risk — under strict confidentiality.

460+hours of work
5DORA pillars
Read the case study →
AuditBanking · ICT vendor due diligence

Passing a bank’s security questionnaire

A complete set of answers and evidence for the ICT vendor questionnaire: policies, procedures and records required under banking outsourcing rules.

100%of areas covered
0follow-up questions
IT SecurityBanking · ING Bank Śląski S.A.

12-month penetration testing program for ING Bank Śląski

A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.

12 monthscontinuous program
OWASPASVS · black-box
Read the case study →