Home/Case studies/crypto exchange

Case study · IT Security

Deploying the Reconmore scanner at a cryptocurrency exchange

Protecting a crypto platform from development flaws: 17 vulnerabilities found in month one and 24 months of continuous protection with the Reconmore scanner.

ReconMoreFinTech

Client

A fast-growing cryptocurrency exchange (FinTech). A trading platform where any flaw in the code can mean direct financial losses for users.

Challenge

The goal was to secure the platform launch and put in place continuous monitoring to protect the environment from bugs introduced during code updates by the client’s development team.

Scope of work

  • Launch audit (month 1): during the first penetration tests under Reconmore, 17 vulnerabilities were identified — 2 critical, 3 high, 3 medium, 6 low, 3 informational
  • Denial of Service (Critical): the platform could be taken down entirely from a single computer using a slow HTTP headers attack against the Apache server
  • Reflected XSS (Critical): a flaw allowing malicious JavaScript to run in the context of a logged-in exchange user — a major session hijacking risk
  • Missing encryption (High): inadequate encryption of connections on sensitive endpoints
  • Continuous monitoring: over the following 23 months, the Reconmore scanner automatically identified 2 critical and 1 high vulnerability caused by new, faulty application releases from the client’s development team

How the engagement worked

Launch auditPenetration testing before the platform launch — 17 vulnerabilities identified and classified in the first month.
Detailed reportWe delivered a classification of the flaws, their location in the architecture and an analysis of the real business risk for the exchange.
Engineering supportMeetings with engineers to discuss the technical aspects of implementing the recommendations, plus free re-tests once fixes were in place.
Continuous monitoring (24 months)The scanner runs constantly — three serious bugs introduced by developers in later releases were detected and blocked before anyone else could exploit them.

Results and value for the client

The platform launched without a single incident, and the initial audit protected the exchange against critical flaws such as DoS and XSS. The following two years of ongoing cooperation proved the value of the continuous model: Remote Admin engineers quickly caught new, dangerous vulnerabilities that developers had unknowingly introduced during platform updates — 3 developer errors blocked in total, 2 of them critical.

Launching the Reconmore service was one of the best technology decisions for our exchange. The initial audit protected us against critical flaws such as DoS and XSS. But it was the following two years of ongoing cooperation that proved the value of the service — Remote Admin engineers quickly caught new, dangerous vulnerabilities that our developers had unknowingly introduced during platform updates.

Chief Technology Officer (CTO), cryptocurrency exchange — details under NDA

Other projects

See more case studies

All projects →
IT SecurityBanking · ING Bank Śląski S.A.

12-month penetration testing program for ING Bank Śląski

A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.

12 monthscontinuous program
OWASPASVS · black-box
Read the case study →
IT SecurityCooperative banking

Annual security audit of a Cooperative Bank’s infrastructure and systems

A comprehensive annual security audit of a cooperative bank's critical infrastructure, banking application and email systems in light of DORA requirements.

3 monthstesting cycle
100%fix effectiveness in re-tests
Read the case study →
IT SecuritySoftware House · B2B applications

Securing the software development lifecycle (SDLC) with the Reconmore scanner

How Reconmore continuous vulnerability scanning supports developers: nearly 60 vulnerabilities found over 6 years with a software house building B2B apps.

~60vulnerabilities found
6 yearsof ongoing cooperation
Read the case study →