critical 7-month persistence

1-Click Account Takeover via Deep Link Domain Validation Bypass

Flawed domain check allowed attacker URL in WebView. Session token stolen in under 2 seconds, valid for 7 months.

Feb 26, 2026
AndroidDeep LinksInput Validation
critical 20% of users exposed

Hardcoded Support System Signing Secret Enables Customer Impersonation

Signing secret in APK enabled forged support tokens. KYC docs, IP addresses, and risk scores exposed for any user.

Feb 25, 2026
AndroidHardcoded SecretsImpersonation
high Full ATO

WebView Token Theft via Exported Activity and Domain Validation Bypass

Domain allowlist used substring matching. Attacker domain passed the check, WebView leaked session tokens.

Feb 24, 2026
AndroidWebViewInput Validation
critical Zero-click wallet drain

Zero-Click Wallet Takeover via Magic Link Verification Race Condition

Timing flaw in login verification bypassed email check entirely. Full recovery phrase and private key extracted in 60 seconds.

Feb 23, 2026
WebRace ConditionWallet Drain
critical Cloud credential theft path

Unauthenticated SSRF Enables Cloud Metadata Exfiltration and Internal Network Access

Unauthenticated webhook endpoint allowed full-read SSRF. Cloud IMDS accessed via redirect bypass, 14 internal hosts mapped.

Feb 21, 2026
WebSSRFCloud
critical 45K wallets exposed

Misconfigured Supabase RLS Exposes 45,000 Wallet Addresses and Enables Mass Data Deletion

Anonymous role had read/update/delete on 13 tables. 45,372 wallet addresses with trading volumes exposed.

Feb 21, 2026
WebAccess ControlData Exposure
critical Full DB downloaded

Exposed Vite Dev Server in Production Enables Full Database Exfiltration

Dev server in production exposed 6.1MB database with admin credentials, API tokens, and GitHub PAT.

Feb 21, 2026
WebMisconfigurationData Exposure
high PII extraction

Pre-Auth POS Token Disclosure and Partner IDOR Exposes Customer PII

Self-ordering endpoint leaked access tokens. Chained with partner lookup to extract emails, phones, and addresses.

Feb 21, 2026
WebIDORPII Exposure