critical One-tap ATO

Deep Link + JS Bridge Chain to Full Account Takeover

Three chained flaws in a crypto exchange's Android app gave full account access from a single tap.

Mar 2, 2026
AndroidDeep LinksJS Bridge
critical Permanent impersonation

Unauthenticated Zendesk JWT Enables Full Support System Impersonation

No-auth endpoint generated support tokens for any user. Read conversations, download KYC docs, send messages as victim.

Mar 2, 2026
WebAuthenticationData Exposure
high Signature capture via deep link

Wallet Deep Link Loads Arbitrary URL in Privileged dApp Browser, Address and Signatures Captured

A wallet's deep link handler accepted any URL and loaded it inside the privileged in-app browser, where the signing bridge gave attacker pages full access to wallet address, message signing, and typed data signing.

Feb 27, 2026
AndroidDeep LinksWallet
critical 7-month persistence

1-Click Account Takeover via Deep Link Domain Validation Bypass

Flawed domain check allowed attacker URL in WebView. Session token stolen in under 2 seconds, valid for 7 months.

Feb 26, 2026
AndroidDeep LinksInput Validation
critical All users affected

Hardcoded RSA Key in Native Library Enables Remote Wallet Compromise

RSA-2048 key extracted from a .so file in 5 seconds. Forged push notifications to any wallet user.

Feb 26, 2026
AndroidReverse EngineeringHardcoded Secrets
critical 250K wallets deanonymized

Unauthenticated GraphQL Endpoint Leaks Emails, IP-to-Wallet Mappings, Push Tokens, and Support Messages

A wallet provider's GraphQL endpoint allowed any anonymous caller to read user emails, 250K IP-to-wallet mappings, 80K push tokens, and private support messages, deanonymizing blockchain users at scale.

Feb 26, 2026
WebGraphQLPII Exposure
critical 20% of users exposed

Hardcoded Support System Signing Secret Enables Customer Impersonation

Signing secret in APK enabled forged support tokens. KYC docs, IP addresses, and risk scores exposed for any user.

Feb 25, 2026
AndroidHardcoded SecretsImpersonation
high Gas refund drain

Cross-Chain Bridge Gateway Overpays Gas Refunds via Zero-Byte Calldata Mispricing

A bridge gateway smart contract refunded relayer gas using a flat 16-gas-per-byte estimator, overpaying on every call and amplifiable by appending zero-byte padding to drain ETH from the gateway balance.

Feb 24, 2026
Smart ContractSolidityCross-Chain
high Full ATO

WebView Token Theft via Exported Activity and Domain Validation Bypass

Domain allowlist used substring matching. Attacker domain passed the check, WebView leaked session tokens.

Feb 24, 2026
AndroidWebViewInput Validation
critical Zero-click wallet drain

Zero-Click Wallet Takeover via Magic Link Verification Race Condition

Timing flaw in login verification bypassed email check entirely. Full recovery phrase and private key extracted in 60 seconds.

Feb 23, 2026
WebRace ConditionWallet Drain