Overview
A security engagement across a fintech and cryptocurrency platform, covering the web application, API surface, mobile applications and cloud configuration, with architectural guidance alongside the findings.
Challenge
A fintech platform with web, API and mobile clients has three views of the same business logic, and they rarely agree on where authorisation is enforced. Assessing them in isolation misses exactly the class of issue that matters most. The engagement needed to look across the surfaces and at the cloud configuration underneath them.
Role
Security auditor — application, API, mobile and cloud assessment with architectural recommendations.
Architecture
- 01
Web Application
Assessment of the application surface and its security controls.
- 02
API Layer
Review of API authorisation, exposure and consistency across clients.
- 03
Mobile Clients
Mobile application security review across the client surface.
- 04
Cloud Configuration
Cloud hardening review covering exposure and access configuration.
Conceptual only. No real topology, configuration or internal architecture is described.
Solution
- Cross-surface assessment covering web, API, mobile and cloud.
- Architectural recommendations addressing where controls should sit.
- Cloud hardening guidance for the platform team.
Security
- This entry describes the engagement only. No vulnerability details, reproduction steps or exploit information are published.
Outcome
- Vulnerabilities identified across the web, API and mobile surfaces.
- Cloud hardening and security architecture recommendations delivered.
Lessons
- When three clients share one backend, authorisation belongs in exactly one of them — the backend.
- Cloud misconfiguration is quieter than an application bug and frequently more expensive.