Loading...
FinchTrade

Product OTC liquidity Cross-border payments Solutions Payment service provider OTC desks EMI / Bank API docs Referrals About Blog

Log in

Hacken penetration test confirms FinchTrade’s low-risk status

Hacken penetration test confirms FinchTrade’s web and API are low risk. Read how PTES/OWASP checks, MFA, and fixes strengthen secure OTC trading.

By FinchTrade 2 min read
TL;DR Key takeaways

TL;DR

  • Hacken's penetration test of FinchTrade Web and API systems (Nov 28, 2023 to Jan 17, 2024) rated overall risk LOW.
  • Hacken used PTES and OWASP frameworks in a gray box assessment, noting MFA, containerized microservices, and robust transaction validation.
  • The report acknowledged testing limitations, and FinchTrade’s IT team remediated identified vulnerabilities, yielding the LOW overall risk level.
  • Stakeholders should review the full Hacken report, remediation details, and scope to independently confirm FinchTrade's LOW risk claim and limitations.

We are thrilled to announce that FinchTrade has successfully completed a comprehensive penetration test conducted by Hacken on our Web and API systems. The test, which took place from November 28th, 2023, to January 17th, 2024, highlights FinchTrade’s digital platform’s low-risk status.

The Hacken.io team, employing top-tier cybersecurity methodologies including PTES and OWASP, meticulously assessed our systems. The process involved gray box security assessment and a detailed risk analysis, aligning with the highest standards in cybersecurity practices.

Key Highlights

  1. Robust Availability: FinchTrade’s use of containers and microservices enhances system resilience and scalability.
  2. Strong User Security: The platform’s Multi-Factor Authentication (MFA) significantly boosts the protection of user accounts.
  3. Effective Transaction Validation: The robust process for transaction validation ensures integrity and security.
  4. Comprehensive Verification Process: Utilization of shared documents for validation highlights a thorough approach to verification.

While the test inherently had its limitations, it’s important to note that our IT team has effectively addressed and resolved the specific vulnerabilities identified, thus, getting the overall risk level at LOW.

Yuri Berg, a Board Member at FinchTrade, stated, “Hacken’s penetration test is a significant milestone for us. It not only confirms our robust security posture but also guides our ongoing commitment to safeguarding our digital ecosystem.

Dyma Budorin, Co-Founder & CEO at Hacken, comments, “Our collaboration with FinchTrade is a testament to Hacken’s commitment to enhancing digital asset trading security. By conducting rigorous penetration tests, we help platforms like FinchTrade identify and mitigate potential risks, ensuring a secure and trustworthy environment for their clients.

This successful assessment positions FinchTrade as a secure and reliable partner in the digital asset market, emphasizing our commitment to maintaining a trustworthy trading environment. For more details about FinchTrade’s security initiatives, please check this page.

About Hacken

Hacken is a leading cybersecurity consulting firm specializing in blockchain security, known for its comprehensive approach to protecting digital assets.

For requesting more information about how we can help reach out to us. We're here to help and answer any questions you may have.

Contact us!

A grid listing FinchTrade security controls matched to their described effects in Hacken's test summary, with short source quotes for each.

Frequently asked questions

Hacken conducted a comprehensive penetration test of FinchTrade’s Web and API systems from November 28, 2023 to January 17, 2024 and classified the platform’s overall risk level as LOW. Specific vulnerabilities identified during the assessment were effectively addressed and resolved by FinchTrade’s IT team.

Hacken used established cybersecurity methodologies, including PTES and OWASP, performing a gray box security assessment and a detailed risk analysis on FinchTrade’s Web and API systems. Their process evaluated system components and produced a risk-based report that informed mitigation by FinchTrade’s IT team.

The assessment highlights several security aspects: Multi-Factor Authentication (MFA) for user accounts, robust transaction validation processes, a comprehensive verification workflow using shared documents, and infrastructure resilience through containers and microservices. These elements contributed to Hacken’s low-risk classification.

The report notes that the penetration test inherently had limitations, and it identified specific vulnerabilities. FinchTrade’s IT team has effectively addressed and resolved those identified issues, and the overall risk level was reported as LOW following remediation.

Following Hacken’s findings, FinchTrade’s IT team addressed and resolved the specific vulnerabilities identified in the Web and API assessment. The platform maintains measures cited in the report—MFA, transaction validation, verification processes, and containerized microservices—to support ongoing resilience and security.

Power your growth with seamless crypto liquidity

A single gateway to liquidity with competitive prices, fast settlements, and lightning-fast issue resolution

Get started