critical 20% of users exposed

Hardcoded Support System Signing Secret Enables Customer Impersonation

Signing secret in APK enabled forged support tokens. KYC docs, IP addresses, and risk scores exposed for any user.

Feb 25, 2026
AndroidHardcoded SecretsImpersonation
high Gas refund drain

Cross-Chain Bridge Gateway Overpays Gas Refunds via Zero-Byte Calldata Mispricing

A bridge gateway smart contract refunded relayer gas using a flat 16-gas-per-byte estimator, overpaying on every call and amplifiable by appending zero-byte padding to drain ETH from the gateway balance.

Feb 24, 2026
Smart ContractSolidityCross-Chain
high Full ATO

WebView Token Theft via Exported Activity and Domain Validation Bypass

Domain allowlist used substring matching. Attacker domain passed the check, WebView leaked session tokens.

Feb 24, 2026
AndroidWebViewInput Validation
critical Zero-click wallet drain

Zero-Click Wallet Takeover via Magic Link Verification Race Condition

Timing flaw in login verification bypassed email check entirely. Full recovery phrase and private key extracted in 60 seconds.

Feb 23, 2026
WebRace ConditionWallet Drain
critical Unauthenticated webhook write access

Public JavaScript Bundle Leaks Production Provider Key, Enabling Unauthenticated Webhook CRUD

A Web3 quests platform shipped a production blockchain data provider API key in its public Next.js bundle, allowing any unauthenticated visitor to create and delete webhooks on the company's billed third-party account.

Feb 21, 2026
WebHardcoded SecretsAccess Control
critical Wallet master keys leaked

Public Telemetry Endpoint Leaks Bitcoin Wallet Master Keys

A self-custody wallet provider's production telemetry exposed thousands of Bitcoin extended public keys to the open internet, enabling permanent wallet surveillance.

Feb 21, 2026
WebData ExposureWallet
critical Cloud credential theft path

Unauthenticated SSRF Enables Cloud Metadata Exfiltration and Internal Network Access

Unauthenticated webhook endpoint allowed full-read SSRF. Cloud IMDS accessed via redirect bypass, 14 internal hosts mapped.

Feb 21, 2026
WebSSRFCloud
critical 45K wallets exposed

Misconfigured Supabase RLS Exposes 45,000 Wallet Addresses and Enables Mass Data Deletion

Anonymous role had read/update/delete on 13 tables. 45,372 wallet addresses with trading volumes exposed.

Feb 21, 2026
WebAccess ControlData Exposure
critical $30M reserves exposed

Public Executive Dashboard Exposes Reserves, Business Metrics, and User Data

A P2P trading platform's internal executive dashboard endpoint required no authentication, exposing approximately $30M in crypto reserves, live business metrics, and user personal data.

Feb 21, 2026
WebAccess ControlPII Exposure
critical Full DB downloaded

Exposed Vite Dev Server in Production Enables Full Database Exfiltration

Dev server in production exposed 6.1MB database with admin credentials, API tokens, and GitHub PAT.

Feb 21, 2026
WebMisconfigurationData Exposure