Xenea — Wallet App Penetration Test

Audit report published Apr 2025. Android app, wallet API and admin API.

Findings at a glance

SeverityCount
Critical4
High7
Medium16
Low13
Total40

Summary

Safe Edges ran a grey-box penetration test of the Xenea Wallet Android app, its wallet API and its admin endpoint between 26 February and 21 March 2025, using test credentials provided by Xenea. Forty issues were identified: four Critical, seven High, sixteen Medium and thirteen Low. The Critical issues were unauthorized access to the admin API, an IDOR that disclosed other users' information, an insecure broadcast receiver that allowed arbitrary file writes, and sensitive data stored unprotected in a local database. Xenea fixed twenty-seven issues and acknowledged thirteen.

Read the full report (PDF).

Findings

Critical (4)

High (7)

Medium (16)

Low (13)

More published reports

Related services

Get a fixed quote in 24 hours

Send the repository and a commit hash through the contact form, message @bugtester25 on Telegram, or book a 30-minute scoping call. 200+ protocols audited · $4B+ secured · 0 hacks post-audit. Prefer email? info@safeedges.in.