Toobit, the award-winning global cryptocurrency exchange, has completed expanded penetration testing conducted by Web3 cybersecurity firm Hacken across its web and API infrastructure, iOS application, and Android application.
Across the three assessments, Hacken recorded no Critical or High-severity findings. All seven Medium-severity findings identified during testing were fixed, strengthening protections across areas including application data handling and access controls.
The 2026 assessments build on Toobit’s 2025 penetration testing, which focused on its mobile applications. By extending the scope to its web platform and API, Toobit expanded independent security testing across more of the exchange’s core systems.
Read More on Fintech : Global FinTech Interview: AI and the future of fintech with Hugh Cumming, CTO, Vena
The assessments were conducted in alignment with established penetration testing standards and guidelines, including NIST SP 800-115, the Penetration Testing Execution Standard (PTES), and the OWASP Testing Guide. Hacken’s methodology draws on these frameworks to support structured vulnerability assessment and security testing across Web2 and Web3 environments.
This initiative complements Toobit’s broader security and compliance framework, including ISO/IEC 27001:2022 certification, the global standard for information security management systems, and Bee-Safe, Toobit’s proprietary multi-layered security framework combining measures such as Proof of Reserves, encryption, and 24/7 threat monitoring.
Catch more Fintech Insights : Global FinTech Innovations Are Transforming Banking into Continuous Financial Guidance
[To share your insights with us, please write to psen@itechseries.com ]