
Crypto exchange Toobit has completed a new round of penetration testing with Web3 cybersecurity firm Hacken, expanding the tests beyond its mobile applications to cover the exchange’s web platform and API infrastructure.
Hacken carried out three separate assessments covering Toobit’s web and API systems, iOS application, and Android application. No Critical or High-severity vulnerabilities were identified across the tests.
Seven Medium-severity findings were recorded during the assessments, which Toobit subsequently fixed, including issues relating to application data handling and access controls.
The latest work added to the scope of Toobit’s independent security testing after Hacken assessed its mobile applications in 2025. Adding the exchange’s web platform and APIs brings more of the infrastructure traders under the same external testing process.
Visit Toobit
Hacken Tests Toobit Across Three Core Environments
Penetration testing is designed to actively probe systems for weaknesses that could potentially be exploited rather than relying solely on automated vulnerability scanning.
For Toobit’s 2026 assessments, Hacken tests on three major parts of the exchange, and the absence of Critical and High-severity findings across all assessments provides Toobit with another independent review of the systems used for account access and trading.
Testing was conducted in line with widely used penetration testing standards and guidance, which includes the National Institute of Standards and Technology’s NIST SP 800-115, the Penetration Testing Execution Standard (PTES), and the OWASP Testing Guide.
Hacken draws on these frameworks when conducting vulnerability assessments across both traditional internet infrastructure and Web3 systems. Its work includes testing applications, APIs, blockchain products, and other infrastructure for exploitable weaknesses.
The complete Toobit penetration testing reports are now available on Hacken’s security assessment platform.
Toobit Builds Testing Into Wider Security Framework
The Hacken assessments sit alongside several security controls already used by Toobit.
The exchange holds ISO/IEC 27001:2022 certification, the international standard covering information security management systems. ISO 27001 focuses on how an organization identifies, manages, and reduces information security risks rather than certifying a single product or application. You can check out Toobit’s full security and compliance framework for more information.
Toobit also operates Bee-Safe, its proprietary multi-layered security framework. The system combines measures including Proof of Reserves, encryption, and continuous threat monitoring.
The Hacken testing brings external security specialists into the process and attempts to identify weaknesses under controlled conditions.
That work has become particularly relevant as attackers increasingly target the infrastructure surrounding crypto platforms rather than relying only on weaknesses in individual smart contracts.
Figures cited by Toobit show that 207 crypto hacks were recorded during the first half of 2026, the largest number reported in any six-month period. Approximately $972 million was stolen.
Infrastructure and operational compromises accounted for only around 15% of recorded incidents but roughly 76% of total losses. In other words, these attacks were less common than some other forms of crypto exploit but considerably more damaging when successful.
That makes exchanges’ web systems, APIs, mobile applications, account permissions, and internal operational controls an important part of the security picture alongside blockchain-specific defenses.
Toobit Extends Independent Security Testing
Toobit is a global cryptocurrency exchange offering spot and derivatives trading across crypto and traditional financial markets. Its platform includes zero-fee spot trading, AI-powered trading tools, and leveraged products.
The 2026 assessments are an extension of Toobit’s previous work with Hacken.
Testing in 2025 focused on Toobit’s mobile applications, and the addition of web and API infrastructure means the assessment now spans more of the exchange’s trading environment.
Regular testing is useful because the exchange infrastructure does not remain static – new features, integrations, application updates, and changes to account architecture can introduce security risks even when earlier versions of a platform have already been reviewed.
With Hacken’s latest assessments complete and all Medium-severity findings remediated, Toobit has now extended external penetration testing across its web platform, APIs, and both major mobile operating systems.
Visit Toobit
