Skip to content

Blockchain Penetration Testing for Exchanges and Custodians

Blockchain penetration testing for exchanges, custodians, wallets and DeFi: withdrawal flows, APIs, key management, cloud and smart contract review.

Invadel Team8 min read

The largest crypto theft on record did not break a smart contract.

On or about February 21, 2025, attackers stole about $1.5 billion in virtual assets from the exchange Bybit. The FBI attributed the theft to North Korea. (FBI) Sygnia’s investigation found that the attackers had modified JavaScript files served by the Safe{Wallet} web interface, the multisig tool Bybit’s signers used. The signers saw legitimate transaction details on screen while a malicious transaction was signed in the background. (Sygnia) Chainalysis counts more than $3.4 billion stolen from January to early December 2025, with Bybit alone about $1.5 billion of it. (Chainalysis)

The lesson for anyone running an exchange, a custody platform, a wallet or a DeFi protocol: the weak point is often off-chain. It is the web application, the API, the signing flow and the cloud account around the chain.

Invadel tests both sides. The platform around the chain is tested at published fixed prices: web application from $5,200, API from $4,000, mobile app from $6,000, cloud from $6,800 and secure code review from $4,800, each with a free retest. Smart contract review is scoped and quoted after we see the code.

What blockchain penetration testing covers

Layer What we test How it is priced
Trading and account platform Web app, admin and support consoles, deposit and withdrawal flows Web application from $5,200
APIs Trading, account and withdrawal APIs, websockets, key scoping API from $4,000
Wallet apps iOS and Android key storage, signing, deep links, the back end Mobile application from $6,000, both platforms included
Custody and cloud Signing services, KMS and HSM access paths, cloud identity Cloud from $6,800
Off-chain code Matching engine, ledger and withdrawal services Secure code review from $4,800
Smart contracts Solidity or other contract code, upgrade and admin paths Scoped and quoted

Most platforms need two or three of these, not all six. We scope from what you run.

Exchanges: follow the money paths

An exchange is a web application that moves money. Test the places where money moves.

  • Deposit crediting. Is a deposit credited once, and only after the confirmations your policy requires? Parallel requests and retries are where double credits hide.
  • Withdrawals. Can a user add a new withdrawal address and use it at once, skipping the allowlist delay? Can a second factor be downgraded or skipped on the withdrawal step? Do withdrawal limits hold when requests arrive in parallel?
  • Account takeover. Password reset, email change, session handling and MFA recovery. On an exchange, account takeover is a withdrawal.
  • Internal transfers. Transfers between users can skip the controls that on-chain withdrawals get.
  • Admin and support consoles. Support tools that can change an email address or reset MFA are a withdrawal path too. We test them from every support role.
  • Identity documents. KYC files are sensitive personal data. We test who can reach them, and whether one customer can reach another’s.

APIs: keys, scopes and other people’s orders

Trading bots and active traders use the API, not the web app. Test it as a product of its own.

  • Key scoping. A read-only key should not trade. A trading key should not withdraw. We test every boundary.
  • Key restrictions. IP allowlists on keys, and what happens when a restricted key is used from elsewhere.
  • Cross-account authorization. Can one account read or cancel another account’s orders by changing an ID? This is the top API risk in the OWASP API Security Top 10. See our OWASP API Security Top 10 guide.
  • Request signing. Replay of signed requests, nonce handling and timestamp windows.
  • Websocket feeds. Private channels that leak other users’ orders or balances.
  • Rate limits on login, withdrawal and order endpoints.

Custody and key management

A custody platform is judged on one question: can anyone move funds without the approvals the policy requires?

  • Signing services. Who and what can submit a transaction for signing, and what checks run before it is signed.
  • Approval policies. Quorum rules, address allowlists and limits. Then the harder question: who can change the policy itself?
  • Key material. Access paths to KMS keys, HSM partitions or MPC key shares, through cloud identity, CI/CD pipelines and administrator workstations.
  • What the signer sees. The Bybit signers saw one transaction while another was signed. We test whether the transaction details your approvers review come from a source an attacker can alter, such as front-end code in a storage bucket. Integrity controls on that code, such as subresource integrity and code signing, are part of the recommendations.
  • Cloud identity. Roles that can read secrets, change deployment code or reach the signing network. See cloud penetration testing.

Wallet apps

A wallet app holds keys on a phone you do not control.

  • Key and seed storage. iOS Keychain and Android Keystore, backups, logs, screenshots and the clipboard.
  • Transaction display. Does the app show the user what they are actually signing?
  • Deep links and session handling. Links and pairing sessions that can trigger a signing request.
  • The back end. The APIs the app trusts for balances, prices and transaction building.

We test iOS and Android together at one price. Our guide to the OWASP Mobile Top 10 covers the underlying risks.

Smart contracts and DeFi

Invadel reviews smart contracts. Our smart contract audit services review the code by hand against the OWASP Smart Contract Top 10 (2025) and your protocol’s own logic. (OWASP Smart Contract Top 10)

OWASP ID Risk
SC01 Access control vulnerabilities
SC02 Price oracle manipulation
SC03 Logic errors
SC04 Lack of input validation
SC05 Reentrancy attacks
SC06 Unchecked external calls
SC07 Flash loan attacks
SC08 Integer overflow and underflow
SC09 Insecure randomness
SC10 Denial of service attacks

Beyond the list, we look at upgrade paths and proxy admins, privileged roles and multisig thresholds, and the front end that builds transactions for your users.

Contract review is scoped and quoted, not fixed-priced from a table. Send the repository, the commit to review, the deployed addresses and your documentation. The quote comes back in writing.

Regulation: BitLicense and NYDFS

New York regulates virtual currency businesses through the BitLicense, 23 NYCRR Part 200. Section 200.16(e) says: “Each Licensee shall conduct penetration testing of its electronic systems, at least annually, and vulnerability assessment of those systems, at least quarterly.” (23 NYCRR 200.16, Cornell LII)

BitLicense holders are also covered entities under NYDFS Part 500, which requires annual penetration testing under section 500.5. Our NYDFS 23 NYCRR 500 penetration testing page explains the Part 500 requirements, and the fintech penetration testing page covers licensed lenders and money transmitters. Other states license virtual currency and money transmission separately; check the requirements attached to each license you hold.

Our office is in Manhattan, so New York exchanges, custodians and protocol teams can have testers on-site when the scope needs it. Our New York City penetration testing page explains how we work across the five boroughs.

Testing safely

Nobody should lose real funds to a penetration test.

  • Testnets and sandboxes first. Most testing runs against a staging environment on a test network.
  • Forked networks for contracts. Exploit paths are proven on a local fork, not on mainnet.
  • Production only in writing. Where production testing is needed, the rules of engagement set the windows, the accounts, the amounts and the destination addresses you control.
  • A stop button. Named emergency contacts on both sides, and a signed authorization letter before any testing starts.
  • Critical findings reported the same day. We report a confirmed critical finding when we confirm it, not in the final report.

What blockchain penetration testing costs

Every figure is a published starting price. You get one fixed quote in writing.

Test Small Medium Large
Web application $5,200 $7,800 From $12,500
API $4,000 $6,000 From $9,500
Mobile app, iOS and Android $6,000 $8,500 From $14,000
Cloud $6,800 $10,500 From $17,500
Secure code review $4,800 $8,900 $12,000
Smart contract review Scoped and quoted Scoped and quoted Scoped and quoted

A typical exchange starts with the web application, the API and the cloud account. A wallet company starts with the mobile app and its API. Every penetration test includes a report, an attestation letter and a free retest. See pricing.

Frequently asked questions

Do you audit smart contracts? Yes. We review contract code by hand against the OWASP Smart Contract Top 10 and your protocol’s logic. It is scoped and quoted after we see the repository; our smart contract audit page explains what the review covers and what to send.

Is a smart contract audit enough? Not for a platform that holds user funds. The Bybit theft went through a web interface and a signing flow, not a contract bug. Test the application, the API, the signing path and the cloud as well.

Do you test on mainnet? Only when the rules of engagement say so in writing, with accounts and amounts you choose. Most work runs on testnets, sandboxes and local forks.

Does NYDFS require penetration testing for BitLicense holders? Yes. 23 NYCRR 200.16(e) requires penetration testing at least annually and vulnerability assessment at least quarterly.

How long does a test take? A small web application takes about a week of testing, followed by reporting. Larger platforms and contract reviews take longer; the timeline comes with the quote.

What do you need from us? Test accounts for every role, access to a staging environment, API documentation and, for code or contracts, repository access and the commit to review.

The short version

Many crypto losses start off-chain: a web interface, an API key, a support console or a signing flow. Test the platform around the chain at a fixed price, have the contracts reviewed, and fix both before someone else finds them.

Fixed price, fixed scope, free retest on every penetration test. Scope your platform test, or compare other firms on our list of fintech cybersecurity companies.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

All articlesApplication Pentesting

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation