AI-assisted detection
AI-driven diffing and path expansion surfaced session invalidation race windows and weakly correlated token lifecycle events.
Fintech Protocol A
Semi-public audit covering wallet session controls and API trust boundaries for a production financial application.
Total findings
9
Critical / High
0 / 1
Resolved
89%
Duration
13 days
Semi-public audit covering wallet session controls and API trust boundaries for a production financial application.
Stack: React / Node.js / Redis / Wallet connectors
AI-assisted detection
AI-driven diffing and path expansion surfaced session invalidation race windows and weakly correlated token lifecycle events.
Auditor-owned decisions
Auditors reconstructed realistic attacker timelines and finalized mitigation ordering to minimize user-facing disruption.
Core auth and session risks were reduced to acceptable operational levels with verified compensating controls.