CASE STUDY · CRYPTO MARKET MAKING AND WEB3 INFRASTRUCTURE

Ten AWS regions, one phishing campaign, no breaches

A dual-track engagement for a crypto market making and Web3 infrastructure firm: an AWS cloud security audit across a globally distributed environment, plus a red team assessment against the internal team.

Get Scoped See CredShields One
/ Engagement

The scope, in short

ENGAGEMENT TYPE
AWS cloud security audit, plus red team assessment (social engineering and phishing simulation)
SCOPE
Global AWS cloud infrastructure spanning 10+ regions (EU, Asia-Pacific, Americas), plus the internal team subjected to live phishing campaigns and social engineering scenarios
INDUSTRY
Crypto market making, Web3 infrastructure
REGULATORY CONTEXT
UK and UAE, VARA regulated
/ Findings overview

Findings across two tracks

1 + 3 + 4 + 3
AWS: CRITICAL, HIGH, MEDIUM, LOW
1 + 4 + 3
RED TEAM: HIGH, MEDIUM, INFORMATIONAL
/ Key risk areas identified

What the dual-track review found

01

Network perimeter fully exposed: security groups allowed unrestricted access to all services and ports across the global infrastructure.

02

Audit trail blind spots: data-plane operations such as file access and serverless function invocations were not captured in activity logs.

03

Administrative server access (SSH) open to the internet without IP restriction, across multiple regions.

04

Data storage volumes not encrypted by default, with trading and operational data potentially stored in plain text.

05

Cloud configuration changes not tracked, so unauthorized infrastructure modifications could go undetected.

06

Backup snapshots left unencrypted, exposing data recovery points if storage is compromised.

07

Red team: employee susceptibility to credential phishing was tested, and MFA integrity was validated under a live simulated attack.

/ Outcome

The AWS audit report was delivered with several high-priority issues remediated on retest. The red team exercise blocked every attack vector: zero credentials compromised, MFA held under all test scenarios.

/ Relevant for

If this looks like your environment, it probably behaves like it too

Regulated tech companies needing both cloud infrastructure review and employee phishing validation.

Organizations with globally distributed AWS infrastructure.

Firms in VARA, FCA, or MAS regulated environments.

/ FAQ

Questions engagements like this raise

Why review infrastructure and people in the same engagement?

A globally distributed, regulated firm faces both risks at once. Testing them together produces one coherent picture of exposure instead of two disconnected reports.

Why is missing data-plane logging a significant finding on its own?

Without it, a successful intrusion into storage or serverless functions may leave no trace, which means detection and incident response depend entirely on controls that were never tested until this audit.

What does "MFA held under all test scenarios" mean in practice?

Every simulated phishing attempt aimed at obtaining credentials or session access was defeated by multi-factor authentication, even where a credential itself may have been at risk.

How does this map to VARA or similar regulatory expectations?

Regulators in these regimes increasingly expect evidence of both technical infrastructure controls and human-layer resilience testing, which is exactly what the two tracks of this engagement produced.

/ More case studies

Other engagements

Red team

Cross-border payments custody

5 attack scenarios, all blocked by existing controls.

Read →
Dual track

DeFi private credit platform

35 findings across web, API, and AWS, pre-launch.

Read →
Mobile

Consumer electronics brand

14 products: 11 mobile apps and 3 backend systems.

Read →
/ Get started

Start with a scoped assessment

Tell us what you are securing. We reply with scope and next steps within one business day.

Scoping within a day, findings within the first week A senior pentester on every engagement Scope and pricing before you commit

Prefer to see it first? Book a demo ↗

Already a CredShields One customer? Log in ↗

Request received We respond within one business day. For urgent requests, email [email protected].
We respond within one business day.
OR
Book a demo ↗