CASE STUDY · DEFI TRANSACTIONS AND PAYMENT LAYER

Caught on testnet, before the relay went live

An API assessment of a gasless payment relay: signed token transfers and relay handling, tested on testnet ahead of mainnet launch.

Get Scoped See CredShields One
/ Engagement

The scope, in short

ENGAGEMENT TYPE
API security assessment, gasless payment relay layer
SCOPE
Gasless backend API handling signed token transfers and payment relay, testnet environment
INDUSTRY
DeFi transactions, payment layer
/ Findings overview

Four findings, caught before mainnet

4
TOTAL FINDINGS
1
HIGH
1 + 2
MEDIUM + LOW
/ Key risk areas identified

What the assessment found

01

A transaction replay attack: the same signed payment could be accepted and broadcast to the chain multiple times, risking double-spend and relayer fund drain.

02

Denial-of-service risk via unrestricted payload size: oversized requests were processed without limits, enabling resource exhaustion attacks.

03

Weak TLS and cipher configuration, exposing transaction data in transit to interception.

04

Missing HTTP security headers, leaving the API surface exposed to cross-origin and injection-type attacks.

/ Outcome

Four findings were identified on testnet infrastructure ahead of mainnet launch. All findings were pending fix and retest before production go-live.

/ Relevant for

If this looks like your environment, it probably behaves like it too

API-first payment platforms and payment relay services.

Fintech companies processing high-frequency signed transactions.

Platforms building gasless or abstracted payment infrastructure.

/ FAQ

Questions engagements like this raise

Why does replay protection matter more in a gasless relay?

The relay itself pays the gas cost of every transaction it broadcasts, so a replay attack does not just risk double-spending a user’s funds, it can also drain the relayer’s own operating balance.

Why test this on testnet instead of waiting for mainnet?

Findings on testnet cost nothing to fix. The same findings on mainnet risk real user funds and a public incident, so testing before launch is the point of a pre-launch assessment.

Is four findings a small result for an API assessment?

It reflects a tightly scoped, single-purpose API. A focused surface with a clear specification typically produces a shorter, more precise findings list than a broad, general-purpose backend.

What is the risk of missing security headers on an API, specifically?

APIs are not just consumed by browsers, but where they are, missing headers remove a layer of defense against cross-origin misuse and certain injection classes at effectively no engineering cost to add.

/ More case studies

Other engagements

Web + API

AI procurement platform

Multi-tenant boundaries and API authorization.

Read →
Web

Tokenized real estate platform

28 findings across investor dashboard and admin portal.

Read →
Data

Global sports data company

Commercially sensitive data assets under test.

Read →
/ Get started

Start with a scoped assessment

Tell us what you are securing. We reply with scope and next steps within one business day.

Scoping within a day, findings within the first week A senior pentester on every engagement Scope and pricing before you commit

Prefer to see it first? Book a demo ↗

Already a CredShields One customer? Log in ↗

Request received We respond within one business day. For urgent requests, email [email protected].
We respond within one business day.
OR
Book a demo ↗