CASE STUDY · REAL ESTATE TOKENIZATION AND WEB3

Two platforms, twenty-eight findings, before onboarding began

Two web audits for a real estate tokenization platform: the investor dashboard and token purchase flows, and the admin portal behind them.

Get Scoped See CredShields One
INVESTOR DASHBOARD ADMIN PORTAL TOKEN PURCHASE FLOWS WEB3 AWS CLOUD AUDIT RED TEAM
/ Engagement

The scope, in short

ENGAGEMENT TYPE
Two web application audits (investor dashboard and admin portal), plus an AWS cloud security audit and a red team phishing simulation
SCOPE
Investor-facing dashboard and token purchase flows, plus the admin portal managing events and platform operations
INDUSTRY
Real estate tokenization, Web3
/ Findings overview

Twenty-eight findings across both platforms

28
TOTAL FINDINGS
5
CRITICAL
6
HIGH
4 + 13
MEDIUM + LOW
/ Key risk areas identified

What the audits found

01

Financial transaction price manipulation: currency parameters were not validated server-side, so investors could be charged incorrect amounts.

02

Financial value drain from missing validation between token amount and payment amount, enabling fund extraction.

03

Access control bypass on wallet whitelisting, allowing unauthorized token purchases.

04

Identity system IDOR, where users could initiate and modify identity verification records for other platform users.

05

Login brute force with no rate limiting, leaving investor accounts vulnerable to credential stuffing and takeover.

06

Identity verification bypass via response manipulation, circumventing phone and email verification entirely.

07

Unauthorized access to sensitive financial event data in the admin portal.

/ Outcome

Comprehensive security hardening was completed before investor onboarding and financial activity commenced. The AWS audit report was delivered with several high-priority issues remediated on retest. The red team exercise blocked every attack vector: zero credentials compromised, MFA held under all test scenarios.

/ Relevant for

If this looks like your environment, it probably behaves like it too

Investment platforms with KYC and identity verification flows.

Regulated tech companies needing both cloud infrastructure review and employee phishing validation.

Organizations with globally distributed AWS infrastructure.

Firms in VARA, FCA, or MAS regulated environments.

Financial platforms where transaction integrity is critical.

Companies with separate investor-facing and admin-facing applications.

Regulated platforms handling user funds.

/ FAQ

Questions engagements like this raise

Why review two platforms separately?

An investor dashboard and an admin portal have different users, different privilege levels, and different consequences if breached. Testing them as two distinct surfaces catches issues that a single combined review would blend together.

What makes a price manipulation finding critical?

When a currency or amount parameter is trusted from the client instead of recalculated server-side, an attacker can charge themselves or another investor an arbitrary amount. In a platform moving real funds, that is a direct financial loss.

What is wallet whitelisting bypass?

A control meant to restrict token purchases to approved wallet addresses. If it can be circumvented, anyone can participate regardless of the eligibility checks the platform is supposed to enforce.

Was this completed before real investor funds were at risk?

Yes. All hardening was completed before investor onboarding and financial activity began on the platform.

/ More case studies

Other engagements

Data

Global sports data company

Commercially sensitive data assets under test.

Read →
Mobile

Indian crypto wallet platform

User-held digital assets on a mobile-first platform.

Read →
Cloud

Fintech neobank AWS audit

42 findings across compute, storage, IAM, and networking.

Read →
/ Get started

Start with a scoped assessment

Tell us what you are securing. We reply with scope and next steps within one business day.

Scoping within a day, findings within the first week A senior pentester on every engagement Scope and pricing before you commit

Prefer to see it first? Book a demo ↗

Already a CredShields One customer? Log in ↗

Request received We respond within one business day. For urgent requests, email [email protected].
We respond within one business day.
OR
Book a demo ↗