30/07/2026
A UK fintech company was moving real money through its app ,banks, suppliers, clients, all connected.
Before scaling it further, they asked us one honest question: could someone break in from the outside?
We tried. Turns out yes, through a setting most people would never think to check. The Android app had "debug mode" quietly switched on in the live version. That's basically leaving a service door unlocked on a bank vault.
We found a few more gaps too, one in the website's security setup, and one in how the mobile apps verified who they were talking to.
Nothing exotic. Just things nobody had tested from an attacker's point of view yet.
Good news: every one of them was fixable, fast, once we knew where to look.
Full breakdown π (link in comments)