Security is one of the few jobs where success can look fairly uneventful.
Getting there takes quite a bit of work.
In 2025, Hacken conducted penetration testing of our iOS and Android applications. This year, we added our web platform and API to the scope, putting more of Toobit under independent scrutiny.
What Hacken found
Across the three assessments, Hacken recorded no Critical or High-severity findings. Seven Medium-severity findings were identified, and all seven were fixed.
That is what a pentest is for. Not to produce a perfectly clean report, but to find weaknesses before someone less welcome does.
The assessments followed established standards and guidelines including NIST SP 800-115, the Penetration Testing Execution Standard, and the OWASP Testing Guide. Testing covered areas including application data handling and access controls.
Security works better in layers
Pentesting is one part of our wider security setup.
Toobit is ISO/IEC 27001:2022-certified, the internationally recognized standard for information security management. We also operate Bee-Safe, our proprietary framework combining measures such as Proof of Reserves, encryption, risk controls, and continuous threat monitoring.
They serve different purposes. ISO 27001 sets a structured approach to managing information security. Bee-Safe brings together protections across the platform. Pentesting gives those protections an outside check.
A checklist is useful. Layers are better.
The threat landscape stays busy
The industry is not short of reminders.
A total of 207 crypto hacks were recorded during the first half of 2026, the highest number in any six-month period, with approximately $972 million stolen. Infrastructure and operational compromises represented only around 15% of incidents but accounted for roughly 76% of total losses.
That imbalance says plenty. The most expensive weaknesses are not always the ones sitting in plain sight.
So we will keep testing the parts users see, the systems they do not, and the connections in between.
Because when someone is going to look for weaknesses in your platform, it is better to invite Hacken first.
The full penetration testing reports are available through Hacken's security assessment platform.
