Security audit

Conclusion for client information

1. Authentication security

Login is only possible with simultaneous verification of your username, password, and two-factor authentication (2FA). Passwords are not stored in plaintext. If multiple unsuccessful login attempts occur, access is temporarily restricted and additional confirmation is requested. All login attempts are recorded with sensitive data masked. The session remains valid until the browser is closed. Registration is protected by user authentication.

2. Cryptocurrency wallet security

Wallet private keys are not stored in the app. When creating a wallet, the user receives and stores a secure backup copy; to withdraw funds, they must present this copy and confirm the action via 2FA. Before a withdrawal, the key is verified to match the wallet address. Withdrawal frequency limits and temporary blocking are in place in the event of suspicious activity. A minimum withdrawal amount can be set, as well as general or personal withdrawal limits, if needed.

3. Supported networks

USDT is supported on the TRC20, BEP20, and TON networks. Requests for other networks are not accepted.

4. General protection

Critical actions are protected against request forgery. Standard headers and settings are used to mitigate the risks of unauthorized access, interface embedding on third-party sites, and content type spoofing. Incoming data is validated and restricted before use.

5. Comparison with similar solutions

Based on a comparison with a number of well-known platforms in the same class (exchange and non-exchange services, wallets, and digital asset platforms): the level of login security (multifactor support, limited attempts) meets or exceeds industry standards; the elimination of in-app storage of private keys is consistent with the approach of non-custodial solutions and enhances user control over funds; mandatory 2FA for withdrawals is consistent with the practices of the most stringent services; transaction frequency limits and blocking in case of verification failures are typical for financial and crypto services; support for a limited set of networks reduces the attack surface compared to platforms with a larger number of networks; the use of standard web application security mechanisms meets expectations for similar products. Overall, the measures employed meet or exceed the typical maturity level of similar well-known solutions in terms of login, key management, and withdrawal operations.

Conclusion

The audit (revised on August 28, 2026) confirmed that the application implements multi-factor authentication, eliminates the storage of private wallet keys, requires two-factor authentication and withdrawal restrictions, supports only specific networks (TRC20, BEP20, TON), and adheres to generally accepted web application security measures. Since the previous audit (March 4, 2026), login page security has been strengthened, and the accounting of deposit wallet transactions has been clarified. Compared to current industry benchmarks for 2026 (non-custodial practices, multi-factor authentication, and attack surface limitation), the measures applied meet or exceed the typical maturity level of similar solutions. This document is prepared for client information purposes and does not constitute a formal certification (CCSS, ISO 27001, etc.). It does not disclose information that constitutes a trade secret or could facilitate unauthorized access.

The conclusion is subject to mandatory revision quarterly and in the event of significant changes in the appendix.

This conclusion is based on an analysis of the application code, comparison with industry practices and artificial intelligence methods.

Signature: Auto
Date: 28.08.2026
Review frequency: quarterly