24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//Crypto & FinTech · 2026
Crypto & FinTech · Case 2026

Turkish crypto exchange with 8M users · API + cold wallet Red Team · 9 critical findings · MASAK compliance

A leading Turkish crypto exchange requested a Red Team from DSET. Target: the REST/WebSocket API, withdrawal flow logic, the cold wallet HSM signing flow. Rule: loss of funds is FORBIDDEN, with an anomaly ban risk. Using a graduated read-only-first method DSET reported 9 critical findings (race + IDOR + signature replay), no funds were lost, and MASAK compliance was achieved.

Duration
14 business days of Red Team · 30 days of remediation
Scope
8M users · REST + WebSocket + cold wallet
Customer Satisfaction
★★★★★

01 The Challenge

A Turkish crypto exchange with 8M users, MASAK + BDDK compliance mandatory. Test wallet limit 0.05 BTC + 100 USDT. Anomaly detection enabled, aggressive testing = an IP/account ban. Black-box pentest, the withdrawal flow logic the most sensitive area. The previous vendor had been banned with an "aggressive" method and lost the contract.

02 DSET's Approach

01

T+0 · Graduated plan

First read-only (price feed, order book) → then trading → withdrawal flow last. A progression plan without triggering anomalies.

02

T+1-7 days · Read-only testing

The authorization layer of the API endpoints was tested. 3 IDOR findings (another user's portfolio + order history).

03

T+7-10 days · Trading testing

A WebSocket order book front-running attempt. A race condition (double-spend) was detected: a 1.4-second window.

04

T+10-14 days · Withdrawal flow

Signature replay: no timestamp validation, the same withdrawal can be re-sent 30 seconds later. Cold wallet HSM signing: insufficient dual-control.

05

T+15 days · Responsible disclosure

Coordinated disclosure with DSET. The exchange closed all findings within 3 weeks; DSET received a 28K USD bounty.

06

T+30 days · Re-test + announcement

The re-test was clean. 2 additional "best practice" recommendations were accepted. A transparent announcement was made to users.

07

T+90 days · DSET RTaaS

DSET quarterly pentest + a bug bounty program were established. MASAK awarded a "model exchange" title. Cyber insurance reimbursement limit 25M USD.

03 Results in Numbers

9 critical
Findings
0
Loss of funds
0
Anomaly ban
Approved
MASAK compliance
28K USD
Bug bounty payout
25M USD
Cyber insurance limit

04 Customer Testimonial

"

The previous vendor got us banned with their aggressive approach. DSET's graduated approach revealed 9 critical findings without any loss of funds. MASAK's "model exchange" title took our business to a whole new place.

Security Director
Crypto Exchange · 8M users
★★★★★

05 Key Takeaways

A crypto exchange pentest must be done in a "graduated" way: read-only → trading → withdrawal flow
Prevent the anomaly detection ban risk; if the test wallet is frozen, reset in 24 hours
A race condition (double-spend) is a common finding at crypto exchanges; pessimistic locking is essential
A timestamp + nonce is mandatory for signature replay (max 30 sec)

06 Services Used in This Case

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms