Matomo

Xaman wallet security assurance and improvements | Cossack Labs
Case studies
Xaman wallet security assurance and improvements

Xaman wallet security assurance and improvements

SEP - OCT 2021 | JAN - APR 2023 Finance Digital wallet
Xaman wallet security assurance and improvements

Xaman wallet audit results

The executive summary of the Xaman (formerly Xumm) security assessment is available here.

See Xaman public report

Overview

Industry

  • FSA / Fintech
  • DeFi
  • Cryptocurrency

Technology stack

  • React Native (iOS, Android)

Regulations

  • Typical fintech security requirements
  • Encryption Export Regulations

Challenges

[01]

Encrypting user data and private keys

Ensure that the protection of sensitive information such as secret numbers, mnemonics, and private keys is addressing all possible risks. Merely storing data in the Keychain or Keystore is insufficient. To enhance security, keys should be encrypted using hardware-backed encryption (Secure Enclave/Hardware-backed Keystore) and tied to biometric authentication.

[02]

Protecting against large-scale exploits

To mitigate the risk of widespread exploits and financial fraud, a number of factors need to be taken into account, such as implementing proper session management, securely handling transactions, and incorporating measures to prevent network attacks (replay, MitM, TLS strip, etc).

[03]

Educating the user to make better choices

In a self-custodial wallet, the weakest link is often the user. By understanding how to protect their secrets, enabling biometric authentication, and identifying phishing attempts, users can make informed decisions that reduce the likelihood of losing their funds.

Technology requirements

Technology requirements

Prevent transaction fraud

The main goal of the Xaman application is to safely interact with the XRP Ledger. It is crucial to use transport encryption to secure communication with the blockchain network and mitigate replay attacks, ensuring that only authenticated users have access and reducing the possibility of transaction fraud.

React Native application security

Security of the Xaman application encompasses three platforms: React Native core, iOS, Android, and their respective backend components. Each platform has specific requirements, features, and vulnerabilities that need to be addressed.

Security that supports UX

The security measures implemented in Xaman should also consider user experience (UX). As Xaman is designed for end users, the security controls should balance usability and security. It is essential to create a secure environment without making the application overly complicated for the users.

Our approach

Bespoke and innovative security solutions

Our primary focus is on providing customised solutions that cater to the risks and requirements of specific wallet applications. This is achieved by leveraging our expertise in cryptography and security engineering, along with an understanding of the challenges faced within the cryptocurrency ecosystem.

Knowledge of cryptography, hardware and mobile wallets combined

By combining our skills in cryptography with a deep understanding of hardware wallets and mobile operating systems, we identify any potential cryptographic weaknesses that could be exploited. We then offer recommendations for improving the cryptographic code to ensure optimal security while maintaining a seamless user experience.

Proactive security controls

We recognize that applications are constantly evolving things. As part of our approach, we proactively suggest security enhancements that anticipate and prevent potential vulnerabilities as the application continues to evolve.
Our approach

Solution

1. Determining the security assessment scope

2. Triaging discovered issues

3. Highlighting application security and platform trust issues

4. Migrating to modern state of the art cryptography

5. Nurturing xApps community

6. Improving security posture and processes

Xaman satisfied 43% of security requirements after the assessment, and 89% after verification of fixes.
Xaman satisfied 43% of security requirements after the assessment, and 89% after verification of fixes.

Results and outcomes

We would like to emphasise the security-focused engineering efforts undertaken by the XRPL Labs team. Although the Xaman (formerly Xumm) application already had pragmatic security controls, its overall security posture experienced significant enhancement after implementation of post-assessment recommendations.

The Xaman team has resolved all "high" flaws and bugs. Moreover, they implemented "medium" and "low" improvements to establish a defense-in-depth approach, laying a strong foundation for future application development and mitigation of potential threats.

As a result of these fixes, we observe significant improvements in handling application security corner cases, managing third-party dependencies and applying platform-specific security controls and settings.

The security posture of the Xaman application has significantly improved. Following the audit, it fulfilled 43% of the security requirements based on the OWASP MASVS v1.5. After fixing the discovered issues, the security score increased to 89%.

This security assessment served as the foundation for long-term product security engagement, which is beyond the scope of this case study.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Application form

Our team will review your resume and provide feedback
within 5 business days

Thank you!

We’ve received your request and will respond soon.

Your resume has been sent!

Our team will review your resume and provide feedback
within 5 business days