Toobit has expanded its penetration testing with Hacken to cover its web and API infrastructure in addition to its mobile applications. Hacken conducted three separate assessments covering Toobit’s web and API systems, the iOS app, and the Android app, and found no Critical or High-severity vulnerabilities across those tests. The expansion occurred amid industry reporting of 207 crypto hacks in the first half of 2026 that resulted in about $972 million in losses.
In 2026, Toobit significantly broadened its scope of penetration testing by engaging Hacken to include web platform and API infrastructure assessments, in addition to those for mobile applications. This expansion builds upon the 2025 assessments, which were limited to mobile app testing, by incorporating these additional facets of Toobit’s trading environment. This more comprehensive approach ensures a thorough evaluation of Toobit’s overall security posture.
Hacken’s testing procedures adhered to several recognized security standards, namely the National Institute of Standards and Technology (NIST) SP 800-115, the Penetration Testing Execution Standard (PTES), and the Open Web Application Security Project (OWASP) Testing Guide. These guidelines ensure the effectiveness and reliability of the testing methodology.
The results from these assessments, which did not identify any Critical or High-severity vulnerabilities, are detailed in comprehensive reports available on Hacken’s security assessment platform. Additionally, Toobit’s commitment to security best practices is further demonstrated by its ISO/IEC 27001:2022 certification, underscoring its adherence to international information security management standards.
The penetration tests conducted by Hacken for Toobit in 2026 revealed no Critical or High-severity vulnerabilities across the assessed components, which included the web platform, API infrastructure, and mobile applications for both iOS and Android. However, seven Medium-severity issues were identified during these evaluations. These issues were mainly associated with data handling and access controls, areas crucial for maintaining robust security standards.
Toobit has promptly addressed and rectified all the Medium-severity vulnerabilities identified in the tests. This underscores their commitment to ensuring robust security measures and upholding industry best practices. The findings and their resolution highlight the effectiveness of Toobit’s multi-layered security strategies and align with their implementation of the ISO/IEC 27001:2022 certification standards.
Toobit operates Bee-Safe, a proprietary multi-layered security framework that includes Proof of Reserves, encryption, and continuous threat monitoring. Bee-Safe is one element of Toobit’s stated security measures. Toobit also holds ISO/IEC 27001:2022 certification.
External security specialists are engaged to assess and test crypto platforms. Industry reporting recorded 207 crypto hacks in the first half of 2026 that resulted in about $972 million stolen. Infrastructure and operational compromises accounted for about 15% of incidents but about 76% of losses.
These proprietary controls and third-party assessments are presented alongside industry data. The reporting on hacks and loss distribution provides context for Toobit’s security measures.


