Authorized security assessment discovered five high-impact vulnerabilities including an infinite payment duplication exploit and cross-user payment hijacking. All findings were disclosed to the operator and patched within 48 hours.
All findings resolved
Operator patched all critical issues within 48 hours of disclosure. Advisory published after 70-day embargo.
Disclosure Timeline
- 2026-07-25Authorized assessment started. Initial critical findings identified and reported to operator same day.
- 2026-07-26Operator patched payment deduplication bypass and cross-user payment hijacking within hours of report.
- 2026-07-27Balance-bypass payout vulnerability identified and reported. Patched same day.
- 2026-07-28Content-proxy XSS chain identified. Final report delivered to operator.
- 2026-10-07Advisory published after 70-day embargo.
Findings
F1 · Payment Deduplication Bypass
CATASTROPHICThe TON payment verification endpoints deduplicated transactions against a raw client-supplied hash string rather than a normalized transaction identifier. Varying the case of hex characters in the same hash value (de5b25… vs DE5B25… vs base64 encoding) caused each variant to pass as a distinct payment. A single 10.23 TON deposit was credited 12 times as raffle tickets plus two NFT items worth 3.3 TON each — a total of ~70 TON value extracted from one real payment.
Because transaction hashes are public on the TON blockchain, any attacker could use any historical transaction — including one they did not originate — as an infinite credit source, limited only by the 2^n case permutations of the hash string.
F2 · Cross-User Payment Hijacking
CRITICALThe ticket purchase endpoint (POST /api/verify-ton-transaction) and NFT purchase endpoint (POST /api/portals/verify-ton) looked up transactions by client-supplied hash and verified only that the received amount met the expected threshold. Neither endpoint verified that the on-chain transaction comment matched the calling user's payment session, nor that the sender address belonged to the calling user's wallet.
Exploited live: a fresh raffle session for 7 tickets (0.0703 TON) was submitted with a third-party transaction hash for 1.94 TON from an unrelated user's wallet. The server responded {"success":true,"totalTickets":7} and issued ticket #313173 in the live raffle at zero cost. Because TON transactions are public and near-real-time, a rate-limit-free attacker could monitor the operator's hot wallet and race every incoming payment before the legitimate user claims it.
F3 · Balance-Bypass Payout
CRITICALPOST /api/payout-request processed TON withdrawal requests without verifying the user's Stars balance against the requested amount before initiating an on-chain transaction. A test account with a lifetime credit of 84 Stars successfully submitted two 100-Star withdrawal requests; both were accepted and one resulted in an executed on-chain transfer of 0.862641 TON (txHash d9237513…, confirmed independently via TonCenter). A request for 999,999 Stars returned {"success":true,"newBalance":0}.
F4 · Promo Code Enumeration Oracle
HIGHPOST /api/cases/promo/redeem returned distinguishable error messages for non-existent codes (promo_not_found) versus exhausted codes (promo_limit_reached), creating a full enumeration oracle with no rate limiting. At 25.8 requests/second, 1,864 candidates were tested in ~60 seconds, yielding five valid promotional codes: FREE, FREE1, SUMMER, GIFTROAD, MINES. New influencer codes could be exhausted within minutes of creation.
F5 · Unauthenticated Full User Database Exposure
HIGHThe raffle history endpoints (GET /api/draws/history, GET /api/gifts/{id}) operated without authentication. Raffle IDs were sequential integers starting from 1. Iterating 80 IDs (approximately 1% of the full dataset) returned 3,186 ticket rows containing raw Telegram user IDs, ticket counts, amounts, and timestamps — exposing 1,012 unique paying users and 82,839 Stars of transaction volume. At 6.5 requests/second with no throttling, a complete extraction of all 8,164 raffles would take under three minutes.
Remediation Status
| Finding | Status | Patched |
|---|---|---|
| F1Payment Hash Bypass | Fixed | 2026-07-26 |
| F2Payment Hijacking | Fixed | 2026-07-26 |
| F3Balance-Bypass Payout | Fixed | 2026-07-27 |
| F4Promo Code Oracle | Fixed | 2026-07-28 |
| F5Unauthenticated User Data | Fixed | 2026-07-28 |
Advisory ID: TEYNA-2026-001 · Published: October 7, 2026 · Contact: hello@teyna.red