Please note: Softstack does not proactively contact individuals for recruitment or job interviews. Please contact us via our website.
We are building secure and innovative Web3 solutions with expert consulting, development, and cybersecurity.
We supporting diverse blockchain ecosystems and programming languages to deliver tailored, cutting-edge Web3 solutions.
Client
Influence360
Project
Web3 influencer marketing marketplace
Industry
Web3
Date
March 2026
Scope
EVM, Solana & Tron Escrow Smart Contracts + Web Application Penetration Test
Auditor
softstack GmbH
softstack GmbH has completed two independent security engagements for Influence360: a smart contract security audit of their multi-chain escrow system and an external black-box penetration test of their web platform. This article summarizes the scope, methodology, findings, and remediation outcomes of both assessments.
Influence360 is redefining Web3 influencer marketing. They are building a platform where companies and creators can grow together, with data-driven campaigns, transparent performance metrics, and onchain payment protection. Founded by crypto veterans, Influence360 brings years of experience leading campaigns for top Web3 projects and connects the dots between companies, influencers, and communities worldwide.
The smart contract audit covered the Influence360 Escrow contracts deployed across three chains: EVM, Solana, and Tron. Each implementation provides platform fee collection, deal creation and completion, and dispute resolution.
Two independent softstack security experts performed a thorough assessment combining:
The audit identified 13 findings classified as follows:
Key findings addressed caller-controlled fee parameters, TRC-20 transfer return value handling, dispute manager access controls, batch size limits, and cross-chain implementation consistency. The Influence360 team addressed all findings
The penetration test targeted influence360 web infrastructure, as an external, internet-facing application. Testing was conducted without source code access, simulating a real-world attacker with no prior knowledge.
Methodology
The assessment followed OWASP Testing Guide and PTES (Penetration Testing Execution Standard), covering over 67 individual security tests across 16 testing phases, from OSINT and reconnaissance through active exploitation and gap analysis.
The assessment identified 15 vulnerabilities:
Key vulnerability categories included CORS misconfiguration enabling cross-site token theft, a 2FA bypass chain allowing full account takeover, broken admin access controls, rate limiting gaps across authentication endpoints, stored XSS via profile fields, and email security weaknesses.
Following the initial assessment, the Influence360 team implemented comprehensive fixes. A re-test on March 1, 2026 confirmed:
Key improvements included server-side Cloudflare Turnstile CAPTCHA enforcement across all authentication endpoints, strict CORS origin whitelisting, backend 2FA verification with rate limiting and account lockout, input validation blocking XSS payloads, profile creation limits, DMARC policy upgrade, and JWT id_token lifetime reduction from 30 to 5 minutes.
Across both engagements, Influence360 demonstrated strong security commitment and rapid remediation capability. The smart contract escrow system provides multi-chain payment protection with well-defined access controls, while the web platform now maintains a robust security posture with defense-in-depth controls across authentication, authorization, and input handling layers.
By investing in both smart contract auditing and penetration testing, Influence360 has taken a comprehensive approach to securing their platform, from the onchain escrow layer to the web application that users interact with daily.
About softstack GmbH
softstack GmbH is a European blockchain security firm specializing in smart contract audits, penetration testing, and security consulting. ISO 27001 certified, our team of experienced security researchers has audited protocols across EVM, SVM and other major blockchain platforms, safeguarding over $100 billion in user funds.
Contact us to discuss your next security audit.