An Indian ethical hacker found several bugs in a banking application that could have allowed anyone to steal $25 billion. An unknown bank was lucky that an ethical hacker found the flaws and informed them about them. If he had come with malicious intent, he could have left $25 billion richer.
Late last year, security researcher Sathya Prakash discovered a series of critical vulnerabilities in an unknown bank's mobile banking app that allowed him to steal money from any or all of its customers with just a few lines of code.
However, Prakash immediately contacted the bank in question and raised the alarm about serious flaws in mobile banking app. He also helped it fix the bugs, rather than exploiting the security loopholes to steal money from the bank, which has about $25 billion in deposits.
According to Prakash, when he analyzed the bank’s application, he found that it had many bugs. Prakash discovered that the application lacked Certificate Pinning, allowing any man-in-the-middle attacker to degrade the SSL connection and “capture” plaintext requests using fraudulently issued certificates. This bug allowed him to easily view bank customers’ records, such as their current account balance and deposits, just by automating and guessing the customer ID.
That was just the beginning though, and when he continued his search, he found a major bug that allowed him to select any account through the App and transfer the money from that account to someone else's account. Prakash found that the mobile banking app had an insecure login architecture, allowing him to perform critical actions on behalf of the targeted account holder without knowing the login password, such as viewing the victim's current account balance and deposits, as well as adding a new beneficiary and making illegal transfers.
Prakash also discovered that the banking app did not check whether the given customer ID or Transaction Authorisation PIN (MTPIN) actually belonged to the sender. MTPIN is used by banking transactions to transfer funds or create a new bank account/term deposit.
Prakash successfully tested this flaw using his parents’ accounts. Once he tested and confirmed the vulnerabilities, instead of exploiting the situation, he sent a responsible email to the bank on November 13, 2015. The bank took notice of his discovery and immediately updated the banking App to fix its flaws. However, Prakash was neither paid handsomely for discovering the bug nor was he congratulated by the bank for saving millions, if not billions.

