Meridian
Meridian

March 10, 2026 — Security Audit & Hardening

Independent security audit completed. All findings resolved:

- Removed address-only authentication — all wallets must now cryptographically sign challenges

- Purchase race condition fixed with atomic listing status updates

- NFT ownership verified before listing activation

- JSON body limit reduced to 100KB

- Admin withdrawal capped at 10,000 XRP per transaction

- Health endpoint no longer leaks environment info

- API versioning (v1 prefix) added to all endpoints


Wawa Meridian
Published by Wawa Meridian