March 10, 2026 — Security Audit & Hardening
Wawa MeridianFounder
Independent security audit completed. All findings resolved:
- Removed address-only authentication — all wallets must now cryptographically sign challenges
- Purchase race condition fixed with atomic listing status updates
- NFT ownership verified before listing activation
- JSON body limit reduced to 100KB
- Admin withdrawal capped at 10,000 XRP per transaction
- Health endpoint no longer leaks environment info
- API versioning (v1 prefix) added to all endpoints