Skip to main content

WB-S-3 — Attacker guesses or brute-forces admin bearer token

Component: Wallet Backend. Mitigations: 256-bit random token; constant-time comparison. Action: Enforce explicit token via env/file for production (do not use auto-generated)

PropertyValue
SectionSpoofing
Owneroperator

Mapped Controls

ControlTitle
SID-AUTH-01FIDO2/WebAuthn Passwordless Authentication
SID-HARD-03Network Segmentation (Separate Server Ports)

Source: STRIDE analysis (April 2026), architecture/stride-threat-model.md