A challenger bank engaged Derivee to test their new mobile banking app ahead of a public App Store and Play Store launch.
Testing of the biometric login flow found that a specific error-handling path allowed session continuation without a valid biometric or PIN challenge under certain network conditions — a bypass that would have been exploitable against any user’s device if it had reached production.
The finding was escalated immediately, fixed within the sprint, and retested before the app’s public release date.