Attacker didn't hack anything... they just POSTed this to the endpoint
{
"event": "transfer.success",
"amount": 500000,
"status": "success"
}
backend credited the user. zero money moved lol. The backend trusted the request blindly
It credited user balances without verifying the payment
Programming
A Nigerian fintech just lost ₦20M to a fake webhook
Started by WheresWaladeen · Apr 30, 2026