In-depth penetration testing for Pix flows. Dynamic QR, refunds, DICT, MED and payment initiation.
Offensive security assessments focused on Pix — Brazil's instant payment system, run by the Central Bank of Brazil (BACEN) — for fintechs, banks and payment companies that operate in Brazil or integrate Pix. Full coverage of static and dynamic QR codes, Pix Cobrança (billing), Pix Saque (cash withdrawal), Pix Troco (cash back), refunds, DICT (the Pix key directory), MED (the Special Refund Mechanism for fraud cases) and payment initiation via Open Finance (FAPI 1.0). Reports formatted for BACEN and internal audits.
- Mutual NDA within 24h
- Retest included
- Direct contact with the researcher
Why Pix is different
A Pix bug means money gone in seconds
Pix is not like card payments. Cards have chargebacks, 3-D Secure and dispute resolution through the card network. Pix is instant and irreversible by default. Once the money is gone, it's gone. Getting it back depends on the recipient's good faith (or on MED when fraud is proven).
That changes the risk math. With Pix, any bug that lets someone:
- Change the amount between the QR code and processing
- Race a refund into a double refund
- Trigger a payment without the payer's explicit consent
- Bypass anti-fraud controls by tampering with the payload
- Leak DICT key data at scale
...turns into direct financial loss or regulatory damage. There's no downstream safety net. That's why Pix penetration testing is its own discipline — it requires a methodology that generic scanners don't have.
Scope
What a Pix penetration test covers
Regulatory coverage
- Pix Security Manual (BACEN) — all technical requirements
- BCB Resolution 1 — Pix operational risk management
- BACEN Resolution 4,893 (CMN 4,893) — cybersecurity policy for regulated financial and payment institutions
- MED Operating Manual — Special Refund Mechanism
- LGPD Art. 46 (Brazil's data protection law) — protection of Pix key and account holder data
Static QR code
- BR Code payload tampering (Brazil's EMV-based QR standard) — changing the receiver or amount
- Multiple payment abuse — several payers on the same QR code
- QR code reuse after payment
- Phishing through forged QR codes in deep links
- Additional information validation (description tampering)
Dynamic QR code (BR Code with a URL)
- Tampering with the billing URL payload
- SSRF via the client-side URL parser
- Race conditions in generation and expiration
- Replay after expiration
- BOLA on the billing endpoint (accessing another recipient's QR code)
- Recipient key leakage through a public URL
Sending (DICT lookup + transaction)
- BOLA in DICT lookups — leaking account holder data
- Rate limiting on DICT lookups (BACEN requires strict limits)
- Race between the debit and the balance reservation
- Inconsistency between the cached balance (Redis) and the source of truth
- Amount tampering between the confirmation screen and actual submission
- JWT/token replay in the flow between frontend, backend and BACEN
Pix refunds and MED
- Race condition — double refund through duplicate requests
- Refund amount tampering (fraudulent partial refunds)
- Receiver tampering (refunding to a different account)
- MED — abuse of the fraud refund flow
- Refund receipt replay
- Bypassing time-window validation (90 days for MED)
Pix Cobrança and Pix Saque
- BR Code Cobrança — tampering with the due date, interest and late fees
- Pix Saque — limit bypass through payload modification
- Pix Troco — race between the cash-back amount and the purchase amount
- Location validation (PSS — the withdrawal service providers behind Saque/Troco at merchants)
Payment initiation (PISP via Open Finance)
- FAPI 1.0 Advanced — JWS detached signatures, mTLS certificate binding
- Confused deputy between the PISP and the account-holding institution
- Scope escalation in consent
- Consent ID replay
- Payment tampering via the JWE response
- Validation of the payments scope × initiated_payment status
DICT (Directory of Transactional Account Identifiers)
- BOLA — leaking other account holders' keys
- Lookup rate limits — abuse to build a database
- Tampering with portability claims
- Ownership validation bypass (taking over someone else's key)
- Replay of authenticated DICT operations
Pricing
Pix penetration testing pricing
| Scenario | Price range | Coverage |
|---|---|---|
| Pix receiving only (inbound) | Sprint (25h): US$ 3,750 to US$ 6,250 | Static + dynamic QR + webhooks + refunds |
| Full Pix (sending + receiving + refunds) | Deep Dive (50h): US$ 7,500 to US$ 12,500 | + DICT + MED + Cobrança + Saque/Troco |
| Pix + Open Finance (PISP) | Full Scope (100h+): from US$ 15,000 | + FAPI 1.0 + payment initiation + ITP (payment initiator) |
| Recurring, for active fintechs | PTaaS: on request | Continuous pentesting + monitoring |
A Pix penetration test can be purchased standalone or as a module of a fintech pentest. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.
FAQ
Frequently asked questions
Which bugs show up in Pix flows?
The most common findings in Pix penetration tests are: race conditions in refunds (double refund), tampering with the dynamic QR payload (changing the amount or recipient), limit bypass by modifying the request body, replay of signed transactions, BOLA on DICT key endpoints (leaking account holder data) and payment initiation without consent validation.
Do you cover Pix Cobrança and Pix Saque?
Yes. Coverage includes Pix Cobrança (dynamic BR Code with a due date), Pix Saque (cash withdrawal), Pix Troco (cash back at checkout) and Pix payment initiation (PISP via Open Finance Brasil). Each one has its own risk pattern — we test payload tampering, race conditions, replay and validation bypass in all of them.
Does Pix use OAuth and FAPI?
Yes, for payment initiation via Open Finance (PISP). FAPI 1.0 Advanced requires JWS/JWE signing on every request, mTLS with certificate binding and strict scope validation. We cover the full set of FAPI attacks: JWS detached signature manipulation, mTLS confusion, scope escalation and consent ID replay.
How much does a Pix penetration test cost?
Early-stage fintech that only receives Pix payments: Sprint (25h), US$ 3,750 to US$ 6,250. Fintech with full Pix (sending + receiving + refunds): Deep Dive (50h), US$ 7,500 to US$ 12,500. Bank or payment institution with Pix + Open Finance + DICT: Full Scope (100h+), from US$ 15,000. It can be purchased standalone or as a module of a fintech pentest. The hourly rate ranges from US$ 150 to US$ 250 per hour.
Next step
Request a proposal for a Pix security assessment.
Mutual NDA within 24h. Once it's signed, a 60-minute technical call to map your flows and a formal proposal within 3 business days.
Talk to a researcher