Learn/Write-up
Write-upOther

Settlement amount tampering on refund API

How a critical other in Webhook delivery service was found, reported to Orbit Payments and fixed.

pa@parseltongueSep 2026 · 4 min read
Verified findingCriticalReported to Orbit Payments · resolved 1 month ago

Summary

A critical issue in Webhook delivery service, reported to Orbit Payments and now fixed. This is the story of finding it, what it would have cost, and what changed.

Finding it

The interesting part was not the bug itself but the assumption behind it: that a value checked once stays checked. It does not.

http
POST /api/v2/refresh HTTP/1.1 Host: orbit.io Content-Type: application/json {"token":"<redacted>"}

Impact

An attacker could exploit this against Orbit Payments production traffic without prior access.

What changed

Orbit Payments shipped a fix and confirmed it on retest. Worth reading their scope before you start — it is unusually specific about what counts.

← More from Learn