The summary.
BROKEN OBJECT-LEVEL AUTHORISATION IS THE COMMONEST SERIOUS FAULT
Authenticating a caller does not establish they may act on that account. Check ownership on every record access, without exception.
DERIVE AMOUNT, CURRENCY AND FEES SERVER-SIDE, ALWAYS
Currency substitution with an unchanged number is a known attack, and trusting client values is what makes it work.
VERIFY NOTIFICATION SIGNATURES OVER THE RAW BODY, THEN QUERY THE PROVIDER ANYWAY
Querying is definitive and immune to signature implementation errors. Never expose an endpoint that credits accounts on receipt of a message.
A COMPROMISED PROVIDER KEY MOVES MONEY DIRECTLY
Scope keys to what they need, separate them per environment, rotate on a schedule, and test rotation before you need it urgently.
AUTOMATED SCANNING DOES NOT FIND BUSINESS LOGIC FLAWS
Which is where financial systems actually fail. Give assessors the money flows and tell them what should be impossible.
Test race conditions explicitly — concurrent identical requests, repeatedly.
WHEN MONEY IS MOVING INCORRECTLY, STOPPING THE FLOW IS USUALLY RIGHT
Continuing multiplies the damage. Preserve records before changing anything, and correct through visible entries rather than silent edits.