iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In a 2014 security audit, student researchers found weaknesses in Venmo’s apps and API, including flaws they said might let some attackers steal money. They also said they could not actually steal money using the exploits they found, though an SMS-spoofing attack might have made it possible. Separately, the FTC later alleged that account takeovers had led to unauthorized withdrawals. These are distinct historical findings, not proof that the same flaws can be exploited today.
What did the 2014 Venmo audit find?
Ben Kraft, Eric Mannes, and Jordan Moldow examined Venmo’s mobile and web applications and reverse-engineered the private API used by its apps. Their paper, Security Research of a Social Payment App, is dated May 14, 2014; the authors note that sections 1.3 and 5 were added July 7, 2014. They reported technical and social vulnerabilities, including privacy leaks and API or authentication weaknesses. Some issues, they wrote, could allow certain adversaries to steal other users’ money. The researchers said they disclosed the paper to Venmo before publication so its engineers could address the issues.
Finding a possible path is not the same as demonstrating theft
The paper’s conclusion is more qualified than the article title: “We were unable to actually steal any money with the exploits we found, although it may be possible to do with the SMS spoofing attack.” This was a controlled audit by researchers, not a report that they drained victims’ accounts. The authors identified a possible route involving SMS spoofing, but said they did not successfully use their exploits to steal funds.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What did the FTC allege about unauthorized withdrawals?
The FTC complaint describes a separate account-security problem. It alleged that until approximately March 2015 Venmo lacked sufficient safeguards for consumer information. Among the examples, it said users were not notified of certain account changes, such as password or email changes or the addition of a new device. The complaint further alleged that in some instances unauthorized users took over accounts, changed passwords and/or email addresses, and withdrew funds without notifying affected consumers. These are allegations in the FTC complaint, not the findings of the student researchers’ audit.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What privacy-setting problem did the FTC describe?
The complaint also discussed historical transaction-audience controls. It alleged that the default audience and a separate sharing setting could produce different outcomes: the sharing control defaulted to Everyone, so leaving it unchanged could result in transactions being published even when a user selected Participants Only as the default audience. The FTC also alleged that another participant could make a transaction public retroactively in certain circumstances.
Those claims describe the interface and behavior addressed in the complaint. They should not be read as a description of Venmo’s current settings.
Rank #2
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
Do the 2014 flaws still affect Venmo?
The cited historical paper and FTC complaint do not establish when each of the 2014 technical issues was fixed, nor do they independently confirm whether any specific issue remains exploitable. The researchers’ findings are evidence about the system they examined in 2014; they do not establish a present-day vulnerability. Venmo’s current security guidance describes protections and recommended settings, but it is first-party guidance rather than an independent retest of the old findings.
How can you secure a Venmo account now?
Venmo’s security guidance recommends enabling multifactor authentication and setting an in-app PIN. It says users can remove the session associated with a lost or unauthorized phone, and directs people who notice unauthorized activity to contact Venmo.
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
- Enable multifactor authentication. Follow the account-security options in Venmo and complete the verification steps shown in the app.
- Set an in-app PIN. Use Venmo’s app-security settings to enable the PIN option.
- Remove a lost phone’s session. If a phone is lost or you do not recognize a device, use Venmo’s session controls to remove that session.
- Contact Venmo about suspicious activity. Use Venmo’s support route if you see a transaction or account change you did not authorize.
Venmo says it uses encryption and monitors activity to help identify unauthorized transactions. Its Trust & Safety information also describes password plus biometric or PIN-based sign-in, privacy controls, and phone-number verification when paying a new recipient. These are Venmo’s descriptions of its present-day safeguards, not independent validation of their effectiveness.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Does Venmo protect payments to sellers?
Venmo says the service is designed for payments among friends and people users trust, and warns that paying strangers for goods can be high risk. It says ordinary payments to strangers do not receive buyer or seller protection. Its Trust & Safety page describes Purchase Protection for eligible transactions when the user indicates the payment is a purchase; eligibility matters, so do not assume every payment qualifies.
Quick Recap
Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

