The new version focuses primarily on reliable transaction processing, the security of the admin panel, and a more stable connection between iEXWallet and integrated websites. The "Sites" section has been redesigned, the Public API expanded, deposits and payouts improved, and the interface updated for faster panel loading.
More reliable payouts
The payout handling logic for disputed cases has been significantly revised.
If a connection error, provider timeout, or another ambiguous response occurs during sending, iEXWallet first checks the transaction status directly on the network and only then determines the result of the operation. This reduces the risk of resending an already completed payout.
The handling of XRP, TON, TRON, Polkadot, and EVM networks has been further enhanced. For each network, the system now more accurately determines the actual transaction status and does not interpret ambiguous provider responses as successful submissions.
The payout feature for the full available balance has been enhanced: if the wallet amount changes after the operation confirmation, the system will not send more than the approved amount.
Rules for resubmission, large payouts, time-lock, and multi-level verification have also been updated. Inserted Markdown
Improved deposit functionality
Fixed processing of incoming payments across multiple networks.
Token verification for TON, USDT, and USDC has been improved — payments from external contracts can no longer be mistakenly credited. For XRP, the actual received amount is considered, including partial payments. Inserted Markdown
For Ethereum, BNB, and other EVM networks, confirmation verification has been improved to handle temporary unavailability of individual RPC providers. Deposits already found and confirmed on the blockchain will no longer revert to error status due to issues from a single data source.
Fixed issues where canceled or expired deposits could incorrectly become active again. Inserted Markdown
Public API expanded
Integrating iEXWallet with the exchanger is now easier.
Now, only one is used for connection API Keyinstead of the pair API ID and API Key. Existing integrations with the old format continue to work.
A site event log has been added, enabling connected systems to retrieve missed events after temporary downtime and restore operation sequences.
Deposit, payout, and account filters have been enhanced; you can now search transactions by hash and generate reconciliation reports for a selected period.
Through API, you can also check the current network status and available liquidity, and before creating a payout — verify the address, the need for a memo or tag, AML restrictions, and the feasibility of the operation.
Late payment on an expired deposit is no longer lost: the system records it, after which a decision can be made to credit or refund the funds. Inserted Markdown
The "Sites" section has been completely redesigned
The connected sites management section has been redesigned.
The list now clearly shows whether the site is ready for operation and if notifications are being delivered correctly.
Settings for each specific site are organized into clear tabs:
Connection · Keys · Notifications · Payments · Billing · General
Settings can be adjusted directly on the page, and the connection process is divided into sequential steps.
Management of the API keys' expiration has been added, allowing you to extend the key for 30, 90, 180, or 365 days or make it permanent.
Fixed issues with displaying a large number of sites, request limits, event subscriptions, and notification settings. Embedded Markdown
Admin panel security enhanced
The employee permissions system and protection for critical actions have been redesigned.
An administrator can no longer change the owner’s password, two-factor authentication, or delete the owner’s account. Employee restrictions by specific sites now apply to all relevant sections, search, reports, and API.
A unified 2FA confirmation window is used for sensitive actions, which also clearly indicates which specific action is being confirmed.
User session security has been enhanced: tokens are refreshed during renewal, sessions are tied to the browser, and reuse of an old token results in session termination and user notification.
Additional security event notifications have been added, 2FA brute-force protection, and automatic logout after prolonged inactivity. Inserted Markdown
Encryption master key rotation has also been improved, the audit log expanded, and protection for key and secret operations strengthened. Inserted Markdown
AML and address verification
Improved AML verification and sanctions list handling.
Background checks resume more reliably after failures and avoid generating unnecessary parallel requests.
Sanctions list updates are now protected against incorrect or incomplete data sources.
Address matching for TON has been improved across different formats, and blacklist rules now more precisely consider specific currency settings. Inserted Markdown
Interface updated
The administrative panel has received additional visual and functional enhancements.
Updated login screen, menu, header, cards, dialog windows, and navigation. Forms have more free space, and controls are more consistent.
The panel header now correctly adjusts to the available width, pages no longer switch to incorrect sections, and the open transaction card retains the selected entry when navigating.
Real-time update functionality restored, search through improved by Cmd/Ctrl + K, fixed saving of JSON settings and several minor interface issues. Inserted Markdown
The dashboard is now faster
Additional optimization of the client-side has been completed.
The initial volume of the admin panel has been reduced from 725 to 439 KB, resulting in loading becoming approximately 39% faster.
Payment page for clients reduced from 394 to 206 KB and loads about twice as fast. Inserted Markdown
Server and Updates
The server infrastructure of iEXWallet has been further enhanced.
SSRF protection has been enhanced; sensitive data no longer appears in service logs, the backend now defaults to operating only through the local interface, and Redis is secured with a password.
The update system only accepts signed archives. Backups are saved with restricted access rights, automatically retaining the last five copies.
Improvements were made to the update process on servers using systemd, including better handling of cases where database migration fails. Inserted Markdown Inserted Markdown

