8 September 2026

Two Years of Continuous Security with Banana Gun

Two Years of Continuous Security with Banana Gun
3 min. readAv Borg

Banana Gun has been a major part of the onchain trading ecosystem for years, processing significant trading activity across its products.

Banana Gun’s infrastructure has processed more than $16B+ in cumulative trading volume and 26M+ lifetime trades.

Borg has been working alongside the Banana Gun team on security for more than two years.

They were one of our earliest clients, and the relationship has since developed into what we now call Forward Deployed Security (FDS): continuous security work that evolves alongside the product.

Security at scale

When a platform is responsible for billions of dollars in trading activity, security cannot be treated as something that happens once a year.

Banana Gun ships quickly. Over the years we have worked together, its products, infrastructure and overall attack surface have changed substantially.

As software development has accelerated, the gap between what gets shipped and what has actually been security-tested has only become more important.

Rather than testing a fixed application once and coming back twelve months later, Borg has continuously worked across Banana Gun's environment as new functionality has been introduced and existing systems have evolved.

That has meant maintaining context on the platform over time and repeatedly approaching it from an offensive perspective.

A strong team on the other side

The model works best when security is taken seriously internally.

The Banana Gun team has consistently been hands-on throughout our work together.

When something requires attention, their engineers are quick to investigate, understand the underlying issue and implement changes. They also work closely with us when new functionality or infrastructure needs to be tested.

Borg is not there to replace that ownership.

We are there to provide an additional offensive security layer around an already highly capable engineering team.

Why continuous security?

Traditional penetration testing is valuable, but it fundamentally represents a point in time.

That model becomes harder to rely on as software starts moving faster. Teams can now ship changes daily or even hourly, while security testing is still often performed quarterly or annually.

Infrastructure moves as new integrations occur. Entire products launch, often long before the next scheduled security review.

For a platform processing billions of dollars in trading volume, that gap matters.

The attack surface does not stand still and security testing should not either.

That is the idea behind Borg FDS: maintain the context of a long-term security team while continuously testing from an attacker's perspective as the environment evolves.

With Banana Gun, we have now been operating that way for more than two years.

Growing together

Banana Gun was one of the earliest teams to work with Borg.

Since then, Banana Gun has continued operating at a significant scale, while our approach to continuous offensive security has matured alongside the relationship. If the product keeps changing, the security testing should too.

Borg på
sosiale medier

Borg spesialiserer seg på å sikre komplekse digitale systemer med høy risiko.