90% of Crypto Mobile Apps 'In Trouble,' Security Report Claims

A new report suggests mobile wallets catering to the cryptocurrency market may not be as secure as consumers may desire.

AccessTimeIconNov 29, 2017 at 4:55 a.m. UTC
Updated Dec 10, 2022 at 8:20 p.m. UTC

The vast majority of mobile cryptocurrency wallet apps employ poor security.

Or so claims new researchhttps://www.htbridge.com/news/security-cryptocurrency-mobile-apps.html from San Francisco security firm High-Tech Bridge based on an analysis of more than 2,000 apps on Google Play. Of the first 30 crypto apps with up to 100,000 total installations, 93 percent contain at least three "medium-risk" vulnerabilities and 90 percent contain at least two "high-risk" issues.

Among the most-downloaded apps, the numbers are a little better, but not by much. Ninety-four percent of apps with over 500,000 installations contain at least three "medium-risk" vulnerabilities and 77 percent contain at least two high-risk vulnerabilities.

The most common vulnerabilities, according to the analysis, include "insecure data storage," which means information that should be private can leak unintentionally, and "insufficient cryptography," which indicates some form of cryptography was implemented to shield data, but was used incorrectly.

In short, this means users might be at risk.

"Depending on the application functionality, design and vulnerabilities, a wide spectrum of nuisances is possible, up to sensitive data and even the wallet (private key) theft," said Ilia Kolochenko, CEO and founder of High-Tech Bridge.

He added:

"Unfortunately, I am not surprised with the outcomes of the research."

Kolochenko attributes the poor scores to a lack of emphasis on security across mobile development.

"For many years, cybersecurity companies and independent experts were notifying mobile app developers about the risks of 'agile' development that usually imply no framework to assure secure design, secure coding and hardening techniques or application security testing," he added.

Users and developers can use the company's free security analysis tool, Mobile X-Rayhttps://www.htbridge.com/mobile/, to plug in mobile apps and see the vulnerabilities for themselves.

However, when it comes to securing funds, there's plenty that can go wrong. The tech firm implies that its own research doesn't go far enough. Its analysis, for instance, only looks at the frontend of the apps, and there could be other problems in the backend.

The report remarks: "This is just the tip of the iceberg."

Broken lock image via Shutterstock


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.