Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[PT] THG AssetGuard Wallet | Android App Pentest | Aug2025

Date:

Oct 3, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the THG AssetGuard Wallet team for the collaborative engagement that enabled the execution of this Pentest.

The Hashgraph Group is a pioneering Swiss-based Web3 technology, venture capital, and business innovation company operating exclusively within the Hedera Hashgraph ecosystem . They design, develop, and deploy enterprise-grade decentralized applications built on Hedera, enabling trustworthy, verifiable, and secure value transactions.

Document

NamePentest and Security Analysis Report for THG AssetGuard
Audited ByAdedolapo Olayinka-Adeyemi
Approved ByStephen Ajayi
Websitehttps://www.hashgraph-group.com/products/assetguard→
Changelog27/08/2025 - Preliminary Report
PlatformAndroid
LanguageJava
TagsPentest, GrayBox
Methodologyhttps://hackenio.cc/pentest_methodology→

Protect your dApp with insights like these.

Audit Summary

5Total Findings
3Resolved
2Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

System Overview

The Hashgraph Group delivers a powerful and intuitive Android-based mobile application accessible on Android devices. The application serves as a gateway for users to interact with Hedera-based services such as managing digital assets, decentralized identities, or ecosystem integrations through a user-centric interface.

Android Application Overview

Key features of the application include:

  • Core Platform Functionality: The app displays real-time account balances (e.g., showing total balance and available tokens like Hedera HBAR), and provides options for token management with actions such as Buy / Sell / Swap.

  • Portfolio and Account Management: A centralized interface shows key account metrics and facilitates actions such as adding new tokens via prompts like “+ Add Token.” Users can also manage their assets through intuitive navigation tabs (Home, Swap, Profile, History), enhancing usability and control.

  • Security Measures: A prominent notification—“Protect Your Assets: Save Your Secret Phrase Now”—indicates that the app relies on private key or mnemonic-based authentication and emphasizes secure handling and storage of sensitive credentials. Secure session handling and potential use of platform-level protection (e.g., Android Keystore) are implied.

  • User-Friendly Interface: The app features a clean, modern design with responsive navigation elements. Key actions (e.g., Buy/Sell/Swap, token management) are clearly accessible. The layout displays context-relevant information, ensuring users can perform vital operations with minimal friction, even on mobile screens.

Findings

F-2025-1237Overly Permissive FileProvider Configuration
Status
fixed
Severity

Low
F-2025-1237Exported Testing Activities in Production Build
Status
fixed
Severity

Low
F-2025-1236 Insecure Network Security Configuration (Missing Cleartext Traffic Restrictions)
Status
fixed
Severity

Low
F-2025-1237Absence of User Data Preservation Prompt on Uninstall
Status
accepted
Severity

Observation
F-2025-1237Use of Deprecated License Verification Permission
Status
accepted
Severity

Observation
Code
―
Title
Status
Severity
F-2025-1237Overly Permissive FileProvider Configuration
fixed

Low
F-2025-1237Exported Testing Activities in Production Build
fixed

Low
F-2025-1236 Insecure Network Security Configuration (Missing Cleartext Traffic Restrictions)
fixed

Low
F-2025-1237Absence of User Data Preservation Prompt on Uninstall
accepted

Observation
F-2025-1237Use of Deprecated License Verification Permission
accepted

Observation
1-5 of 5 findings

Uncover findings like these to secure your project.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following:

Disclaimer