Introduction
We express our gratitude to the THG AssetGuard Wallet team for the collaborative engagement that enabled the execution of this Pentest.
The Hashgraph Group is a pioneering Swiss-based Web3 technology, venture capital, and business innovation company operating exclusively within the Hedera Hashgraph ecosystem . They design, develop, and deploy enterprise-grade decentralized applications built on Hedera, enabling trustworthy, verifiable, and secure value transactions.
Document | |
|---|---|
| Name | Pentest and Security Analysis Report for THG AssetGuard |
| Audited By | Adedolapo Olayinka-Adeyemi |
| Approved By | Stephen Ajayi |
| Website | https://www.hashgraph-group.com/products/assetguard→ |
| Changelog | 27/08/2025 - Preliminary Report |
| Platform | Android |
| Language | Java |
| Tags | Pentest, GrayBox |
| Methodology | https://hackenio.cc/pentest_methodology→ |
Document
- Name
- Pentest and Security Analysis Report for THG AssetGuard
- Audited By
- Adedolapo Olayinka-Adeyemi
- Approved By
- Stephen Ajayi
- Changelog
- 27/08/2025 - Preliminary Report
- Platform
- Android
- Language
- Java
- Tags
- Pentest, GrayBox
- Methodology
- https://hackenio.cc/pentest_methodology→
Review Scope | |
|---|---|
| Android | https://play.google.com/store/apps/details?id=org.thg.wallettest→ |
| version | 1.0.7 |
Review Scope
- version
- 1.0.7
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
System Overview
The Hashgraph Group delivers a powerful and intuitive Android-based mobile application accessible on Android devices. The application serves as a gateway for users to interact with Hedera-based services such as managing digital assets, decentralized identities, or ecosystem integrations through a user-centric interface.
Android Application Overview
Key features of the application include:
Core Platform Functionality: The app displays real-time account balances (e.g., showing total balance and available tokens like Hedera HBAR), and provides options for token management with actions such as Buy / Sell / Swap.
Portfolio and Account Management: A centralized interface shows key account metrics and facilitates actions such as adding new tokens via prompts like “+ Add Token.” Users can also manage their assets through intuitive navigation tabs (Home, Swap, Profile, History), enhancing usability and control.
Security Measures: A prominent notification—“Protect Your Assets: Save Your Secret Phrase Now”—indicates that the app relies on private key or mnemonic-based authentication and emphasizes secure handling and storage of sensitive credentials. Secure session handling and potential use of platform-level protection (e.g., Android Keystore) are implied.
User-Friendly Interface: The app features a clean, modern design with responsive navigation elements. Key actions (e.g., Buy/Sell/Swap, token management) are clearly accessible. The layout displays context-relevant information, ensuring users can perform vital operations with minimal friction, even on mobile screens.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2025-1237 | Overly Permissive FileProvider Configuration | fixed | Low | |
| F-2025-1237 | Exported Testing Activities in Production Build | fixed | Low | |
| F-2025-1236 | Insecure Network Security Configuration (Missing Cleartext Traffic Restrictions) | fixed | Low | |
| F-2025-1237 | Absence of User Data Preservation Prompt on Uninstall | accepted | Observation | |
| F-2025-1237 | Use of Deprecated License Verification Permission | accepted | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes the following:
Scope Details | |
|---|---|
| Android | https://play.google.com/store/apps/details?id=org.thg.wallettest→ |
| version | 1.0.7 |
Scope Details
- version
- 1.0.7