Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[PT] Zoomex | Android App Pentest | Sep2025

Date:

Oct 20, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Zoomex team for the collaborative engagement that enabled the execution of this Pentest.

Document

NamePentest and Security Analysis Report for Zoomex
Audited By
Approved By
Websitehttp://zoomex.com/→
Changelog22/09/2025 - Preliminary Report
PlatformAndroid
LanguageFlutter
TagsAndroid Mobile Application Pentest
Methodologyhttps://hackenio.cc/pentest_methodology→

Protect your dApp with insights like these.

Audit Summary

7Total Findings
2Resolved
5Accepted
0Mitigated

Audit Summar

The system users should acknowledge all the risks summed up in the risks section of the report

System Overview

Zoomex - the digital asset trading platform, providing users with derivative trading services for a wide range of assets, including Bitcoin (BTC), Ethereum (ETH), Dogecoin (DOGE), and many more.

Zoomex currently supports trading pairs such as Bitcoin (BTC), Ethereum (ETH), Bitcoin Cash (BCH), Chainlink (LINK), Litecoin (LTC), Cardano (ADA), Polkadot (DOT), EOS (EOS), Ripple (XRP), Uniswap (UNI), DASH, DOGE, FIL, and XLM. Additionally, high-performing assets like Solana (SOL), Decentraland (MANA), and Avalanche (AVAX) are also available for both spot and derivative trading.

Features Supported by Zoomex: \- Spot Trading: Professional settings for limit orders, allowing simultaneous stop-loss and take-profit settings when placing orders. \- Perpetual Contract Trading: Supports up to 120x leverage to maximize returns, with one-click closing for easy management of all positions. \- Copy Trading: Follow professional traders worldwide with one click. Even beginners can earn stable returns with zero entry barriers.

Findings

F-2025-1310Pattern Lock Brute Forcing
Status
accepted
Severity

Low
F-2025-1309Sensitive Information Stored in Plaintext Within App Sandbox
Status
fixed
Severity

Low
F-2025-1309Sensitive Information Visible in App Switcher Screenshots
Status
accepted
Severity

Low
F-2025-1312Lack of Anti-Hook and Anti-Debug Protections
Status
accepted
Severity

Observation
F-2025-1310Sensitive Data Exposed via Clipboard
Status
accepted
Severity

Observation
F-2025-1310Insecure Network Traffic Configuration
Status
fixed
Severity

Observation
F-2025-1309Application Can Be Launched on Rooted Device and Emulator
Status
accepted
Severity

Observation
Code
―
Title
Status
Severity
F-2025-1310Pattern Lock Brute Forcing
accepted

Low
F-2025-1309Sensitive Information Stored in Plaintext Within App Sandbox
fixed

Low
F-2025-1309Sensitive Information Visible in App Switcher Screenshots
accepted

Low
F-2025-1312Lack of Anti-Hook and Anti-Debug Protections
accepted

Observation
F-2025-1310Sensitive Data Exposed via Clipboard
accepted

Observation
F-2025-1310Insecure Network Traffic Configuration
fixed

Observation
F-2025-1309Application Can Be Launched on Rooted Device and Emulator
accepted

Observation
1-7 of 7 findings

Uncover findings like these to secure your project.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following:

Disclaimer