Greatminds Security Review
A security-focused code review of Greatminds' fintech mobile app and backend ahead of app store submission. Found a live payment-processor secret key hardcoded directly into the compiled mobile app bundle (extractable by decompiling the APK/IPA), user PINs and payment tokens being written to production logs, and account-deletion flows that retained KYC/BVN/NIN data after a user requested deletion. All flagged issues were remediated before submission.
Greatminds Security Review
A security-focused code review of Greatminds' fintech mobile app and backend ahead of app store submission. Found a live payment-processor secret key hardcoded directly into the compiled mobile app bundle (extractable by decompiling the APK/IPA), user PINs and payment tokens being written to production logs, and account-deletion flows that retained KYC/BVN/NIN data after a user requested deletion. All flagged issues were remediated before submission.
Technologies Used
Results
Hardcoded payment secret, PII/PIN log exposure, and data-retention gaps found and fixed pre-launch
