BlueWallet Identifies 45 High-Risk Wallets
According to Bitcoin News, the Chief Technology Officer of BlueWallet disclosed the results of a security screening for non-custodial cryptocurrency wallet applications in the App Store.
The screening covered 904 iOS applications labeled as non-custodial cryptocurrency wallets in the App Store, with the team further analyzing the specific code and behavioral characteristics of 494 applications.
Ultimately, 45 applications were flagged as potentially having serious or high-risk security issues, with 23 classified as potentially severe risks and 22 as high risks. The two categories of risky applications together accounted for about one-tenth of the in-depth analysis sample.
The flagged applications had issues mainly including: allegedly uploading user mnemonic phrases or private keys to servers, insufficient randomness in generated wallet private keys or addresses, storing user keys on the server side, using hard-coded encryption keys, and loading unsigned JavaScript code that could interact with sensitive wallet data. These issues directly relate to the security of user asset private key storage.
The Chief Technology Officer of BlueWallet also reminded that the analysis results may contain false positives, and applications not listed as risky do not necessarily represent safety; he emphasized that in scenarios involving the storage of large amounts of Bitcoin assets, passing App Store review or having a good market reputation is not sufficient to trust the software.
This disclosure has a trust-rebuilding effect on the entire non-custodial wallet market—previously, the App Store was seen as an implicit endorsement of application security, but the screening results indicate that the official app store review mechanism cannot effectively identify security risks related to private key management. This may lead users and institutional investors to prefer wallet products that have undergone independent third-party security audits and have open verifiable code, objectively benefiting leading non-custodial wallets with transparent codebases and public audit records, while putting reputational and customer acquisition pressure on small to medium-sized wallet developers lacking security audit capabilities.
Source: Public Information
ABAB AI Insight
BlueWallet, as an open-source non-custodial wallet focused on Bitcoin for a long time, has previously established a trust base within the Bitcoin user community through open-source code audits and community security reviews. The third-party wallet application security screening led by its Chief Technology Officer continues the team's consistent narrative of "transparency and verifiability" as core product principles.
From a resource investment perspective, conducting a security screening covering nearly a thousand applications requires significant engineering and security research resources. BlueWallet chose to invest these resources in public disclosure and non-commercial security research rather than direct product monetization. Its motivation lies in shaping an image of an "industry security overseer" to indirectly accumulate user trust and brand capital for its open-source, transparent product positioning, representing a path of exchanging security reputation for user mindshare.
This is similar to the public security audits and risk disclosures conducted by several security companies (such as CertiK and SlowMist) for DeFi protocols and exchanges—security audits and risk disclosures are gradually becoming standardized mechanisms for establishing trust in the crypto industry. The difference is that this screening focuses on the mobile wallet application layer, which has been less systematically examined, filling the regulatory gap in private key security within the App Store review mechanism.
Essentially, this is a trust reconstruction spontaneously filled by the industry in the absence of regulation—the Apple App Store's review standards mainly target application functionality compliance and content safety, without including the security of private key generation randomness and key storage methods in mandatory review categories. This regulatory gap has caused a disconnection between the actual security level of wallet applications and their app store ratings and download volumes, and this third-party disclosure is an attempt by the industry to fill the official regulatory void with spontaneous technical audits.
ABAB News · Cognitive Laws
- Just because it passed the listing review does not mean it passed private key security.
- Reputation is the endorsement of traffic; code is the endorsement of assets.
- Where there is regulatory void, the industry will grow its own audits.