
Key takeaways
- Researcher overtorment says the review identified 904 App Store listings marketed as noncustodial Bitcoin wallets across several categories
- The researcher analyzed 494 wallets for private key exfiltration and weak entropy, then flagged 45 apps for further concern
- After an independent pass, the researcher classifies 23 findings as potentially critical and 22 as potentially high risk
A security researcher reported identifying 904 App Store listings marketed as noncustodial Bitcoin wallets, and analyzing 494 of them. The review looked for code that could exfiltrate private keys or was built on weak entropy, among other warning signs. The researcher initially flagged 45 apps, then described 23 as potentially critical and 22 as potentially high after an independent pass.
A large review with a narrow claim
The researcher said the starting set contained 904 App Store listings marketed as noncustodial Bitcoin wallets across several categories. Of those, 494 were analyzed. The review focused on code behaviors that could expose wallet secrets, including exfiltrating private keys and weak entropy.
The researcher flagged 45 apps for further concern. After a separate independent pass, the researcher retained 23 findings as potentially critical and 22 as potentially high risk. Those labels described the researcher's assessment of potential problems; the report did not establish confirmed theft, exploitation, or customer loss across those apps.
Private keys and weak entropy drove the screening
The researcher said the screening examined two specific behaviors among others: code that exfiltrates a wallet's private key, and weak entropy during key creation. The first means the app sends or exposes the secret that controls the wallet. The second means the randomness behind that secret is not random enough.
The researcher also acknowledged that false positives were possible. That warning matters when reading the counts: 45 apps raised red flags in the review, while 23 were classified as potentially critical and 22 as potentially high after the independent pass. The numbers were not a tally of confirmed thefts or exploited users.
The report questions trust in a single device
Based on the findings, the researcher recommended against relying on a single mobile device as the only signer for meaningful funds. That recommendation was the researcher's response to potential private key exfiltration and weak entropy found during the review. It is not a finding that every mobile wallet is unsafe.
The report's real distinction is between a wallet listing's noncustodial marketing and what the code actually does. The researcher treated custody claims as something that needed inspection, because the review looked directly for private key leaks and weak entropy. The 45 flagged apps are candidates for further scrutiny, not confirmed incidents of customer theft.
Why It Matters
The researcher reviewed 494 of 904 App Store listings marketed as noncustodial Bitcoin wallets and flagged 45 for issues that were potentially critical or potentially high risk. Because the screening looked for private key leaks and weak entropy, the review focused on the self-custody code paths that handle the secrets controlling bitcoin. A noncustodial label on an App Store listing (marketing copy, essentially) is not, by itself, evidence of how that code handles keys. The researcher's warning against a single mobile device as the only signer for meaningful funds follows from those risks around how keys are handled, and the acknowledged possibility of false positives keeps the findings provisional.



















