Muun: Bitcoin Lightning WalletGoogle Play
Our wallet review process
We examine wallets starting at the code level and continue all the way up to the finished app that lives on your device. Provided below is an outline of each of these steps along with security tips for you and general test results.
Application build test result
With this test script (?) we get:
===== Begin Results ===== appId: io.muun.apollo signer: 026ae0ac859cc32adf2d4e7aa909daf902f40db0b4fe6138358026fd62836ad1 apkVersionName: 50.13 apkVersionCode: 1013 verdict: appHash: d9eab324dc83c171350ca4918bb24e0f14dda06f4f7b3cfa0c5f9ab86ca5ea60 commit: 58c9c82a68e63b3ae005fed05621be0cf869cc05 Diff: Only in /tmp/fromPlay_io.muun.apollo_1013/META-INF: APOLLORE.RSA Only in /tmp/fromPlay_io.muun.apollo_1013/META-INF: APOLLORE.SF Only in /tmp/fromPlay_io.muun.apollo_1013/META-INF: MANIFEST.MF Files /tmp/fromPlay_io.muun.apollo_1013/resources.arsc and /tmp/fromBuild_io.muun.apollo_1013/resources.arsc differ Revision, tag (and its signature): object 58c9c82a68e63b3ae005fed05621be0cf869cc05 type commit tag v50.13 tagger acrespo <firstname.lastname@example.org> 1684797231 -0300 v50.13 (1013) ===== End Results =====
resources.arsc files and compare:
$ aapt2 dump resources apollo.apk > fromPlay.txt $ aapt2 dump resources /tmp/test_io.muun.apollo/app/apk/apolloui-prod-release-unsigned.apk > fromBuild.txt $ diff fromPlay.txt fromBuild.txt 11708c11708 < () "e2e27f098f0f4dd5bd472ec4d8b0ba2d" --- > () "10abb903957f4fe18afcf69d8156997d"
The diff is related to
com.crashlytics.android.build_id string value which is an
issue in Crashlytics.
Sadly, while looking benign, that is not reproducible.
Tests performed by Leo Wandersleb, mohammad
Previous application build tests
|19th September 2022||49.3|
|15th April 2022||49.2|
|24th March 2022||49.1|
|9th October 2021||46.10|
|6th April 2021||45.2|
|29th December 2019||beta-36.2|
Do your own research
In addition to reading our analysis, it is important to do your own checks. Before transferring any bitcoin to your wallet, look up reviews for the wallet you want to use. They should be easy to find. If they aren't, that itself is a reason to be extra careful.