Karsten Wenzlaff, Advisor
August 26th, 2025
AI Security | April 22, 2025

Image: Freepik/atlascompany
Perplexity AI is growing fast with over 10 million Android downloads and is backed by tech royalty like Jeff Bezos but a new security report by a Singapore security firm AppKnox found major vulnerabilities that could be exploited by attackers. We're not talking small potatoes here. We're talking about huge issues like hardcoded API keys and significant weaknesses against any sort of malicious hacking.
While Perplexity's android app isn't what most fintechs run their AI service on, it's a red flag about the state of security in the quickly evolving world of artificial intelligence tools that banks, wealthtech platforms, and credit unions are exploring, embedding, investing and integrating in..
Perplexity’s Android app includes private access keys that should not be exposed. These keys work like internal passwords and were stored inside the app itself. This makes it easy for anyone with technical skills to find and misuse them. These hardcoded credentials could be downloaded and used to access Perplexity's AI full system completely for free.
Another serious problem is that the app does not check if it is connecting to a real or fake server. Cybernews reports that someone on public WiFi could take advantage of this to spy on what users are doing. This might include watching what they search, type, or log in to.
The app has not fixed several known security flaws that have existed in Android for years, such as StrandHogg and Janus are still present. These are weaknesses that hackers already understand and can use to gain control or access private information.
Perplexity's app doesn't check if a phone is rooted or not, and it's less secure if it is.
The app’s code is also not protected. This means someone could open it up, look inside, and understand exactly how it works. They could then use this to find more vulnerabilities to attack or copy its features.
The app can be tricked into letting attackers control parts of the screen without the user knowing. So, you could be typing into a pop-up form or something that looks familiar but it's actually a trap that can steal your information.
How is it possible that a high profile AI unicorn like Perplexity ships a mobile app that fails basic security checks? If they are missing the basics, how many others are? This raises a critical question for fintechs and financial institutions looking to integrate AI whether it's a chatbot, SDK, API, or embedded assistants.
Are you checking how secure your vendors really are?
It's a reality check that a soaring valuation doesn’t guarantee strong engineering discipline.
Where are the API keys stored? If they live in the mobile app code, that’s a no-go.
Does the vendor use SSL validation and pinning? If not, data can be intercepted over public WiFi.
Are known vulnerabilities patched? Run a third party scan or ask for one.
Is the code protected? If it’s not, attackers can easily reverse-engineer how it works.
Does the app detect rooted or jailbroken devices? If not, it might be operating in a compromised environment.
What’s the vendor’s breach response plan? Ask how they handle disclosures, patches, and updates.
How much access are you really giving? Use API scopes, rate limits, and narrow permissions by default.
Perplexity's Android app glaring security risks is a textbook example of what happens when security gets left behind in a rush to launch/scale products out the door. Don't ever forget that financial data isn't forgiving when it leaks. Whether you're exploring AI for customer support, product recommendations, or internal workflows, you need to prioritize the app and API security for your use case. Trust is earned but it can be lost in a heart beat.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
August 26th, 2025
January 4th, 2024
June 1st, 2021
September 9th, 2020
July 9th, 2018
January 3rd, 2018
September 25th, 2017
June 20th, 2017
May 10th, 2017
December 14th, 2016

NCFA Canada
Craig Asano
CEO and Executive Director
casano@ncfacanada.org
ncfacanada.org





Leave a Reply