Global fintech and funding innovation ecosystem

Perplexity’s Security Flaws A Red Flag for Industry

AI Security | April 22, 2025

Freepik atlascompany, security risks

Image: Freepik/atlascompany

Why Perplexity's App Flaws Should Alarm Anyone Building with AI

Perplexity AI is growing fast with over 10 million Android downloads and is backed by tech royalty like Jeff Bezos but a new security report by a Singapore security firm AppKnox found major vulnerabilities that could be exploited by attackers.  We're not talking small potatoes here.  We're talking about huge issues like hardcoded API keys and significant weaknesses against any sort of malicious hacking.

See:  Perplexity AI Sued for Copyright Infringement

While Perplexity's android app isn't what most fintechs run their AI service on, it's a red flag about the state of security in the quickly evolving world of artificial intelligence tools that banks, wealthtech platforms, and credit unions are exploring, embedding, investing and integrating in..

What Appknox Found in Perplexity’s Android App

Perplexity’s Android app includes private access keys that should not be exposed. These keys work like internal passwords and were stored inside the app itself. This makes it easy for anyone with technical skills to find and misuse them. These hardcoded credentials could be downloaded and used to access Perplexity's AI full system completely for free.

Another serious problem is that the app does not check if it is connecting to a real or fake server. Cybernews reports that someone on public WiFi could take advantage of this to spy on what users are doing. This might include watching what they search, type, or log in to.

The app has not fixed several known security flaws that have existed in Android for years, such as StrandHogg and Janus are still present. These are weaknesses that hackers already understand and can use to gain control or access private information.

Perplexity's app doesn't check if a phone is rooted or not, and it's less secure if it is.

The app’s code is also not protected. This means someone could open it up, look inside, and understand exactly how it works. They could then use this to find more vulnerabilities to attack or copy its features.

See:  Why No Code AI Agents Matter for Fintech in Canada

The app can be tricked into letting attackers control parts of the screen without the user knowing. So, you could be typing into a pop-up form or something that looks familiar but it's actually a trap that can steal your information.

Implications Even If You Don’t Use the App

How is it possible that a high profile AI unicorn like Perplexity ships a mobile app that fails basic security checks?  If they are missing the basics, how many others are?  This raises a critical question for fintechs and financial institutions looking to integrate AI whether it's a chatbot, SDK, API, or embedded assistants.

Are you checking how secure your vendors really are?

It's a reality check that a soaring valuation doesn’t guarantee strong engineering discipline.

Some Security Questions You Should Be Asking

Where are the API keys stored? If they live in the mobile app code, that’s a no-go.

Does the vendor use SSL validation and pinning?  If not, data can be intercepted over public WiFi.

Are known vulnerabilities patched?  Run a third party scan or ask for one.

See:  Is AI Going to Change Fintech Security?

Is the code protected?  If it’s not, attackers can easily reverse-engineer how it works.

Does the app detect rooted or jailbroken devices?  If not, it might be operating in a compromised environment.

What’s the vendor’s breach response plan?  Ask how they handle disclosures, patches, and updates.

How much access are you really giving?  Use API scopes, rate limits, and narrow permissions by default.

Conclusion - You Don’t Have to Use the App to Learn from It

Perplexity's Android app glaring security risks is a textbook example of what happens when security gets left behind in a rush to launch/scale products out the door.  Don't ever forget that financial data isn't forgiving when it leaks.  Whether you're exploring AI for customer support, product recommendations, or internal workflows, you need to prioritize the app and API security for your use case.  Trust is earned but it can be lost in a heart beat.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Leave a Reply

Your email address will not be published. Required fields are marked *