Audit report published Aug 2026. iOS and Android (Flutter) · Dart.
| Severity | Count |
|---|---|
| High | 1 |
| Low | 1 |
| Informational | 4 |
| Total | 6 |
Safe Edges reviewed the SNPIT Flutter mobile app codebase (snpit-app-develop). Six issues were identified: one High, one Low, three Informational and one Note. The High issue was that fake-location detection runs only on Android while the backend accepts client-supplied GPS coordinates for location-based rewards and battle multipliers, so spoofed locations can claim rewards. The original report did not record resolution statuses.
H-01 Location Spoofing Enables Reward Abuse By Intentionally Allowing iOSL-01 Sentry Crash Reporting Includes User PII Without Proper ScrubbingI-01 Global iOS App Transport Security Bypass EnabledI-02 Marketplace One-Time JWT Passed Through URL Query ParameterI-03 Plaintext Local Storage of Access Tokens and Location MetadataN-01 Privy Wallet Linking Could Potentially Accept Unverified WebView JavaScript MessagesSend the repository and a commit hash through the contact form, message @bugtester25 on Telegram, or book a 30-minute scoping call. 200+ protocols audited · $4B+ secured · 0 hacks post-audit. Prefer email? info@safeedges.in.