Android reverse engineering · Integrity and anti-tamper
Anti-tamper that fails safe, or fails quietly.
A tamper check compares a file against a value the author recorded, then decides what to do when they do not match. The choice is what matters. Some checks stop the app. Some let it run and break a single feature later, so nothing obvious happens at first.
// the app reads its own signing certificate val sig = pkgInfo.signatures.first().toByteArray() val mine = app.expectedSignature() // the constant-time compare. Either it throws, or it does not. if (!MessageDigest.isEqual(sig, mine)) { throw SecurityException("tampered") // fails safe, or return null // fails quietly, later }
Fig. 01 · the whole protection is one decision, and it is easy to find
Two ways to fail
Loud, or quiet. The difference changes your approach.
Fail loudly (fails safe)
Fail quietly (soft brick)
app opens normally check fails, result ignored one feature breaks hours later the failing call is hidden
Fig. 02 · the quiet one is the hard one to see
A loud check is easy to notice and easy to locate. A quiet check can pass your first test because nothing appears broken, then a server call goes wrong in a build that looks identical to the release. The reliable way to find it is to compare the network output of a modified build against a known-good baseline.
The checks
Where the comparisons live, and how you read them.
The app reads its signing certificate through PackageInfo.signatures and compares bytes. Search for a comparison against a stored digest after a call to getPackageInfo. The workaround is to read the value the app computed and reuse it, not to change the file that produced it.
The app hashes its own classes.dex and compares the result with a constant. Search for a MessageDigest that reads the app's own assets or its own file descriptor. The check runs on a copy, so you point it at the original dex instead of the modified one.
The same pattern appears in .so files, often read from the native library's own code region. A scan loop over the module base, or a read of the file back off disk, ends in a compare. The workaround is to keep the bytes it reads unchanged while changing behavior elsewhere.
Assets, layouts and raw resources are hashed too, so a repackaged resource fails the check. The workaround is to patch the code that calls the affected resource rather than replace the resource, keeping the expected hash intact.
The route
Read what the app reads, then reuse it.
An integrity check is local. It decides whether the running image is the released one. The app still has to talk to its server, and in many apps the value the check verifies is the same value that goes into a request header or a signature.
We trace the integrity check to its inputs and callers, then compare an unmodified run with the failing run. That shows whether the check stops execution, changes a request value or reports a result to the server.
import sreverse sig = sreverse.read_signature(apk) # the app's own certificate digest cl = sreverse.client(cert=sig) token = cl.login(device_id, secret) # same flow, outside the UI
Fig. 03 · a signature is often also a request parameter
Start a project
Something breaks only in the modified build.
Send the full APK. We locate every relevant check and return a fixed quote for the complete API reconstruction.
One full APK. One complete delivery.
Projects start at $120. Most are delivered in 24 to 72 hours.
Every format included
Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.
Ready in 24–72 hours
The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.
Deployment checked before the quote
The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.
30 days of fixes
Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.