Phantom

Technical profile for Phantom.

React Native Uncategorized
Bundle ID app.phantom
Version analyzed 26.13.2
Build framework React Native
SDKs detected 33
Analyzed 2026-08-21
Exploratory agent run

What Phantom does

This mobile application is a multi-chain Web3 wallet and decentralized finance (DeFi) trading platform designed for managing digital assets and executing advanced trading strategies. It supports major blockchain ecosystems including Bitcoin, Ethereum, Solana, and Base, providing a unified interface for spot trading, perpetual futures (Perps), and market discovery. The application integrates social trading elements through token-specific chat rooms and offers a hybrid onboarding experience that supports both traditional mnemonic recovery phrases and social-login-based wallet abstraction.

Observed on screen

  • Multi-Chain Wallet Management Enables non-custodial storage, receiving, and sending of assets across Bitcoin, Ethereum, Solana, and several emerging Layer-2 networks.
  • Flexible Onboarding Offers users the choice between high-security 12-word recovery phrases or streamlined account creation via Google/Apple social authentication.
  • Perpetual Futures Trading Facilitates leveraged long and short positions with technical controls for liquidation prices, auto-close parameters, and margin management.
  • Social Trading Integration Features real-time community chat interfaces for specific tokens, allowing users to discuss market movements and view recent trade activity.
  • Market Analytics and Discovery Provides real-time price charting, 24-hour performance rankings, and categorized asset lists including meme coins and trending tokens.
  • Fiat On-Ramp Includes a simplified "Pay Cash" interface for purchasing cryptocurrency directly within the application.
  • Custom Identity System Allows users to personalize their accounts with unique usernames to facilitate social interactions and simplified addressing.
  • Portfolio Tracking Delivers a comprehensive dashboard for monitoring cash balances, token holdings, and 24-hour returns across multiple blockchain networks.

Written from a FlyTrap agent exploring the app on a real device, not from the store listing. It covers only the screens that run reached, so anything behind a login, paywall or region lock is absent.

Static + runtime analysis

SDKs detected

33 SDKs found across 22 categories. Click any SDK to see every other app that uses it.

All SDKs
From manifest + Info.plist

Permissions requested 11 sensitive

53 permissions requested at runtime. Colors reflect platform sensitivity tier.

Approximate location sensitive

Access approximate location (network-based).

Precise location sensitive

Access exact location via GPS, cell, and Wi-Fi.

Connect to Bluetooth devices sensitive

Connect to paired Bluetooth devices.

Scan for Bluetooth devices sensitive

Discover nearby Bluetooth devices.

Camera sensitive

Take pictures and record video.

Read storage sensitive

Read files from shared external storage. Replaced by READ_MEDIA_* on Android 13+.

Read audio sensitive

Read audio files from shared storage.

Selected photos and videos sensitive

Access only photos and videos the user explicitly selected.

Microphone sensitive

Record audio from the microphone.

Write storage sensitive

Write files to shared external storage. No-op for apps targeting Android 11+.

Post notifications sensitive

Post notifications to the system.

Network state standard

Read connectivity information.

Bluetooth (legacy) standard

Connect to paired Bluetooth devices on Android 11 and below.

Bluetooth admin (legacy) standard

Discover and pair Bluetooth devices on Android 11 and below.

Internet access standard

Open network sockets.

MEDIA LIBRARY standard
Display over other apps standard

Draw windows on top of other apps. Granted from system settings.

Biometric authentication standard

Authenticate using biometric hardware.

Fingerprint authentication standard

Authenticate using fingerprint hardware.

Vibrate standard

Control the vibrator.

com.google.android.gms.permission.AD ID standard
Wi-Fi state standard

Read Wi-Fi connection information.

Wake lock standard

Keep the device awake.

Modify audio settings standard

Modify global audio settings.

Foreground service standard

Run a foreground service.

Foreground service: media playback standard

Required for foreground services of type mediaPlayback.

Run at startup standard

Receive the BOOT_COMPLETED broadcast.

com.google.android.c2dm.permission.RECEIVE standard
ACCESS ADSERVICES ATTRIBUTION standard
com.samsung.android.mapsagent.permission.READ APP INFO standard
com.huawei.appmarket.service.commondata.permission.GET COMMON DATA standard
ACCESS ADSERVICES AD ID standard
com.google.android.finsky.permission.BIND GET INSTALL REFERRER SERVICE standard
app.phantom.DYNAMIC RECEIVER NOT EXPORTED PERMISSION standard
com.google.android.providers.gsf.permission.READ GSERVICES standard
com.solanamobile.seedvault.ACCESS SEED VAULT standard
com.sec.android.provider.badge.permission.READ standard
com.sec.android.provider.badge.permission.WRITE standard
com.htc.launcher.permission.READ SETTINGS standard
com.htc.launcher.permission.UPDATE SHORTCUT standard
com.sonyericsson.home.permission.BROADCAST BADGE standard
com.sonymobile.home.permission.PROVIDER INSERT BADGE standard
com.anddoes.launcher.permission.UPDATE COUNT standard
com.majeur.launcher.permission.UPDATE BADGE standard
com.huawei.android.launcher.permission.CHANGE BADGE standard
com.huawei.android.launcher.permission.READ SETTINGS standard
com.huawei.android.launcher.permission.WRITE SETTINGS standard
READ APP BADGE standard
com.oppo.launcher.permission.READ SETTINGS standard
com.oppo.launcher.permission.WRITE SETTINGS standard
me.everything.badger.permission.BADGE COUNT READ standard
me.everything.badger.permission.BADGE COUNT WRITE standard
com.android.vending.CHECK LICENSE standard

Frequently asked questions

What FlyTrap detected inside Phantom.

What does Phantom do?

This mobile application is a multi-chain Web3 wallet and decentralized finance (DeFi) trading platform designed for managing digital assets and executing advanced trading strategies. It supports major blockchain ecosystems including Bitcoin, Ethereum, Solana, and Base, providing a unified interface for spot trading, perpetual futures (Perps), and market discovery. The application integrates social trading elements through token-specific chat rooms and offers a hybrid onboarding experience that supports both traditional mnemonic recovery phrases and social-login-based wallet abstraction. This comes from a FlyTrap agent exploring the app on a real device, so it covers only the screens that run reached.

What is Phantom built with?

Phantom is built with React Native. FlyTrap determined this by analyzing the app's compiled binary, not from anything the developer published.

What SDKs does Phantom use?

FlyTrap detected 33 third-party SDKs inside Phantom, including Amplitude, BLE PLX (react-native-ble-plx) and Crossmint. They span areas such as Analytics, Hardware Wallet, Web3 Wallet and Monitoring. The full list, grouped by category, is on this page.

What permissions does Phantom request?

Phantom requests 53 permissions. 11 of these are sensitive, such as Approximate location, Precise location and Connect to Bluetooth devices. Each is listed above with its platform sensitivity tier.

Is Phantom safe to use?

FlyTrap reports what an app contains, it does not issue a safety verdict. Phantom requests 53 permissions (11 sensitive) and bundles 33 third-party SDKs. Reviewing those alongside the developer helps you decide what you are comfortable granting.

What platforms is Phantom available on?

The version FlyTrap analyzed targets Android.