bKash

bKash Limited · bKash is a mobile financial services app that lets you pay, send, and manage money securely.

Flutter Finance bKash Limited
Bundle ID com.bKash.customerapp
Version analyzed 7.2.0
Build framework Flutter
SDKs detected 9
Analyzed 2026-09-12
Exploratory agent run

What bKash does

The bKash mobile application is a financial services platform designed for digital transactions, peer-to-peer money transfers, and mobile account management. It utilizes a mobile-number-based authentication system and supports multi-language localization (English and Bengali) to facilitate financial inclusion. The application integrates core fintech modules such as airtime top-ups, contactless NFC payments, and secure user registration protocols, while managing external web redirects for legal compliance and security verification.

Observed on screen

  • User Authentication and Registration Facilitates secure account access and onboarding through mobile number verification and SMS-based notification consent.
  • Mobile Airtime Recharge Enables users to perform instant credit top-ups for their registered mobile devices directly within the application interface.
  • Peer-to-Peer Fund Transfers Supports the "Send Money" protocol, including optimized transaction features for frequently used "Priyo" (favorite) numbers.
  • NFC Contactless Payments Implements Near Field Communication technology to allow users to execute "Tap to Pay" transactions at supported point-of-sale terminals.
  • Multi-Language Localization Provides a toggleable interface between English and Bengali to accommodate diverse user demographics and regional requirements.
  • External Web Integration Manages secure redirects to external browser environments for displaying comprehensive terms of service and executing security challenges.
  • International Dialing Support Includes a country code selection module to facilitate registration for users across different geographic regions, such as Germany (+49).

Written from a FlyTrap agent exploring the app on a real device, not from the store listing. It covers only the screens that run reached, so anything behind a login, paywall or region lock is absent.

Static + runtime analysis

SDKs detected

9 SDKs found across 8 categories. Click any SDK to see every other app that uses it.

All SDKs
From manifest + Info.plist

Permissions requested 12 sensitive

25 permissions requested at runtime. Colors reflect platform sensitivity tier.

Read contacts sensitive

Read the user's contacts data.

Camera sensitive

Take pictures and record video.

Precise location sensitive

Access exact location via GPS, cell, and Wi-Fi.

Read phone state sensitive

Read phone state, network info, and the device's phone number.

Microphone sensitive

Record audio from the microphone.

Connect to Bluetooth devices sensitive

Connect to paired Bluetooth devices.

Write storage sensitive

Write files to shared external storage. No-op for apps targeting Android 11+.

Read storage sensitive

Read files from shared external storage. Replaced by READ_MEDIA_* on Android 13+.

Post notifications sensitive

Post notifications to the system.

Approximate location sensitive

Access approximate location (network-based).

Modify contacts sensitive

Add, modify, or remove contacts.

Read audio sensitive

Read audio files from shared storage.

Internet access standard

Open network sockets.

Bluetooth (legacy) standard

Connect to paired Bluetooth devices on Android 11 and below.

Bluetooth admin (legacy) standard

Discover and pair Bluetooth devices on Android 11 and below.

Vibrate standard

Control the vibrator.

Network state standard

Read connectivity information.

Wi-Fi state standard

Read Wi-Fi connection information.

Biometric authentication standard

Authenticate using biometric hardware.

Fingerprint authentication standard

Authenticate using fingerprint hardware.

Wake lock standard

Keep the device awake.

Foreground service standard

Run a foreground service.

NFC standard

Perform I/O over NFC.

Reorder tasks standard

Move tasks within the back stack.

Change Wi-Fi state standard

Change Wi-Fi connectivity state.

Frequently asked questions

What FlyTrap detected inside bKash.

What does bKash do?

The bKash mobile application is a financial services platform designed for digital transactions, peer-to-peer money transfers, and mobile account management. It utilizes a mobile-number-based authentication system and supports multi-language localization (English and Bengali) to facilitate financial inclusion. The application integrates core fintech modules such as airtime top-ups, contactless NFC payments, and secure user registration protocols, while managing external web redirects for legal compliance and security verification. This comes from a FlyTrap agent exploring the app on a real device, so it covers only the screens that run reached.

What is bKash built with?

bKash by bKash Limited is built with Flutter. FlyTrap determined this by analyzing the app's compiled binary, not from anything the developer published.

What SDKs does bKash use?

FlyTrap detected 9 third-party SDKs inside bKash, including Firebase Analytics, Firebase Cloud Messaging and Firebase Crashlytics. They span areas such as Analytics, Push Notifications, Crash Reporting and Anti-Abuse. The full list, grouped by category, is on this page.

What permissions does bKash request?

bKash requests 25 permissions. 12 of these are sensitive, such as Read contacts, Camera and Precise location. Each is listed above with its platform sensitivity tier.

Is bKash safe to use?

FlyTrap reports what an app contains, it does not issue a safety verdict. bKash requests 25 permissions (12 sensitive) and bundles 9 third-party SDKs. Reviewing those alongside the developer helps you decide what you are comfortable granting.

What platforms is bKash available on?

The version FlyTrap analyzed targets Android.