Insecure App Making
Anand Venkatanarayanan

The weak point in this case you have corroborated is the leakage of the API_KEY, as it could then be misused. IMO, if API_KEY is secured and not embedded in the APK, then the entire disassembly of the APK would not yield the key.

