TradeOgre.app Open a verified account Open account

Mobile apps

TradeOgre on Android: no official app, and a sideloading problem

On Android the picture is slightly more complicated than on iOS, and slightly more dangerous. TradeOgre never released an official Android client either — but Android permits installation from outside the Play Store, which means the gap was filled by third-party apps and, inevitably, by APK files distributed from websites. That second category is where the real harm happens, and it is still happening now that the exchange itself is gone.

The short version

There was no official TradeOgre Android app. Third-party clients built against the public API existed on Google Play, published by independent developers with no affiliation to the exchange. Since the platform was seized in September 2025, none of them can connect to anything, and any new app or APK using the name should be treated as malware.

How Android crypto attacks actually work

The techniques used against Android users of crypto apps, and the defence that works against each. None of these are theoretical.

  1. Sideloaded APK

    A site offers a “TradeOgre APK” for direct download, often ranking well for the app search. The file installs an app that looks right and harvests credentials, or requests permissions that let it read everything on screen.

    Install only from the Play Store, reached from the exchange’s own website. Treat any downloadable APK for a financial service as hostile by default.

  2. Accessibility service abuse

    The app requests accessibility permissions “to improve usability”. Those permissions allow it to read screen contents and simulate taps, which is enough to read a 2FA code and approve a transfer.

    Never grant accessibility permissions to a finance app. Audit the accessibility settings menu periodically and revoke anything you do not recognise.

  3. Clipboard address substitution

    Malware watches the clipboard for anything shaped like a crypto address and replaces it with the attacker’s. You paste, the address looks plausible, and the funds go elsewhere.

    Verify the first and last characters of every pasted address against the source, and confirm the full string for any significant transfer.

  4. Screen overlay phishing

    A malicious app draws a fake login screen over the real one. You type your credentials into the overlay while believing you are in the genuine app.

    Review which apps have “display over other apps” permission and disable it for everything that does not clearly need it.

  5. Fake app store listing

    A clone is published to the Play Store with an exchange’s branding and a recently created developer account, sometimes staying benign long enough to pass review before an update adds the payload.

    Check the developer name against the exchange’s published entity, and look for years of release history rather than a recent first version.

There was no official Android app

The reason is the same one that kept TradeOgre off the App Store. Publishing to Google Play requires a developer account tied to an identity, and financial applications face additional verification requirements. An exchange with no named operator, no disclosed company and no regulatory registration cannot complete that process.

So the official mobile experience on Android was identical to the one on iOS: the website in a browser. It worked, it was responsive enough to trade from, and it offered nothing else — no notifications, no biometric unlock, no background alerts.

What differs between the platforms is what happens next. On iOS, an absent official app mostly means users go without. On Android, the ability to install applications from outside the store means a gap in the official offering gets filled by whoever wants to fill it, and the quality of what appears ranges from genuinely useful open-source work to outright malware wearing the same name.

The third-party clients on Play

At least one third-party TradeOgre client was published on Google Play by an independent developer. Apps of this kind were built against the exchange's public API, and the honest ones described themselves accurately as unofficial. They generally offered what the API supported: market data, balance views, sometimes order placement using an API key you supplied.

Two things are worth understanding about that arrangement, and they apply to any third-party client for any exchange.

First, the developer is not the exchange. If the app mishandles your key, or the developer's account is compromised, or the app is sold to someone else and updated with different behaviour, the exchange has no obligation to you and no ability to help. You are extending trust to an individual you have never met.

Second, TradeOgre's API keys had no permission scoping and no IP restriction, so any key capable of reading your balance could also place trades. There was no read-only mode to grant, which meant a portfolio-viewing app necessarily received full trading authority. On a platform with scoped keys, the correct practice is to issue read-only keys to any tool that only needs to read. On TradeOgre, that option did not exist.

None of these apps function now. The endpoints they called stopped responding in 2025, and an abandoned client left installed is dead weight at best.

Why sideloading an exchange APK is the worst option

Android's willingness to install software from outside the Play Store is a real feature, and for many purposes a good one. For crypto applications it is the single largest source of loss.

An APK downloaded from a website has passed no review of any kind. Nobody has checked the developer's identity, scanned the binary, or verified that the app does what the page claims. The only thing standing between you and a malicious build is the operating system's warning dialogue, which asks you to confirm that you know what you are doing — and which every user in this situation clicks through, because they are in the middle of trying to accomplish something.

What these builds typically do is straightforward. They present a login screen that mirrors the real service, capture the credentials, and forward them immediately. Many also request accessibility permissions during setup, framed as necessary for the app to work. Granting that permission gives the app the ability to read what is on your screen and to interact with other applications — enough to read a one-time code as it arrives and to authorise a transfer without you seeing it.

The search demand around a dead exchange makes this worse rather than better. Someone searching for a TradeOgre APK today is highly motivated, is unlikely to find an official source contradicting a fake, and is often specifically hoping to recover funds. That is close to an ideal target profile.

The rule is simple and admits no exceptions worth making: never install a financial application from a downloaded file.

Hardening an Android phone you use for crypto

None of this is exotic, and all of it takes less time than recovering from a single compromise.

  • Keep Google Play Protect enabled and install only from the Play Store, reached via the service’s own website link.
  • Audit accessibility services and "display over other apps" permissions, and revoke everything you do not actively need.
  • Use an authenticator app rather than SMS for two-factor codes — SIM swap attacks defeat SMS entirely.
  • Keep the operating system updated. The majority of successful mobile attacks use vulnerabilities that were patched months earlier.
  • Consider a separate device or a dedicated user profile for crypto, kept free of games, side-loaded utilities and messaging apps.
  • Never store a seed phrase as a photo, a screenshot or a note. Anything in your gallery or notes app is one permission grant away from being uploaded.

What the app landscape looks like after the seizure

Since September 2025, anything presenting itself as a TradeOgre app falls into one of three categories.

Abandoned third-party clients. Still installed on people's phones, still trying to reach endpoints that no longer answer. Harmless in themselves, but they hold API keys and should be uninstalled.

Impersonation apps. Newly published clones using the name and any branding they can copy, existing to collect credentials from users who have not learned the platform is gone. These are the growth area.

"Recovery" apps and services. The most cynical category — applications or bots promising to help you claim your seized balance, which request personal information, an upfront fee, or a seed phrase. No application can access assets held by a police force, so every one of these is fraudulent by construction.

If you have any TradeOgre-related app installed, uninstall it, revoke any API keys it held, and change any password it stored. Then treat future search results for that name as a hazard rather than a resource.

Choosing a real exchange app on Android

The verification procedure is short and it works. Open the exchange's website in a browser, find its own link to the Play Store listing, and follow it. This single step defeats almost every impersonation, because a clone cannot get itself linked from the genuine site.

On the listing, check the developer name against the company the exchange publishes in its terms or legal pages. Check the release history — a real exchange app has years of updates, not a version 1.0 from last month. Read the one-star reviews, which surface fraud faster than any other signal.

After installing, look at what the app requests. A legitimate exchange app needs network access, storage for documents during verification, and a camera for document capture. It does not need accessibility services, SMS access, contacts, or permission to display over other apps. Any of those is a reason to stop.

And decide in advance how much you are willing to have reachable from a phone at all. A device you carry, use on public networks and occasionally lose is an appropriate home for a trading balance, not for savings. Keep long-term holdings in a wallet whose keys are not on the device in your pocket.

Frequently asked questions

Is there an official TradeOgre Android app?

No. The exchange never published one. Third-party clients built against its public API appeared on Google Play, published by independent developers with no affiliation to TradeOgre, and none of them work now that the platform has been seized.

Can I download a TradeOgre APK?

You should not. There is no official APK, and any file offered under that name is at best an abandoned third-party build and at worst credential-stealing malware. Never install a financial application from a downloaded file.

Is the TradeOgre app on Google Play safe?

Any listing under that name is not from the exchange. Older third-party clients cannot connect to anything since the seizure, and newly published apps using the name should be assumed to be impersonations designed to collect credentials.

Why does an app ask for accessibility permissions?

On Android, accessibility permissions allow an app to read screen contents and simulate input. Malware requests them because that capability is enough to read a two-factor code and approve a transfer. No legitimate exchange app needs them.

I installed a TradeOgre app. What should I do?

Uninstall it, revoke any API keys it held, and change any password you entered into it wherever else that password is used. Then review your accessibility settings and “display over other apps” permissions and revoke anything unfamiliar.

How do I find the real Android app for an exchange?

Open the exchange’s official website on your phone and follow its own link to the Play Store listing. Verify the developer name against the company the exchange publishes, and check for a multi-year release history before installing.