Search
Advertisement
Can your UPI App be hacked? Student exposes 3 loopholes

Can your UPI App be hacked? Student exposes 3 loopholes

Ankit Thakur, a BTech student, did a thorough study on how UPI apps work and looked for weaknesses that scammers can exploit.

Business Today Desk
Business Today Desk
  • Noida,
  • Updated Apr 13, 2026 2:36 PM IST
Can your UPI App be hacked? Student exposes 3 loopholesGoogle Pay and Paytm have acknowledged the flaws and that the vulnerabilities have been fixed.

Ankit Thakur, a B.Tech (CSE) student from Haryana, identified three technical bugs in the UPI apps ecosystem that could be misused by fraudsters. According to The Tribune report, Thakur was still in school when his father, a driver by profession, lost Rs 20,000 in an online fraud back in 2020. 

Advertisement

Related Articles

The incident deeply affected him, prompting him to dig deeper into how UPI apps work and look for weaknesses that scammers can exploit. Thakur started flagging the identified flaws to the Google security bot in June 2025, and the company also acknowledged the bugs and rolled out fixes in February 2026.

Also read: UPI fee backlash: 3 in 4 users say they will stop using platform if transaction charges are imposed

The three technical bugs included Chrome Intent Vulnerability, Authentication Bypass, and Audio Hijack. One of these threats lets harmful websites open apps like UPI without user consent or interaction. “This feature acts as an open door for scammers, giving them a direct path to the user’s payment interface,” The Tribune quoted Thakur.

Advertisement

The second threat bypasses the first layer of authentication, such as app locks or biometrics, which helps secure UPI apps. The teen further stated that Google Pay and Paytm have acknowledged his report, and that the vulnerabilities have been fixed.

Also read: US flags ‘non-level playing field’ in India’s UPI, raises concerns over IT rules and rising takedown orders

Lastly, the Audio Hijack is said to be the most dangerous of them all. “In this scenario, UPI apps fail to ‘lock audio focus’ during a payment. Taking advantage of this, a fake app hidden in the background can play its own audio. The user believes the voice is coming from the payment app itself and falls prey to fraudsters.”

Advertisement

However, it should be noted that Google conducts rigorous verification before acknowledging the severity of the flaws. Then it makes necessary fixes and critical patches to secure the Android ecosystem for UPI. Therefore, it also brings attention to how crucial it is for smartphone users to regularly update and download security patches and keep the operating system and apps updated at all times.

For Unparalleled coverage of India's Businesses and Economy – Subscribe to Business Today Magazine

Published on: Apr 13, 2026 1:15 PM IST
    Post a comment0