TL;DR: Mobile ID wallets are moving from convenience feature to high-value identity infrastructure, and Guardsquare argues they face cloned apps, malware tampering, MitM attacks, and API abuse unless security is built into the mobile SDLC. That shifts the governance problem from device trust to runtime, API, and attestation controls.
NHIMG editorial — based on content published by Guardsquare: Mobile ID wallets offer cross-border convenience, if they’re secure
By the numbers:
- 44% of advanced bot activity now specifically targets APIs, making mobile API abuse a primary attack path.
- 48% of mobile app publishers monitor API activity, ivity, even as 82% say backend and API abuse is increasing.
Questions worth separating out
Q: How should organisations secure mobile identity wallets against tampering and cloned apps?
A: Organisations should combine app hardening, runtime attestation, and backend validation so the wallet cannot be trusted solely because it is installed on a legitimate device.
Q: Why do mobile ID wallets create more fraud risk than traditional identity documents?
A: Mobile wallets can be cloned, instrumented, or attacked through APIs, which means the attacker may not need to forge the identity itself.
Q: How do security teams know if a mobile identity wallet programme is working?
A: They should look for low rates of tampering, strong attestation coverage, minimal API abuse, and fast detection of cloned or modified apps.
Practitioner guidance
- Classify wallet integrity as an identity control Map mobile ID wallet risks to identity assurance requirements, not just app security checklists, and define ownership across IAM, fraud, and mobile engineering.
- Add runtime attestation to wallet trust decisions Require proof that the wallet instance is legitimate and untampered before allowing high-risk identity transactions or document presentation.
- Instrument mobile APIs for fraud and abuse signals Correlate API requests with device posture, app integrity, and session behaviour so cloned apps and automation are visible in backend telemetry.
What's in the full article
Guardsquare's full post covers the mobile security detail this analysis intentionally leaves at the governance level:
- The article's breakdown of mobile app hardening techniques for reverse engineering and tamper resistance
- Its discussion of app attestation and runtime monitoring for trusted identity presentation
- The mobile API protection angle, including how backend abuse and bot activity are detected
- The SDLC testing focus for identity apps, including static and dynamic analysis considerations
👉 Read Guardsquare's analysis of mobile ID wallet security and fraud controls →
Mobile ID wallets: are app-layer controls keeping pace with fraud?
Explore further
Mobile ID wallets are identity systems, not just consumer apps. Once a wallet contains government-issued attributes, the security bar shifts from app usability to identity assurance, fraud resistance, and policy enforcement. That means the relevant governance model spans identity verification, application security, and runtime trust, not just mobile device management. Practitioners should classify wallet security as part of the identity control plane.
A question worth separating out:
Q: Which controls matter most when mobile ID wallets are used for government or financial services?
A: The most relevant controls are secure-by-design development, continuous testing, runtime protection, app attestation, and monitoring tied to fraud detection. Where wallets support regulated identity and transaction decisions, the control set must also align with identity verification, privacy, and audit requirements.
👉 Read our full editorial: Mobile ID wallets need app-layer security to withstand fraud