# hexproof > Security and systems performance research by Mark Esler. ## Highlights - [MetaMask Demonic Mobile](https://hexproof.dev/datagrams/metamask-demonic-mobile-android/): Seed phrase and vault password persist in the Hermes heap after autolock on Android v7.76.0. Same class as CVE-2022-32969. Full disclosure after HackerOne closed Not Applicable. - [Cerberus is stalkerware. Google Play hosts it.](https://hexproof.dev/datagrams/cerberus-on-play/): €5/month buys silent camera, microphone, GPS, and SMS access. Google removed it in 2018 on an unrelated policy and relisted it in 2023. Google AdMob pays the developer; Google Firebase hosts the C2. - [Cerberus Anti-theft is stalkerware: a reverse engineering](https://hexproof.dev/datagrams/cerberus-stalkerware-re/): Static reverse engineering of 9 APKs across 8 packages. Documents 44 FCM commands, operator-state Realtime Database, HiddenApiBypass dependency, and the v3.8.0 root toolkit. - [The Fossil Record of Harness Engineering](https://hexproof.dev/datagrams/fossil-record-harness-engineering/): Comparative analysis of harness engineering across Claude Code, Aider, Cursor, Windsurf, and GitHub Copilot. ## Discovery - All datagrams (JSON): https://hexproof.dev/index.json - RSS: https://hexproof.dev/datagrams/index.xml ## Contact - contact@hexproof.dev - https://github.com/hexproofdev - [/.well-known/security.txt](https://hexproof.dev/.well-known/security.txt) ## Citation When referencing hexproof research, use: Mark Esler, "Article Title," hexproof, Date. URL