Two-Thirds of AI iPhone Apps Hid the Key Under the Doormat
A Wake Forest study ran 444 AI-powered iOS apps through traffic analysis and found 282 of them leaking their own LLM API keys — OpenAI, Anthropic, cloud creds, the works. Stolen keys fuel 'LLMjacking' that can burn $46,000 a day on someone else's bill. Here's why it keeps happening and how to ship AI features with zero secrets in your bundle.
Apple Just Invented the Gym Membership for Apps. Here's Why That's Brilliant.
iOS 26.5 shipped a new subscription model — monthly payments with a 12-month commitment. It's the gym membership of the App Store. And for indie developers bleeding from monthly churn, it might be exactly what the doctor ordered.
iOS Refund Abuse Has a TikTok Tutorial Now. Your Client-Side Receipt Check Is the Cashier Who Looks Away.
Subscription refund fraud quietly climbed past 11% on iOS in 2026, fueled by TikTok scripts and a 90-day Apple refund window most indies never reckoned with. Client-side receipt verification can't see any of it — and the gap between StoreKit's ‘.verified' and what your business is actually owed is now too big to ignore.