Activ8 Insights
News11 min read

The AppLovin Exposé: How Three Research Firms Uncovered a $173B Tech Giant’s Alleged Fraud Empire

From AI Claims to Backdoor Installs: The Systematic Unraveling of Mobile Advertising's Biggest Success Story The mobile advertising empire built on AI promises may be crumbling faster than anyone…

Activ8 Newsroom • May 30, 2025

The AppLovin Exposé: How Three Research Firms Uncovered a $173B Tech Giant's Alleged Fraud Empire

From AI Claims to Backdoor Installs: The Systematic Unraveling of Mobile Advertising's Biggest Success Story

The mobile advertising empire built on AI promises may be crumbling faster than anyone expected. Three separate activist research firms have unleashed devastating reports against AppLovin Corporation (NASDAQ: APP), painting a picture of systematic fraud, privacy violations, and questionable business practices that could spell doom for one of 2024's biggest stock market darlings.

The Perfect Storm: When Three Research Giants Unite Against One Target

Between February and May 2025, three prominent research firms launched a coordinated assault on AppLovin Corporation (NASDAQ: APP), unveiling what may be the most comprehensive corporate fraud allegation since the Global Financial Crisis. With AppLovin's stock having soared over 500% to peak at a $173 billion market cap, these reports paint a damning picture of a company whose meteoric rise was allegedly built not on revolutionary AI technology, but on systematic deception, privacy violations, and platform manipulation.

The Coalition of Critics:

The Bottom Line: All four reports converge on a singular thesis: AppLovin's AXON 2.0 "AI revolution" is allegedly a smokescreen masking practices that violate major platform policies, privacy laws, and user consent - creating existential business risks that could destroy the company overnight.


Report #1: Culper Research - "The Glass Box Revelation"

February 26, 2025: "Force-Feeding Users with Silent Backdoor Installs"

The Opening Salvo: Culper Research fired the first shot, calling AppLovin potentially "the single largest US stock promotion unraveling since at least the GFC."

The AXON 2.0 "AI" Charade

CEO's Evasive Answers: When pressed to explain AXON 2.0's revolutionary capabilities, CEO Adam Foroughi's responses were tellingly vague:

"Yes, it's just better. I mean just the technology is built to scale better, it's more efficient, more effective... what we can't see in a black box algorithm is a type in and a result."

Red Flags:

  • AXON 2.0 developed in under 12 months (suspiciously fast for genuine AI breakthrough)
  • Former engineer admitted management's AI interest only emerged "with the whole AI stocks thing"
  • Previous failed ventures included an NFT marketplace called "Vessel" (now defunct)

The Three-Part Backdoor Scheme

Culper's investigation uncovered an elaborate system to circumvent app store policies:

Part 1: The Array Trojan Horse

  • Partnerships with major OEMs (Samsung, OPPO) and carriers (T-Mobile, Sprint)
  • Pre-installs "AppHub" on devices with dangerous system-level permissions
  • Grants power to install apps outside Google Play Store
  • Deployed to 20 million T-Mobile phones in just 6 months

Part 2: SDK Permission Smuggling

  • Since November 2022, embedded binding permission in customer apps via MAX SDK updates
  • Permission: com.applovin.array.apphub.permission.BIND_APPHUB_SERVICE
  • Infected popular games: Subway Surfers, 8 Ball Pool, Wordscapes, Angry Birds 2
  • Apps can now "inherit" AppHub's direct install powers

Part 3: The One-Click Exploitation

Culper's code analysis revealed the step-by-step process:

  1. User clicks anywhere on an ad (intentionally or accidentally)
  2. AppLovinAdClickListener triggers startDirectInstallOrDownloadProcess
  3. App binds to AppHub service
  4. Checks if "isDirectDownloadEnabled" is true
  5. Installs advertised app directly, bypassing app stores

User Testimony: A Digital Nightmare

Real User Complaints:

  • "My phone just started installing random apps to my secure folder"
  • "The games automatically download to the device when the ads are tapped... WITHOUT YOUR CONSENT"
  • "Three times now I've gotten that ad for Tower War and 30 seconds after the ad is over I get a push notification that Tower War has finished installing"
  • Apps described as "pure cancer" by users

The Smoking Gun: Case Study Evidence

Animal Restaurant → Bricks n Balls Connection:

  • Users complained Animal Restaurant (10M+ installs) automatically installed "Bricks n Balls" (10M+ installs)
  • Installation spikes precisely correlated with Array partnerships in Brazil (May 2023) and India (September 2023)
  • Geographic concentration proves connection to Array's OEM/carrier partnerships

The E-Commerce Rigging Operation

AppLovin's expansion into e-commerce appears equally manipulative:

The Rigged Game:

  • Requires proof of $600,000/month Meta spending before platform access
  • Uses MAX mediation to "see" Meta ads and claim credit for conversions
  • Maintains tight advertiser control to prevent narrative slippage
  • Creates artificial waitlist hype with cherry-picked success stories

CEO's Checkered Past: A Pattern of Deception

The Troubling Timeline:

  • 2004: Worked at Gator Corporation, "notorious as one of the first widespread spyware applications"
  • LifeStreet Media: Co-founded with former Gator/Claria executives
  • 2008-2010: Social Hour CEO - banned by Facebook for "deceptive content"
  • Current Team: Filled with colleagues from previous questionable ventures

Report #2: Fuzzy Panda Research - "Protecting Children from Digital Predators"

The Child Privacy Bombshell

Fuzzy Panda exposed AppLovin's most disturbing alleged violation: systematically tracking children despite explicit "Do Not Track" settings.

How the Child Tracking Works

Apple/Google's Protection Attempt:

  • Mark children's devices as "Do Not Track" with identifier string of 0s (IDFA = "0000-0000-0000")
  • Clear signal that tracking is prohibited

AppLovin's Alleged Circumvention:

  • Assigns different numerical ID even for protected children
  • Creates persistent tracking across all AppLovin apps
  • Enhances profiles using third-party data brokers
  • Builds comprehensive "fingerprints" for targeted advertising

Third-Party Data Broker Enhancement

The Data Multiplication Scheme:

  • Over 100 data brokers available for enhanced targeting
  • AppLovin allegedly pays 50%+ above normal rates for enhanced user data
  • Combines unique device IDs with personal information (email, phone, age, etc.)
  • Creates detailed profiles for retargeting campaigns

Platform Policy Violations

Apple's Clear Prohibition: Apple's Developer Program License explicitly states apps cannot fingerprint users. Fuzzy Panda provided screenshots showing Apple's policy states "NO 'Fingerprinting'" in bold red text.

Google Play Violations: Similar violations of Google's privacy and user choice policies, particularly regarding children's privacy protections.

The "Ponzi Scheme" Business Model

Industry Expert Testimony: "I'm almost certain that what they're doing is a Ponzi scheme... It's junk inventory, junk apps... It's kicked you out of the app and forced you to download the other app via the ad. It's dirty metrics."

Platform Ban Predictions

Why AppLovin Faces Existential Risk:

  • Apple will likely remove AppLovin SDKs for child privacy violations
  • Google faces pressure to ban apps with AppLovin SDKs
  • Meta (Facebook) could cut ties to protect user data
  • All three control 99%+ of AppLovin's revenue pathway

Report #3: Muddy Waters Research - "The Forensic Evidence"

Muddy Waters published two devastating reports that provided the technical smoking gun.


Report 3A: The Original Exposé (March 27, 2025)

"Just Another Scammy AdTech Company"

The Data Analysis Breakthrough

Key Findings:

  • 52% of e-commerce sales are retargeting (not new customer acquisition)
  • Only 25-35% incrementality (vs. CEO's claimed "nearly 100%")
  • 23% customer churn rate in Q1 2025 (vs. CEO's claim of "almost no churn")

The Persistent Identity Graph (PIG) System

How AppLovin Allegedly Steals Platform Data:

  1. Data Extraction: Illegally captures proprietary IDs from Meta, Snap, TikTok, Reddit, Google
  2. Identity Fusion: Combines stolen data to create "artificial and persistent user IDs"
  3. Shopify Integration: Adds e-commerce behavioral data (cart additions, checkouts)
  4. Auction Advantage: Uses comprehensive profiles for unfair ad auction advantages

Technical Evidence: The Desktop Test

Muddy Waters provided a step-by-step guide for readers to witness AppLovin's data collection:

  1. Visit AppLovin customer website (e.g., trueclassictees.com)
  2. Open Chrome DevTools
  3. Add item to cart and checkout
  4. Search for "b.applovin.com" in Network tab
  5. Observe data being collected and sent to AppLovin servers

Sample Data Captured:

  • Instagram IDs: "igId": "ig_e86b73aa40d1933de4328f62a3b026983ada"
  • Cart tracking: "__fondue_cart_id": "314dd843-315a-4246-9343-c7ce5d3dc204"
  • Payment signals: "GE_isApplePay": "false"

Report 3B: The Follow-Up Bombshell (May 7, 2025)

"APP's Persistent Lies, Denying Use of Persistent IDs"

Catching Executives in Outright Lies

The Executive Denials:

  • March 31, 2025: CEO Foroughi published blog post explicitly denying AppLovin creates or uses persistent identifiers
  • Same Day: CTO Basil Shikin provided technical explanations claiming compliance with privacy policies

Muddy Waters' Response: "We show this denial is a lie... Shikin's explanation of how identifiers data are used and how APP creates and uses personal identifiers is misleading—a lie of omission."

Third-Party Forensic Validation

Permanent Record Research Inc. (PRR) Investigation:

  • Independent technical analysis firm engaged by Muddy Waters
  • Captured real-time data showing persistent identifier usage
  • Created visualizations proving cross-domain tracking
  • Video presentation explains technical details of the deception

The Smoking Gun Spreadsheet

Cross-Domain Tracking Evidence: Same identifier value (285035d2-a4bf-4275-bd06-31ea02d6a9fe) found across:

E-commerce Sites:

  • drinkbrez.com
  • namacbd.com
  • minceetbien.com
  • ilmakiage.com

AppLovin Domains:

  • sts.applovin.com
  • b.applovin.com
  • ms.applovin.com

The Gephi Visualization

The report included a network graph mapping showing:

  • Nodes: Individual user identifiers and servers
  • Connections: Data sharing relationships across domains
  • Visual Proof: Same persistent IDs connecting mobile apps and e-commerce websites

Why the Lies Matter

Deplatforming Pressure:

  • Evidence suggests executives lied due to pressure from deplatforming risks
  • Meta (Facebook) identified as key threat - both partner and competitor
  • Regulatory action risks from FTC and California AG
  • Margin compression as competitors copy techniques

Quote from Muddy Waters: "Evidence in the captured data indicates that APP's CEO and CTO blatantly lied and misled investors about APP's use of persistent identifiers. We think this is because there is significant risk of APP being deplatformed for TOS privacy violations."


The Convergence: Four Reports, One Conclusion

Interlocking Evidence

The research firms' findings reinforce each other across multiple dimensions:

Technical Convergence:

  • Culper: Code analysis showing backdoor installation permissions
  • Fuzzy Panda: Child tracking despite "Do Not Track" settings
  • Muddy Waters: Forensic proof of persistent cross-domain identifiers

Business Model Convergence:

  • All Reports: AXON 2.0 AI claims are marketing theater
  • Consistent Theme: Revenue growth built on policy violations
  • Shared Conclusion: Unsustainable practices create existential risks

Platform Risk Convergence:

  • Google Play: 84% of mobile gaming ecosystem at risk
  • Apple App Store: Child privacy violations could trigger bans
  • Meta: Both key partner and competitive threat with power to "shut it down"

Financial Red Flags

Insider Activity Speaks Volumes:

  • $2.0 billion in insider sales over last 12 months
  • KKR dumped entire $7.3 billion stake
  • Pattern suggests insiders know practices are unsustainable

The Math Doesn't Add Up:

  • Peak market cap: $173 billion
  • Based on allegedly fraudulent growth metrics
  • Multiple firms estimate true incrementality at 25-35% vs. claimed "nearly 100%"

Legal and Regulatory Landmines

Immediate Enforcement Risks

Platform Actions:

  • Google Play Store bans (controls 84% of mobile gaming)
  • Apple App Store removals (child privacy violations)
  • Meta deplatforming (terms of service violations)

Regulatory Investigations:

  • FTC enforcement for privacy violations
  • California AG action for child privacy laws
  • Class action lawsuits from affected users
  • SEC investigation for investor deception

Legal Precedents

Cheetah Mobile Comparison: Muddy Waters explicitly compared AppLovin to Cheetah Mobile, which was:

  • Banned from Google Play Store
  • Stock collapsed from manipulation allegations
  • Serves as cautionary tale for platform-dependent businesses

Potential Criminal Liability

Executive Deception:

  • Documented lies to investors about core business practices
  • Intentional misrepresentation of AI capabilities
  • Securities fraud potential for material misstatements

Investment Risk Assessment

Immediate Risks (0-6 months)

  • Platform enforcement actions could eliminate 84%+ of revenue overnight
  • Regulatory investigations creating investor uncertainty
  • Customer churn as tracking practices become public knowledge
  • Stock volatility from ongoing research firm scrutiny

Medium-term Risks (6-24 months)

  • Competitive replication of techniques reducing advantages
  • Margin compression as "black edge" disappears
  • Talent flight as practices become public knowledge
  • Customer lawsuits from privacy violations

Long-term Risks (24+ months)

  • Permanent platform bans eliminating business model
  • Criminal prosecution of executives
  • Business model obsolescence without policy violations
  • Reputation damage preventing legitimate growth

The Bottom Line: A House of Cards

What the Research Coalition Proved:

  1. The AI Claims Are False: AXON 2.0 appears to be marketing theater masking policy violations
  2. The Growth Is Artificial: Based on unauthorized installs and stolen data rather than legitimate performance
  3. The Practices Are Illegal: Systematic violation of platform policies, privacy laws, and user consent
  4. The Executives Are Deceptive: Documented lies to investors about core business practices
  5. The Risks Are Existential: Platform bans could eliminate the business overnight

Why This Matters Beyond AppLovin

This case study represents a broader indictment of:

  • AdTech industry practices and their sustainability
  • Platform oversight gaps allowing systematic abuse
  • Regulatory enforcement needs in digital privacy
  • Investor due diligence in high-growth tech companies

The Ultimate Question

AppLovin's stock peaked at a $173 billion market capitalization based on claims of revolutionary AI technology. Four independent research reports now suggest that success was allegedly built on:

  • Backdoor app installations without user consent
  • Systematic child privacy violations
  • Stolen data from major platforms
  • Persistent cross-domain tracking
  • Executive deception about core practices

For investors, the question isn't whether AppLovin will face consequences - it's whether the company can survive them.


"When the tide goes out, you discover who's been swimming naked." - Warren Buffett

The research coalition may have just exposed one of the biggest corporate frauds in tech history. Whether AppLovin can navigate the incoming tsunami of platform enforcement, regulatory action, and customer backlash will determine if this $173 billion story ends in vindication or devastation.