Elyzium DexBuild
Application hardening that protects critical Android code from cracking.
Internal testing
↓ Elyzium DexBuild (at build time)
Critical code hidden and locked
↓
Runs only while the app is intactIllustrative diagram.
The problem it solves
Android apps are easy to unpack with widely available tools. From there, others can read the internal logic, strip licence or payment checks, modify the app to cheat, inject their own ads and redistribute it as a “mod”. Elyzium DexBuild significantly raises the cost of doing this and lets the app recognise when it has been tampered with.
Who it is for
Android app and game developers with paid features, licence checks, sensitive data or proprietary algorithms to protect.
Use cases
- Protect licence checks and in-app purchase logic.
- Make cheating mods of a game harder to build.
- Protect proprietary algorithms or business logic.
- Detect and refuse to run when the app has been repackaged by someone else.
Key features
Hide critical code
The classes you select no longer exist in readable form inside the app package. They are stored locked and only unlocked in memory at the moment they are needed.
Move sensitive functions to a separate form
For especially critical functions, such as licence checks, Elyzium DexBuild converts them into a separate executable form that common Android analysis tools cannot read directly.
Tamper detection
At run time the app checks that its code is intact. If tampering is detected, the protected parts are not unlocked.
Anti-repackaging
Protected code is bound to your app's identity and signing certificate. If someone re-signs the app with a different key, the protection does not unlock.
Resists code lifting
Protected code cannot be copied into another process or build and run on its own.
Fits your existing workflow
Elyzium DexBuild is a Gradle plugin. It supports both APK and the AAB format used for Google Play, together with R8 code shrinking and multi-dex apps.
Optional server confirmation
For apps that need tighter control, a mode can require confirmation from your own server, so you can revoke the right to run when something looks wrong.
How it is deployed
Choose what to protect
Mark the critical classes or functions in your source code.
Add the plugin
Declare Elyzium DexBuild in your app's Gradle configuration.
Build and sign
The plugin processes and packages the protected app automatically.
Run and verify
At run time the app checks its integrity and unlocks protected code only if everything is valid.
Technical details
| Stage | Internal testing; no independent third-party review yet |
|---|---|
| Platform | Android |
| Integration | Gradle plugin plus a runtime library shipped inside the app |
| Release formats | APK and AAB |
| Compatibility | R8 code shrinking, multi-dex apps |
| Optional hardening | Native code obfuscation |
Known limitations
We state these clearly so you know what to expect:
- The product is in internal testing; coverage across device models and Android versions is still limited.
- Functions under the strongest protection are slower on every call, so they suit infrequent decisions such as licence checks, not tight loops.
- No solution can fully stop a user who controls a rooted device; the server-confirmation mode allows revocation when needed.
Interested in Elyzium DexBuild?
Send a request for a consultation and a quote tailored to your project.