In the Proton Authenticator application presented last week, used for authentication with one-time passwords, a privacy issue was identified — the detailed debug log was left enabled in the builds for the iOS mobile platform, where the original secret keys for generating one-time passwords were saved in plaintext. Such a log nullified the encryption of keys and the restriction of access to them via PIN codes or biometric authentication. The issue has been resolved in update 1.1.1. In the Android builds, only the key identifier was saved in the log, not the key itself.
Source: opennet.ru