Have you tried extracting, decompiling, and modifying someone else's app?
It wasn't hard before LLMs and it's nearly trivial now.
The crypographic flow that allows payments to work is straight up pub/priv key encryption with one time use tokens. It's not something you can hack. As soon you see the token it's already been used and thrown away. So whatever nonsense about decompiling literally doesn't matter.
Is that not possible with ios applications?