My professional opinion is that APKs can be de-compiled regardless and that has nothing to do with tokenized payments themselves which are like you said handled through server-server communications at the payment processor level. Your phone simply sends a one time use token to authorize the transaction.
You were the one that brought up payments though. Nobody else specified. They just said it could be hacked, which you seem to agree with.