An app should not be considered "secure" because it doesn't currently have important data.
Twitter wasn't much of a honeypot, either, until activists and corporations started using it. Did Twitter know the exact moment that happened? No. They should have been secure long before that.
There's this thing called a "jasager" that you might also be interested in looking into. Particularly combined with airdrop-ng. I was a bit shocked when I learned how that particular aspect of 802.11 is implemented.
2. Give it a default name (e.g. 'linksys').
3. Capture packets.
4. Profit.