Thanks for a good response, this explains quite a bit. What prevents you (the central server) from changing addresses before relaying the address to the wallet? Others might be unable to MITM, but you would be able to from what I gather, as well as anyone with access to your mailservers.
Data are digitally signed. It's unable to change content without resigning message. Tomorrow we'll update the Security Description of the HODLER Wallet.
We are happy to inform, https://forkdelta.github.io will be listing the HDL token in the next few days. The rest of the exchanges will be announced immediately after the acceptance of our application.