Skip to content Skip to sidebar Skip to footer

Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them

Apple’s tightly controlled App Store is facing renewed scrutiny after three Bitcoin holders alleged they lost $1.8 million to a fake crypto wallet, adding to a growing list of malicious wallet apps that have reached users despite the company’s screening process.

The lawsuit, filed July 24 in California, accuses Apple of failing to adequately review and remove applications impersonating Sparrow Wallet while promoting the App Store as a safe and trusted source for software.

The case follows warnings dating back more than two years about fake Sparrow apps and comes months after researchers identified 26 applications impersonating major crypto brands across Apple’s ecosystem.

Together, the incidents are putting pressure on one of Apple’s longstanding arguments for maintaining tight control over software distribution: that screening applications before they reach users provides greater protection against fraud and malicious software.

Sparrow developer warned Apple more than a year before losses

Apple’s exposure in the case rests less on the initial appearance of a fraudulent app than on what the company allegedly knew before later victims were hit.

Sparrow founder Craig Raw had been flagging unauthorized mobile versions of his wallet since early 2024. Sparrow is a desktop-only product, so an iPhone app bearing its name should not have required a complex technical investigation to identify as an impersonator.

Yet the complaint says variants carrying the Sparrow name continued to surface inside the App Store over the following year.

The first plaintiff cited in the lawsuit, Jalen Delgado, allegedly downloaded one of those apps in May 2025. After supplying his seed phrase, he lost just over 1 BTC, valued at about $120,000 in the filing.

The alleged notice to Apple became more direct two months later.

James Ramirez says he lost 7.4 BTC, worth approximately $875,000, after using another Sparrow impersonator on July 25, 2025. He reported both the application and the theft to Apple that day.

Christopher Ellis allegedly encountered a Sparrow app through the App Store nine days later. He entered his recovery phrase and lost crypto assets valued at roughly $840,000, according to the complaint.

That sequence is central to the plaintiffs’ case. They are arguing that Apple was no longer dealing only with a previously reported brand impersonation by the time Ellis was targeted. It had allegedly received a fresh report linking a specific fake wallet to a major Bitcoin theft.

The complaint further claims Apple did more than distribute the app. It alleges the platform ranked the Sparrow impersonator and surfaced it within cryptocurrency app collections, potentially increasing the credibility and reach of software masquerading as an established wallet.

According to the lawsuit:

“Despite multiple reports made to Apple that its App Store hosted fraudulent and dangerous applications, Apple failed to warn consumers that spoofed wallet apps, including fake Sparrow applications, had appeared in the App Store and posed a serious risk of theft of cryptocurrency, seed phrases, private keys, wallet credentials, and other sensitive account information.”

Apple says it removed fraudulent Sparrow apps and terminated the developer accounts responsible for them.

The company has also pointed to its reporting channels and said it acts when applications are found to breach App Store rules.

Raw’s experience, however, illustrates the difficulty legitimate developers have faced in stopping the impersonations.

Last month, Raw revealed that he submitted a basic iOS listing intended to tell users that Sparrow had no official mobile version.

Apple initially treated that submission as potentially deceptive and warned that his developer account could be closed, according to Raw, before later reversing course.

The episode adds another layer to the lawsuit’s argument: Apple allegedly struggled not only to keep impersonators out, but also to distinguish the genuine wallet developer from those misusing his brand.

Apple's App Store fake wallet problem has spread beyond Sparrow

The Sparrow dispute is part of a wider wave of crypto wallet impersonation targeting Apple users.

Kaspersky Threat Research said in April that it had identified 26 fraudulent applications mimicking crypto brands including MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken and Bitpie.

Fake Crypto Applications on Apple's App Store
Fake Crypto Applications on Apple's App Store (Source: Kaspersky)

The campaign had been active since at least fall 2025 and was linked with moderate confidence to threat actors behind SparkKitty, according to the cybersecurity firm.

The attack was more elaborate than simply publishing a malicious wallet directly through the App Store.

Kaspersky found that the applications could redirect victims to phishing pages designed to resemble Apple's marketplace and persuade them to install developer profiles. Those profiles could then be used to install trojanized versions of crypto wallets outside the App Store.

Once installed, the malicious software targeted the credentials controlling users' assets.

For hot wallets, the malware monitored wallet recovery or creation screens for seed phrases. Attackers obtaining those words could then gain control over the victim's funds.

Cold-wallet users faced a similar social-engineering threat. Fraudulent software impersonating interfaces associated with hardware wallets could persuade victims to surrender recovery credentials that should never be entered into an unverified application.

The campaign largely targeted users of Apple's Chinese App Store, where official iOS versions of several wallets being impersonated were unavailable.

But significant losses involving fake wallet software have also emerged in the United States.

American musician Garrett Dutton, better known as G. Love, said in April that he lost 5.9 BTC after downloading what he believed was legitimate Ledger software from Apple's App Store.

Dutton entered his recovery phrase when prompted by the application. His Bitcoin, worth roughly $424,000 at the time, was subsequently transferred away.

Blockchain investigator ZachXBT traced the stolen assets to deposit addresses associated with crypto exchange KuCoin, which temporarily froze a suspected account as the incident was investigated.

The episode closely resembles the allegations at the center of the Sparrow lawsuit: users encountered software carrying the identity of an established crypto wallet through Apple's ecosystem, trusted it enough to enter recovery credentials and lost control of their assets.

Crypto scams challenge Apple’s App Store security pitch

The repeated incidents are increasingly colliding with how Apple markets its control over software distribution.

Apple describes the App Store as a “safe and trusted place” and says applications undergo a review process intended to protect users from fraud, malware and other security threats.

That promise has also supported Apple's broader defense of its tightly managed ecosystem.

The company has argued that allowing unrestricted sideloading could weaken privacy and security protections on its devices, while its centralized review process allows potentially dangerous software to be intercepted before reaching customers.

Crypto wallets create a particularly difficult test for that model because an application does not necessarily need sophisticated malware to cause an irreversible loss.

A convincing imitation can be enough.

Seed phrases typically provide control over the assets associated with a self-custodied wallet. Once a user enters those words into malicious software, attackers can transfer the assets to addresses they control, with no bank or payment processor capable of reversing the transaction.

That makes the perceived legitimacy conveyed by an app marketplace especially important for crypto users.

The Sparrow plaintiffs argue that Apple's own representations encouraged them to believe software distributed through the App Store had been sufficiently vetted. They are seeking reimbursement for their stolen assets, along with compensatory and punitive damages, restitution, and legal fees.

They also want Apple to improve and publicly disclose its procedures for detecting fraudulent applications and introduce warnings about risks associated with cryptocurrency apps.

Whether Apple bears legal responsibility for the losses remains unresolved, and the company can contest both the plaintiffs' reliance on its security representations and their decision to enter sensitive recovery credentials into third-party software.

Apple also points to the scale of threats its review process already prevents.

The company said last year that the App Store blocked more than $9 billion in potentially fraudulent transactions between 2020 and 2024, including more than $2 billion in 2024 alone.

During 2024, Apple said it rejected nearly 2 million app submissions that failed to meet standards for security, reliability and user experience, while terminating more than 146,000 developer accounts over fraud concerns and rejecting another 139,000 developer enrollment attempts.

Those figures show the scale of malicious activity Apple is attempting to keep outside its ecosystem. They also highlight the stakes when fraudulent financial software gets through.

For crypto users, where surrendering a single recovery phrase can put an entire wallet beyond recovery, the growing list of impersonators is testing how much confidence Apple's App Store badge should inspire.

The post Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them appeared first on CryptoSlate.



source https://cryptoslate.com/apples-app-store-security-promise-faces-test-as-fake-crypto-wallets-keep-getting-through/

Post a Comment for "Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them"