Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them
Apple’s tightly managed App Store is dealing with renewed scrutiny after three Bitcoin holders alleged they misplaced $1.8 million to a fake crypto wallet, including to a rising checklist of malicious wallet apps that have reached customers regardless of the corporate’s screening course of.
The lawsuit, filed July 24 in California, accuses Apple of failing to adequately assessment and take away functions impersonating Sparrow Wallet whereas selling the App Store as a protected and trusted supply for software program.
The case follows warnings courting again greater than two years about fake Sparrow apps and comes months after researchers recognized 26 functions impersonating main crypto manufacturers throughout Apple’s ecosystem.
Together, the incidents are placing stress on considered one of Apple’s longstanding arguments for sustaining tight management over software program distribution: that screening functions earlier than they attain customers gives larger safety in opposition to fraud and malicious software program.
Sparrow developer warned Apple greater than a year earlier than losses
Apple’s publicity within the case rests much less on the preliminary look of a fraudulent app than on what the corporate allegedly knew earlier than later victims had been hit.
Sparrow founder Craig Raw had been flagging unauthorized cellular variations of his wallet since early 2024. Sparrow is a desktop-only product, so an iPhone app bearing its identify shouldn’t have required a advanced technical investigation to determine as an impersonator.
Yet the grievance says variants carrying the Sparrow identify continued to floor contained in the App Store over the next year.
The first plaintiff cited within the lawsuit, Jalen Delgado, allegedly downloaded a kind of apps in May 2025. After supplying his seed phrase, he misplaced simply over 1 BTC, valued at about $120,000 within the submitting.
The alleged discover to Apple turned extra direct two months later.
James Ramirez says he misplaced 7.4 BTC, price roughly $875,000, after utilizing one other Sparrow impersonator on July 25, 2025. He reported each the applying and the theft to Apple that day.
Christopher Ellis allegedly encountered a Sparrow app by means of the App Store 9 days later. He entered his restoration phrase and misplaced crypto belongings valued at roughly $840,000, in response to the grievance.
That sequence is central to the plaintiffs’ case. They are arguing that Apple was not dealing solely with a beforehand reported model impersonation by the point Ellis was focused. It had allegedly obtained a recent report linking a particular fake wallet to a major Bitcoin theft.
The grievance additional claims Apple did greater than distribute the app. It alleges the platform ranked the Sparrow impersonator and surfaced it inside cryptocurrency app collections, probably rising the credibility and attain of software program masquerading as a longtime wallet.
According to the lawsuit:
“Despite a number of reviews made to Apple that its App Store hosted fraudulent and harmful functions, Apple didn’t warn customers that spoofed wallet apps, together with fake Sparrow functions, had appeared within the App Store and posed a severe threat of theft of cryptocurrency, seed phrases, non-public keys, wallet credentials, and different delicate account data.”
Apple says it eliminated fraudulent Sparrow apps and terminated the developer accounts accountable for them.
The firm has additionally pointed to its reporting channels and stated it acts when functions are discovered to breach App Store guidelines.
Raw’s expertise, nevertheless, illustrates the issue respectable builders have confronted in stopping the impersonations.
Last month, Raw revealed that he submitted a primary iOS itemizing supposed to inform customers that Sparrow had no official cellular model.
Apple initially handled that submission as probably misleading and warned that his developer account may very well be closed, in response to Raw, earlier than later reversing course.
The episode provides one other layer to the lawsuit’s argument: Apple allegedly struggled not solely to maintain impersonators out, but additionally to tell apart the real wallet developer from these misusing his model.
Apple’s App Store fake wallet downside has unfold past Sparrow
The Sparrow dispute is a part of a wider wave of crypto wallet impersonation targeting Apple users.
Kaspersky Threat Research said in April that it had recognized 26 fraudulent functions mimicking crypto manufacturers together with MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken and Bitpie.

The marketing campaign had been lively since not less than fall 2025 and was linked with reasonable confidence to risk actors behind SparkKitty, in response to the cybersecurity agency.
The assault was extra elaborate than merely publishing a malicious wallet straight by means of the App Store.
Kaspersky discovered that the functions might redirect victims to phishing pages designed to resemble Apple’s market and persuade them to put in developer profiles. Those profiles might then be used to put in trojanized variations of crypto wallets outdoors the App Store.
Once put in, the malicious software program focused the credentials controlling customers’ belongings.
For sizzling wallets, the malware monitored wallet restoration or creation screens for seed phrases. Attackers acquiring these phrases might then achieve management over the sufferer’s funds.
Cold-wallet customers confronted a comparable social-engineering risk. Fraudulent software program impersonating interfaces related to {hardware} wallets might persuade victims to give up restoration credentials that ought to by no means be entered into an unverified utility.
The marketing campaign largely focused customers of Apple’s Chinese App Store, the place official iOS variations of a number of wallets being impersonated had been unavailable.
But vital losses involving fake wallet software have additionally emerged within the United States.
American musician Garrett Dutton, higher often called G. Love, stated in April that he misplaced 5.9 BTC after downloading what he believed was respectable Ledger software program from Apple’s App Store.
Dutton entered his restoration phrase when prompted by the applying. His Bitcoin, price roughly $424,000 on the time, was subsequently transferred away.
Blockchain investigator ZachXBT traced the stolen belongings to deposit addresses related to crypto change KuCoin, which briefly froze a suspected account because the incident was investigated.
The episode intently resembles the allegations on the middle of the Sparrow lawsuit: customers encountered software program carrying the identification of a longtime crypto wallet through Apple’s ecosystem, trusted it sufficient to enter restoration credentials and misplaced management of their belongings.
Crypto scams problem Apple’s App Store safety pitch
The repeated incidents are more and more colliding with how Apple markets its management over software program distribution.
Apple describes the App Store as a “protected and trusted place” and says functions bear a assessment course of supposed to guard customers from fraud, malware and different safety threats.
That promise has additionally supported Apple’s broader protection of its tightly managed ecosystem.
The firm has argued that permitting unrestricted sideloading might weaken privateness and safety protections on its gadgets, whereas its centralized assessment course of permits probably harmful software program to be intercepted earlier than reaching clients.
Crypto wallets create a significantly troublesome take a look at for that mannequin as a result of an utility doesn’t essentially want subtle malware to trigger an irreversible loss.
A convincing imitation may be sufficient.
Seed phrases sometimes present management over the belongings related to a self-custodied wallet. Once a person enters these phrases into malicious software program, attackers can switch the belongings to addresses they management, with no financial institution or fee processor able to reversing the transaction.
That makes the perceived legitimacy conveyed by an app market particularly necessary for crypto customers.
The Sparrow plaintiffs argue that Apple’s personal representations inspired them to imagine software program distributed by means of the App Store had been sufficiently vetted. They are searching for reimbursement for his or her stolen belongings, together with compensatory and punitive damages, restitution, and authorized charges.
They additionally need Apple to enhance and publicly disclose its procedures for detecting fraudulent functions and introduce warnings about dangers related to cryptocurrency apps.
Whether Apple bears obligation for the losses stays unresolved, and the corporate can contest each the plaintiffs’ reliance on its safety representations and their choice to enter delicate restoration credentials into third-party software program.
Apple additionally factors to the size of threats its review process already prevents.
The firm said final year that the App Store blocked greater than $9 billion in probably fraudulent transactions between 2020 and 2024, together with greater than $2 billion in 2024 alone.
During 2024, Apple stated it rejected almost 2 million app submissions that failed to satisfy requirements for safety, reliability and person expertise, whereas terminating greater than 146,000 developer accounts over fraud considerations and rejecting one other 139,000 developer enrollment makes an attempt.
Those figures present the size of malicious exercise Apple is trying to maintain outdoors its ecosystem. They additionally spotlight the stakes when fraudulent monetary software program will get by means of.
For crypto customers, the place surrendering a single restoration phrase can put a whole wallet past restoration, the rising checklist of impersonators is testing how a lot confidence Apple’s App Store badge ought to encourage.
The put up Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them appeared first on CryptoSlate.
