
Counterfeit Crypto Wallet Listed on App Store, Users Scammed out of $1.8 Million Sue Apple
TechFlow Selected TechFlow Selected

Counterfeit Crypto Wallet Listed on App Store, Users Scammed out of $1.8 Million Sue Apple
Developers Reported for a Year with No Result, App Store Has Already Found 26 Fake Wallets, Why Is Apple Turning a Blind Eye?
By: Oluwapelumi Adejumo
Compiled by: Saoirse, Foresight News
The strictly controlled Apple App Store is once again facing scrutiny. Previously, three Bitcoin holders claimed they lost $1.8 million due to a fake crypto wallet. Such malicious wallet applications are already common; even though Apple has set up multiple layers of review mechanisms, fraudulent software still manages to reach users.
The lawsuit filed on July 24 in California alleges that Apple failed to fulfill its adequate review obligations and did not remove various applications impersonating the Sparrow wallet, while simultaneously promoting the App Store as a safe and reliable software download channel.
More than two years ago, there were already risk warnings regarding fake Sparrow applications. A few months ago, researchers also identified 26 applications impersonating major mainstream cryptocurrency brands within the Apple ecosystem. The successive occurrences of various events have put significant pressure on a logic Apple has long adhered to: Apple argues that strict control over software distribution and pre-screening of applications can maximize defense against fraud and malicious software.
Sparrow Developers Warned Apple More Than a Year Before User Assets Were Compromised
In this case, the key point where Apple needs to bear responsibility lies not in the initial listing of the fraudulent application, but in the fact that Apple was already aware of the relevant risks before subsequent victims were defrauded.
Sparrow founder Craig Raw has been continuously reporting various unauthorized mobile fake wallets since early 2024. Sparrow itself only has a computer desktop version; theoretically, Apple should be able to identify that iPhone applications with the same name are counterfeit products without complex technical investigations.
However, the complaint shows that throughout the following year, various variant applications using the Sparrow name continued to appear in the App Store.
The first plaintiff in the lawsuit, Jalen Delgado, claimed that he downloaded one of the fake software applications in May 2025 and lost more than 1 Bitcoin after entering his seed phrase. According to the complaint, this asset was worth approximately $120,000 at the time.
Two months later, user reports to Apple became more specific. James Ramirez stated that on July 25, 2025, he used another fake Sparrow wallet and lost a total of 7.4 Bitcoins, worth approximately $875,000; he reported the application and the theft to Apple on the same day.
Nine days later, Christopher Ellis also found a Sparrow application on the App Store and lost crypto assets worth approximately $840,000 after entering his recovery seed phrase.
The entire timeline is the core basis for the plaintiffs' lawsuit. The plaintiffs argue that when Ellis suffered financial loss, Apple had already received not just ordinary complaints about brand impersonation, but clear cases proving that this fake wallet would cause large-scale Bitcoin theft.
The complaint further points out that Apple did not just list this fake application. The platform also provided traffic-weighted recommendations for this fake Sparrow application, including it in cryptocurrency application collections, indirectly enhancing the credibility of this fraudulent software and expanding its distribution range.
The litigation documents state: "Users have repeatedly reported to Apple that there are high-risk fraudulent applications within the App Store. However, Apple neither warned consumers about the presence of fake wallets such as Sparrow in the App Store, nor informed users that such software easily leads to the theft of cryptocurrencies, seed phrases, private keys, wallet accounts, and various privacy information."
Apple responded that it has removed all involved fake Sparrow applications and banned the corresponding developer accounts. Apple also stated that the platform has dedicated reporting channels, and as long as an application is verified to violate store rules, disposal measures will be taken.
However, Craig Raw's rights protection experience reflects how difficult it is for legitimate developers to fundamentally rectify the chaos of brand impersonation. Last month, Craig Raw revealed that he had submitted page public information on the iOS platform to inform users that Sparrow does not have an official mobile version. However, Apple initially determined that this public content was suspected of being misleading and even warned that his developer account might be banned, before subsequently overturning this determination.
This matter also adds new arguments to the lawsuit: Apple not only fails to stop fake software but even struggles to distinguish between legitimate developers and fraudulent developers who steal brands.
Fake Wallet Issues in App Store Are Not Limited to Sparrow
Disputes related to Sparrow are just the tip of the iceberg of crypto wallet impersonation fraud encountered by Apple users.
The Kaspersky Threat Research team released a report in April, identifying a total of 26 fraudulent applications impersonating popular crypto brands, including MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie.

Cryptocurrency impersonation applications in the Apple App Store (Source: Kaspersky)
Kaspersky stated that this round of fraudulent activity has been active at least since the fall of 2025 and has a high probability of being related to the behind-the-scenes attackers of the network organization SparkKitty.
This fraud scheme is far more complex than simply listing malicious wallets. Scammers use application redirects to guide users to phishing pages impersonating the Apple App Store, inducing users to install developer profiles; relying on such profiles, scammers can also bypass the App Store to install tampered crypto wallets carrying Trojans.
After the software is installed, the malicious program will do its utmost to steal various credentials controlling user assets. For hot wallets, the Trojan monitors wallet creation and seed phrase recovery pages; as long as the user enters the seed phrase, hackers can control all funds. Cold wallet users are equally unable to escape social engineering fraud traps: malicious software impersonating hardware wallet interfaces will deceive users into entering recovery credentials that should not be entered into unfamiliar software.
The fraud gang specifically targets Apple China App Store users; many of the impersonated mainstream wallets are not listed on the China App Store themselves. Multiple cases of large-scale asset theft caused by fake wallets have also occurred in the United States.
American musician Garrett Dutton (stage name G. Love) revealed in April that he downloaded what he believed to be the genuine Ledger wallet on the App Store and ultimately lost 5.9 Bitcoins. After he filled in the recovery seed phrase according to the software instructions, Bitcoins worth approximately $424,000 were all transferred away. Blockchain investigator ZachXBT tracked the stolen funds flowing into the deposit address of crypto exchange KuCoin, and KuCoin temporarily froze the involved account during the investigation.
This incident is highly similar to the Sparrow lawsuit case: users download software impersonating well-known wallet names within the Apple ecosystem, fill in key credentials out of trust, and ultimately lose complete control of their assets.
Crypto Fraud Sharply Pierces App Store's Security Marketing Rhetoric
Successive fraud incidents continuously impact the ecosystem control advantages that Apple promotes externally.
Apple defines the App Store as a "safe and trusted software platform," claiming that all applications undergo multiple layers of review to protect users from fraud, Trojans, and various security risks. This security rhetoric is also an important reason for Apple's insistence on a closed ecosystem and strict control over software installation channels.
Apple has always argued that unrestricted opening of sideloading would significantly reduce the privacy and security protection of Apple devices; relying on centralized review allows interception to be completed before malicious software reaches users.
However, crypto wallets have become a huge test for this risk control model: such software does not require complex Trojan programs; merely relying on interfaces that are indistinguishable from the real thing can cause irreversible financial loss.
Seed phrases fully control decentralized wallet assets. Once a user enters a seed phrase within malicious software, hackers can transfer assets to their own addresses; all transfers cannot be withdrawn, and no financial institution can reverse the transaction. Precisely because of this, the platform credibility of the App Store is crucial for cryptocurrency users.
Plaintiffs in the Sparrow case stated that Apple continuously emphasizes that platform review is reliable, causing users to default to assuming that software within the App Store has undergone strict verification. The plaintiffs require Apple to compensate for all stolen assets, as well as pay compensatory damages, punitive damages, litigation costs, and return all lost funds. In addition, the plaintiffs require Apple to optimize the fake application screening process and publicly disclose review guidelines, adding risk warnings for cryptocurrency applications.
Currently, whether Apple needs to bear legal liability remains undecided. Apple can refute on two points: first, users should not completely trust platform promotions blindly; second, users themselves were negligent in entering private keys into third-party software.
Apple simultaneously showcased risk control results, stating that the platform intercepted massive risk attacks. Apple published data last year: from 2020 to 2024, the App Store cumulatively blocked potential fraudulent transactions worth over $9 billion, with the intercepted amount in 2024 alone exceeding $2 billion. In 2024, Apple rejected nearly 2 million application listing requests that did not meet security, stability, and usage specifications; banned over 146,000 developer accounts due to fraud, and additionally refused 139,000 developer registrations.
These data are sufficient to prove that the Apple ecosystem faces massive malicious attacks year-round, but also highlight that once financial fraud applications pass review unchecked, the cost is extremely severe.
For cryptocurrency users, leaking a string of seed phrases could mean permanently losing wallet assets. The endless emergence of fake wallets also causes everyone to begin re-examining: how much trust can people actually place in the App Store's platform endorsement.
Join TechFlow official community to stay tuned
Telegram:https://t.me/TechFlowDaily
X (Twitter):https://x.com/TechFlowPost
X (Twitter) EN:https://x.com/BlockFlow_News














