Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them

by admin

Apple’s tightly controlled App Store is facing renewed scrutiny after three Bitcoin holders alleged they lost $1.8 million to a fake crypto wallet, adding to a growing list of malicious wallet apps that have reached users despite the company’s screening process.

The lawsuit, filed July 24 in California, accuses Apple of failing to adequately review and remove applications impersonating Sparrow Wallet while promoting the App Store as a safe and trusted source for software.

The case follows warnings dating back more than two years about fake Sparrow apps and comes months after researchers identified 26 applications impersonating major crypto brands across Apple’s ecosystem.

Together, the incidents are putting pressure on one of Apple’s longstanding arguments for maintaining tight control over software distribution: that screening applications before they reach users provides greater protection against fraud and malicious software.

Sparrow developer warned Apple more than a year before losses

Apple’s exposure in the case rests less on the initial appearance of a fraudulent app than on what the company allegedly knew before later victims were hit.

Sparrow founder Craig Raw had been flagging unauthorized mobile versions of his wallet since early 2024. Sparrow is a desktop-only product, so an iPhone app bearing its name should not have required a complex technical investigation to identify as an impersonator.

Yet the complaint says variants carrying the Sparrow name continued to surface inside the App Store over the following year.

The first plaintiff cited in the lawsuit, Jalen Delgado, allegedly downloaded one of those apps in May 2025. After supplying his seed phrase, he lost just over 1 BTC, valued at about $120,000 in the filing.

The alleged notice to Apple became more direct two months later.

James Ramirez says he lost 7.4 BTC, worth approximately $875,000, after using another Sparrow impersonator on July 25, 2025. He reported both the application and the theft to Apple that day.

Christopher Ellis allegedly encountered a Sparrow app through the App Store nine days later. He entered his recovery phrase and lost crypto assets valued at roughly $840,000, according to the complaint.

That sequence is central to the plaintiffs’ case. They are arguing that Apple was no longer dealing only with a previously reported brand impersonation by the time Ellis was targeted. It had allegedly received a fresh report linking a specific fake wallet to a major Bitcoin theft.

The complaint further claims Apple did more than distribute the app. It alleges the platform ranked the Sparrow impersonator and surfaced it within cryptocurrency app collections, potentially increasing the credibility and reach of software masquerading as an established wallet.

According to the lawsuit:

“Despite multiple reports made to Apple that its App Store hosted fraudulent and dangerous applications, Apple failed to warn consumers that spoofed wallet apps, including fake Sparrow applications, had appeared in the App Store and posed a serious risk of theft of cryptocurrency, seed phrases, private keys, wallet credentials, and other sensitive account information.”

Apple says it removed fraudulent Sparrow apps and terminated the developer accounts responsible for them.

The company has also pointed to its reporting channels and said it acts when applications are found to breach App Store rules.

Raw’s experience, however, illustrates the difficulty legitimate developers have faced in stopping the impersonations.

Last month, Raw revealed that he submitted a basic iOS listing intended to tell users that Sparrow had no official mobile version.

Apple initially treated that submission as potentially deceptive and warned that his developer account could be closed, according to Raw, before later reversing course.

The episode adds another layer to the lawsuit’s argument: Apple allegedly struggled not only to keep impersonators out, but also to distinguish the genuine wallet developer from those misusing his brand.

Apple’s App Store fake wallet problem has spread beyond Sparrow

The Sparrow dispute is part of a wider wave of crypto wallet impersonation targeting Apple users.

Kaspersky Threat Research said in April that it had identified 26 fraudulent applications mimicking crypto brands including MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken and Bitpie.

Fake Crypto Applications on Apple's App Store
Fake Crypto Applications on Apple’s App Store (Source: Kaspersky)

The campaign had been active since at least fall 2025 and was linked with moderate confidence to threat actors behind SparkKitty, according to the cybersecurity firm.

The attack was more elaborate than simply publishing a malicious wallet directly through the App Store.

Kaspersky found that the applications could redirect victims to phishing pages designed to resemble Apple’s marketplace and persuade them to install developer profiles. Those profiles could then be used to install trojanized versions of crypto wallets outside the App Store.

Once installed, the malicious software targeted the credentials controlling users’ assets.

For hot wallets, the malware monitored wallet recovery or creation screens for seed phrases. Attackers obtaining those words could then gain control over the victim’s funds.

Cold-wallet users faced a similar social-engineering threat. Fraudulent software impersonating interfaces associated with hardware wallets could persuade victims to surrender recovery credentials that should never be entered into an unverified application.

The campaign largely targeted users of Apple’s Chinese App Store, where official iOS versions of several wallets being impersonated were unavailable.

But significant losses involving fake wallet software have also emerged in the United States.

American musician Garrett Dutton, better known as G. Love, said in April that he lost 5.9 BTC after downloading what he believed was legitimate Ledger software from Apple’s App Store.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.