A counterfeit cryptocurrency wallet was listed on the App Store, users were scammed and have sued Apple for 1.8 million dollars.

CN
14 hours ago
The developer reported fruitlessly for a year, the App Store has found 26 fake wallets, why is Apple turning a blind eye?

Written by: Oluwapelumi Adejumo

Translated by: Saoirse, Foresight News

The strictly controlled Apple App Store is once again under scrutiny from multiple parties. Three Bitcoin holders previously claimed to have lost $1.8 million due to a fake cryptocurrency wallet. Such malicious wallet applications have long been common, and even though Apple has set up multi-tiered review mechanisms, fraudulent software is still able to reach users.

This lawsuit, filed on July 24 in California, alleges that Apple failed to fulfill its review obligations and did not remove various applications imitating the Sparrow wallet, while publicly promoting the App Store as a safe and reliable download channel.

As early as more than two years ago, there were already risk warnings regarding imitations of the Sparrow application. A few months ago, researchers also identified 26 applications in the Apple ecosystem that imitated various mainstream cryptocurrency brands. The continuous occurrence of various incidents has put pressure on Apple’s long-held logic: Apple advocates strict control over software distribution, claiming that preemptive application reviews can minimize fraud and malware.

Sparrow developers warned Apple of user asset harm more than a year ago

The key point of Apple's responsibility in this case does not lie in the initial listing of the fraudulent application, but in the fact that Apple was already aware of the related risks before subsequent victims were defrauded.

Craig Raw, the founder of Sparrow, has been continuously reporting various unauthorized mobile imitation wallets since early 2024. Sparrow itself only has a desktop version, so Apple should theoretically be able to recognize that an iPhone application with the same name is an imitation product without complicated technical investigations.

However, the lawsuit shows that for an entire year afterward, various applications using the Sparrow name continued to appear in the App Store.

The first plaintiff in the lawsuit, Jalen Delgado, stated that he downloaded one of the fake applications in May 2025, and after entering the recovery phrase, he lost over 1 Bitcoin, which at that time was worth about $120,000 according to the lawsuit.

Two months later, user complaints to Apple became clearer. James Ramirez stated that he used another Sparrow imitation wallet on July 25, 2025, and lost a total of 7.4 Bitcoins, worth about $875,000; he reported this application and the theft to Apple on the same day.

Nine days later, Christopher Ellis also found a Sparrow application in the App Store and, after entering the recovery phrase, lost cryptocurrency assets worth about $840,000.

The entire timeline is the core basis for the plaintiffs' lawsuit. The plaintiffs argue that when Ellis suffered property loss, Apple had received complaints that were no longer just ordinary complaints about brand imitation, but had clear cases proving that this imitation wallet would cause significant Bitcoin theft.

The lawsuit further points out that Apple did not only list this imitation application. The platform also heavily promoted this Sparrow imitation application, including it in cryptocurrency application collections, indirectly increasing the credibility of this fraudulent software and expanding its reach.

The legal documents state: "Users have repeatedly reported to Apple that there are high-risk fraudulent applications in the App Store. However, Apple neither warned consumers about the existence of various imitation wallets like Sparrow in the App Store, nor informed users that such software can easily lead to the theft of cryptocurrency, recovery phrases, private keys, wallet accounts, and various personal information."

Apple responded by stating that it has removed all involved fraudulent Sparrow applications and banned the corresponding developer accounts. Apple also indicated that the platform has specialized reporting channels, and if violations of store rules are confirmed, it will take remedial measures.

However, Craig Raw's experience in defending his rights reflects the difficulties that legitimate developers face in eradicating brand imitation issues. Last month, Craig Raw revealed that he had submitted information on the iOS platform to inform users that Sparrow does not have an official mobile version. However, Apple initially determined that this notice contained misleading implications, even warning that it might ban his developer account, before eventually overturning this judgment.

This incident also adds new arguments to the lawsuit: Apple not only fails to stop imitation software but also finds it difficult to distinguish between legitimate developers and fraudulent developers who misuse brands.

The problem of fake wallets in the App Store is not limited to Sparrow

The disputes related to Sparrow are just the tip of the iceberg when it comes to Apple users encountering cryptocurrency wallet imitation fraud.

The Kaspersky Threat Research team released a report in April, identifying a total of 26 fraudulent applications imitating popular cryptocurrency brands, including MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie.

Fake cryptocurrency applications in the Apple App Store (source: Kaspersky)

Kaspersky noted that this round of fraud activities has been active at least since the fall of 2025 and is likely related to the cyber organization SparkKitty.

This fraud scheme is far more complex than simply listing malicious wallets. The scammers redirect users to phishing web pages that imitate the Apple App Store through the application, enticing them to install developer configuration profiles; relying on such configuration files, scammers can bypass the App Store and install modified cryptocurrency wallets carrying trojans.

Once the software is installed, the malicious program will fully steal various credentials that control user assets. For hot wallets, the trojan will monitor the wallet creation and recovery phrase pages; as soon as users enter the recovery phrase, hackers can take control of all funds. Cold wallet users are also difficult to escape social engineering fraud traps: malware posing as hardware wallet interfaces can deceive users into entering recovery credentials that should not be inputted into unfamiliar software.

This fraud gang primarily targets Apple App Store users in China, with many of the mainstream wallets being imitated not even listed in the Chinese App Store. Several cases of significant asset theft due to fake wallets have also occurred in the United States.

American musician Garrett Dutton (stage name G. Love) revealed in April that he had downloaded what he believed was the genuine Ledger wallet from the App Store, ultimately losing 5.9 Bitcoins. Following the software’s instructions to input the recovery phrase, cryptocurrencies worth about $424,000 were completely transferred away. Blockchain investigator ZachXBT traced the stolen funds to a recharge address on the cryptocurrency exchange KuCoin, which temporarily froze the involved accounts during the investigation.

This incident is highly similar to the Sparrow lawsuit: users download software that mimics well-known wallet names in the Apple ecosystem, fill in key credentials out of trust, and ultimately lose control of their assets.

Cryptocurrency fraud sharply undermines the App Store's safety claims

The continuous stream of fraud incidents poses ongoing challenges to Apple's externally promoted ecosystem control advantages.

Apple defines the App Store as a "safe and trustworthy software platform," claiming that all applications undergo multi-layered reviews to protect users from fraud, trojans, and various security risks. This security rhetoric is also a key reason Apple insists on a closed ecosystem and strictly controls software installation channels.

Apple has long argued that unrestricted sideloading would significantly reduce the privacy and security protections of Apple devices; relying on centralized reviews, it can intercept malicious software before it reaches users.

However, cryptocurrency wallets have become a huge test for this risk control model: such software does not require complex trojan programs and can cause irreversible property loss simply by having a lifelike interface.

The recovery phrase fully controls decentralized wallet assets. Once users input the recovery phrase within malicious software, hackers can transfer assets to their addresses, and all transactions cannot be reversed, with no financial institution able to restore the transaction. For this reason, the platform credibility of the App Store is crucial for cryptocurrency users.

The plaintiffs in the Sparrow case stated that Apple constantly emphasizes the reliability of platform reviews, leading users to assume that the software in the App Store has undergone strict verification. The plaintiffs demand that Apple compensate for all stolen assets, as well as compensatory damages, punitive damages, litigation costs, and return all loss amounts. In addition, the plaintiffs request that Apple optimize the screening process for imitation applications and publicly disclose review criteria, adding risk warnings specifically for cryptocurrency applications.

Currently, it is unclear whether Apple needs to bear legal responsibility. Apple can counter with two points: one is that users should not completely trust platform promotions, and the second is that users themselves were negligent in entering private keys into third-party software.

Apple meanwhile showcases its risk control achievements, stating that the platform has intercepted a vast number of risk attacks. Apple publicly shared data last year: from 2020 to 2024, the App Store has cumulatively blocked potential fraudulent transactions valued at over $9 billion, with the amount intercepted in 2024 alone exceeding $2 billion. In 2024, Apple rejected nearly 2 million application listing requests that did not meet safety, stability, and usability standards; over 146,000 developer accounts were banned for fraud, and an additional 139,000 developer registrations were rejected.

These figures demonstrate that the Apple ecosystem faces a massive volume of malicious attacks every year, but also highlight the extremely severe consequences of missing a review for financial fraud applications.

For cryptocurrency users, leaking a single recovery phrase can lead to permanent loss of wallet assets. The endless stream of imitation wallets has also prompted everyone to reassess how much trust can still be placed in the platform endorsement of the App Store.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink