Users sue Apple over $1.8 million loss from fake crypto wallet on App Store

iconTechFlow
Share
AI summary iconSummary
Three users sued Apple, claiming $1.8 million in losses from counterfeit Sparrow wallets on the App Store. The lawsuit alleges that Apple failed to act despite warnings from the legitimate developer and user reports. Apple later removed the apps and suspended associated accounts. A Kaspersky report identified 26 fake apps mimicking MetaMask and Ledger. The case raises concerns around CFT, as counterfeit wallets could be exploited to launder funds or finance illegal activities. Traders are monitoring whether this impacts risk-on assets such as cryptocurrency.

Written by: Oluwapelumi Adejumo

Compiled by Saoirse, Foresight News

The tightly controlled Apple App Store is once again facing renewed scrutiny. Previously, three Bitcoin holders claimed they lost $1.8 million due to a fake crypto wallet app. Such malicious wallet applications have long been common, and even with Apple’s multi-layered review system, fraudulent software continues to reach users.

The lawsuit, filed on July 24 in California, alleges that Apple failed to fulfill its duty of adequate review by not removing various counterfeit Sparrow wallet apps, while simultaneously promoting the App Store as a secure and reliable source for software downloads.

More than two years ago, warnings were already issued regarding the fraudulent Sparrow app. Several months ago, researchers identified 26 counterfeit applications impersonating major cryptocurrency brands within the Apple ecosystem. A series of such incidents have placed increasing pressure on Apple’s long-standing principle: Apple advocates strict control over software distribution, asserting that pre-approval app reviews can best defend against fraud and malware.

The Sparrow developers warned Apple more than a year before users' assets were compromised.

In this case, the key point for Apple's liability is not that the fraudulent app was initially listed, but that Apple was already aware of the associated risks before victims were defrauded.

Sparrow's founder, Craig Raw, has been consistently reporting various unauthorized mobile counterfeit wallets since early 2024. Since Sparrow offers only a desktop version, Apple should be able to easily identify the iPhone app with the same name as a counterfeit without requiring complex technical investigation.

However, the complaint shows that throughout the following year, various applications using variants of the name Sparrow continued to appear on the App Store.

The lead plaintiff, Jalen Delgado, stated that in May 2025, he downloaded one of the counterfeit apps, entered his seed phrase, and lost one Bitcoin, which, according to the complaint, was worth approximately $120,000 at the time.

Two months later, the user’s report to Apple became more specific. James Ramirez stated that on July 25, 2025, he lost 7.4 bitcoins—valued at approximately $875,000—using another counterfeit Sparrow wallet, and he reported the app and the theft to Apple on the same day.

Nine days later, Christopher Ellis also found a Sparrow app on the App Store; after entering his recovery mnemonic, he lost cryptocurrency assets worth approximately $840,000.

The entire timeline is the core basis of the plaintiff's lawsuit. The plaintiff argues that when Ellis suffered property loss, Apple had received far more than generic complaints about brand counterfeiting—it had clear evidence demonstrating that this counterfeit wallet could lead to substantial Bitcoin theft.

The complaint further states that Apple did not merely list this counterfeit app; the platform also gave the fake Sparrow app boosted visibility, included it in a collection of cryptocurrency apps, and thereby implicitly increased the scam app’s credibility and expanded its reach.

The legal document states: "Users repeatedly reported to Apple that fraudulent high-risk applications existed on the App Store. However, Apple neither warned consumers about counterfeit wallets such as Sparrow on the App Store nor informed users that such software极易 leads to the theft of cryptocurrencies, seed phrases, private keys, wallet accounts, and other sensitive personal information."

Apple responded that it has removed all counterfeit Sparrow apps and suspended the associated developer accounts. Apple also stated that the platform has a dedicated reporting channel, and any app found to violate store guidelines will be addressed accordingly.

However, Craig Raw’s experience in defending his rights highlights the immense challenges legitimate developers face in eradicating brand counterfeiting. Last month, Craig Raw revealed that he had submitted a notice on the iOS platform to inform users that Sparrow has no official mobile version. Initially, Apple deemed this notice potentially misleading and even warned that it might suspend his developer account—later reversing this decision.

This also adds new evidence to the lawsuit: Apple not only fails to block counterfeit apps but also struggles to distinguish between legitimate developers and fraudulent ones impersonating established brands.

The issue of counterfeit wallets on the App Store is not limited to Sparrow alone.

The Sparrow-related disputes are just the tip of the iceberg of crypto wallet impersonation scams faced by Apple users.

In April, the Kaspersky Threat Research team released a report identifying 26 fraudulent apps impersonating popular cryptocurrency brands, including MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie.

Cryptocurrency impersonation apps on the Apple App Store (Source: Kaspersky)

Kaspersky stated that this phishing campaign has been active since at least fall 2025 and is highly likely linked to the actors behind the cyber group SparkKitty.

This scam is far more complex than simply listing malicious wallets. Fraudsters use app redirection to lead users to phishing websites mimicking the Apple App Store, tricking them into installing developer profiles; with these profiles, they can bypass the App Store entirely to install modified crypto wallets containing malware.

After the software is installed, the malicious program will aggressively steal credentials used to access user assets. For hot wallets, the malware monitors wallet creation and seed phrase recovery pages; as soon as the user enters their seed phrase, the hacker gains full control of all funds. Cold wallet users are also vulnerable to social engineering scams: malicious software mimicking hardware wallet interfaces tricks users into entering recovery credentials that should never be input into unfamiliar software.

The fraud group primarily targets users of the Apple China App Store, and many of the impersonated mainstream wallets were never officially listed on the China App Store. Numerous cases of significant asset theft due to counterfeit wallets have also occurred in the United States.

American musician Garrett Dutton (stage name G. Love) revealed in April that he downloaded what he believed to be a legitimate Ledger wallet from the App Store, resulting in the loss of 5.9 bitcoins. After following the software’s instructions to enter his recovery mnemonic phrase, approximately $424,000 worth of bitcoin was drained from his account. Blockchain investigators at ZachXBT traced the stolen funds to KuCoin’s deposit address; KuCoin temporarily froze the involved account during the investigation.

This incident is highly similar to the Sparrow lawsuit: users downloaded software impersonating a well-known wallet within the Apple ecosystem, entered their key credentials out of trust, and ultimately lost complete control of their assets.

Cryptocurrency scams sharply expose the false security claims of the App Store

A series of ongoing scam incidents continue to undermine Apple’s advertised advantages in ecosystem control.

Apple defines the App Store as a "secure and trusted software platform," claiming that all apps undergo multiple layers of review to protect users from scams, trojans, and various security risks. This security narrative serves as a key justification for Apple’s insistence on a closed ecosystem and strict control over software installation channels.

Apple has consistently argued that unrestricted sideloading would significantly reduce privacy and security protections on Apple devices; centralized review enables the interception of malware before it reaches users.

However, crypto wallets pose a significant challenge to this risk control model: such software can cause irreversible financial losses without complex malware, simply by using deceptive interfaces that mimic legitimate ones.

The mnemonic phrase fully controls the assets in a decentralized wallet. Once a user enters their mnemonic phrase into malicious software, hackers can transfer the assets to their own address; all transactions are irreversible, and no financial institution can recover them. For this reason, the platform’s credibility on the App Store is crucial for cryptocurrency users.

The plaintiff in the Sparrow case stated that Apple consistently emphasizes the reliability of its platform review process, leading users to assume that all software on the App Store has undergone rigorous verification. The plaintiff is demanding that Apple compensate for all stolen assets, as well as provide compensatory damages, punitive damages, litigation costs, and reimbursement of all lost funds. In addition, the plaintiff is requesting that Apple improve its process for detecting counterfeit applications, publicly disclose its review guidelines, and implement risk warnings specifically for cryptocurrency applications.

It is currently unclear whether Apple bears legal responsibility. Apple can counter with two points: first, users should not fully rely on platform claims, and second, users themselves were negligent in entering their private keys into third-party software.

Apple also disclosed its risk control achievements, stating that the platform blocked a massive volume of risky attacks. According to Apple’s publicly released data, from 2020 to 2024, the App Store prevented potential fraudulent transactions totaling over $9 billion, with the amount blocked in 2024 alone exceeding $2 billion. In 2024, Apple rejected nearly 2 million app submission applications that failed to meet security, stability, and usage guidelines; suspended over 146,000 developer accounts due to fraud; and denied 139,000 developer registrations.

This data is sufficient to demonstrate that the Apple ecosystem consistently faces massive malicious attacks, but it also highlights the severe consequences when financial scam apps slip through review.

For cryptocurrency users, leaking a mnemonic phrase could result in the permanent loss of wallet assets. With countless fake wallets emerging, people are beginning to reconsider: how much trust can still be placed in the App Store’s platform endorsement?

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.