Apple’s tightly controlled App Store is facing new scrutiny after three Bitcoin holders claimed they lost $1.8 million to fake cryptocurrency wallets. This adds to the growing list of malicious wallet apps that have reached users despite the company’s vetting process.
The lawsuit, filed July 24 in California, accuses Apple of promoting the App Store as a safe and trusted software source while failing to properly review and remove applications that impersonate Sparrow Wallet.
The lawsuit follows more than two-year-old warnings about fake Sparrow apps and comes months after researchers identified 26 applications masquerading as major cryptocurrency brands across Apple’s ecosystem.
These incidents add to Apple’s long-standing insistence on maintaining strict controls over software distribution: Screening applications before they reach users provides greater protection against fraud and malicious software.
Sparrow developer warns Apple more than a year ahead of losses
Apple’s findings in this case are based less on the fraudulent app’s initial appearance and more on what Apple allegedly knew before subsequent victims were harmed.
Sparrow founder Craig Raw has been warning of fraudulent activity on the mobile version of his wallet since early 2024. Because Sparrow is a desktop-only product, no complicated technical research was required to identify the eponymous iPhone app as an impostor.
However, the complaint says variants bearing the Sparrow name continued to appear in the App Store over the next year.
Jalen Delgado, the first plaintiff named in the lawsuit, allegedly downloaded one of these apps in May 2025. After providing the seed phrase, he lost just over 1 BTC, which the complaint says was worth about $120,000.
The purported notice to Apple became more direct two months later.
James Ramirez said he lost 7.4 BTC (worth about $875,000) after using another Sparrow impersonation on July 25, 2025. He reported both the application and the theft to Apple that day.
Christopher Ellis allegedly came across the Sparrow app through the App Store nine days later. He entered the recovery phrase and lost approximately $840,000 worth of crypto assets, according to the complaint.
This series of events is at the heart of the plaintiffs’ lawsuit. They argue that at the time Mr. Ellis was targeted, Apple was not just dealing with the brand impersonation that had already been reported. The company has reportedly received a new report linking certain fake wallets to large-scale Bitcoin theft.
The complaint further alleges that Apple did more than just distribute the app. The platform claims to have ranked Sparrow impersonators and surfaced them within a collection of crypto apps, potentially increasing the credibility and reach of existing software masquerading as wallets.
According to the complaint:
“Despite multiple reports to Apple that its App Store was hosting fraudulent and dangerous applications, Apple failed to warn consumers that spoofed wallet apps, including the fake Sparrow application, were appearing on the App Store, posing a significant risk of theft of cryptocurrencies, seed phrases, private keys, wallet credentials, and other sensitive account information.”
Apple announced that it has removed the fraudulent Sparrow apps and terminated the developer accounts involved with them.
The company also pointed to its reporting channels and said it will take action if an application is found to violate App Store rules.
But Raw’s experience illustrates the difficulty legitimate developers face in thwarting impersonation.
Last month, Raw revealed that it submitted a basic iOS listing aimed at informing users that Sparrow does not have an official mobile version.
Raw said Apple initially treated the submission as potentially deceptive and warned that developer accounts could be closed, but later reversed course.
This episode adds another layer to the lawsuit’s claims. Apple reportedly struggled not only to keep out impersonators, but also to distinguish between genuine wallet developers and those abusing its brand.
Apple’s App Store fake wallet problem extends beyond Sparrow
The Sparrow dispute is part of a growing wave of crypto wallet impersonations targeting Apple users.
Kaspersky Threat Research announced in April that it had identified 26 fraudulent applications that imitated cryptocurrency brands such as MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie.
The cybersecurity firm says the campaign has been active since at least the fall of 2025 and has been linked with some certainty to the attackers behind SparkKitty.
This attack was more complex than simply exposing a malicious wallet directly through the App Store.
Kaspersky Lab has discovered that these applications can redirect victims to phishing pages that resemble Apple’s Marketplace and induce them to install developer profiles. These profiles could be used to install Trojanized versions of cryptocurrency wallets outside of the App Store.
Once installed, malicious software targets the credentials that control a user’s assets.
For hot wallets, the malware monitored the wallet recovery or creation screen for the seed phrase. Once an attacker obtains these words, they may be able to take control of the victim’s funds.
Cold wallet users faced similar social engineering threats. Malicious software that impersonates the interface associated with a hardware wallet can convince victims to provide recovery credentials that should never be entered into unverified applications.
The campaign primarily targeted users of Apple’s China App Store, and official iOS versions of some of the spoofed wallets were not available.
However, the US has also experienced significant losses related to fake wallet software.
In April, American musician Garrett Dutton, better known as G. Love, said he lost 5.9 BTC after downloading what he believed to be legitimate ledger software from Apple’s App Store.
Mr. Dutton followed the application’s instructions and entered his recovery phrase. His Bitcoins, worth about $424,000 at the time, were later transferred.
Blockchain investigator ZachXBT traced the stolen assets to a deposit address associated with cryptocurrency exchange KuCoin and temporarily frozen the suspect account while investigating the incident.
This episode is very similar to the allegations at the center of the Sparrow lawsuit. Users encountered software that passed on the identity of a cryptocurrency wallet established through Apple’s ecosystem, trusted it, entered recovery credentials, and lost control of their assets.
Cryptocurrency fraud challenges Apple’s App Store security proposals
The repeated incidents increasingly clash with the way Apple advertises its control over software distribution.
Apple describes the App Store as a “safe and trusted place” and says applications undergo a review process aimed at protecting users from fraud, malware and other security threats.
This promise has also supported Apple’s broader defense of its tightly controlled ecosystem.
The company claims that allowing unlimited sideloading could weaken device privacy and security protections, while its centralized review process allows potentially dangerous software to be intercepted before it reaches customers.
Crypto wallets create a particularly difficult test for that model because an application does not necessarily require sophisticated malware to cause irreversible loss.
Convincing imitation is enough.
A seed phrase typically controls the assets associated with a self-custodial wallet. Once a user enters these words into malicious software, the attacker can transfer assets to an address controlled by the attacker, bypassing the bank or payment processor who can reverse the transaction.
For crypto users, the legitimacy conveyed by app marketplaces is therefore particularly important.
The Sparrow plaintiffs argue that Apple’s own representations led them to believe that the software distributed through the App Store was adequately vetted. They are seeking reimbursement of stolen assets, along with compensatory and punitive damages, restitution and legal costs.
It also calls on Apple to improve and publish procedures for detecting fraudulent applications and introduce warnings about the risks associated with crypto apps.
Whether Apple bears legal liability for the losses is unresolved, and the company may challenge both the plaintiffs’ reliance on the company’s security representations and the plaintiffs’ decision to enter sensitive recovery credentials into third-party software.
Apple also points to the scale of threats its review process has already thwarted.
The company announced last year that the App Store blocked more than $9 billion in potential fraudulent transactions from 2020 to 2024, including more than $2 billion in transactions in 2024 alone.
Apple announced that in 2024, it will reject nearly 2 million app applications that don’t meet security, reliability, and user experience standards, while suspending more than 146,000 developer accounts and rejecting an additional 139,000 developer registration attempts due to fraud concerns.
These numbers demonstrate the scale of malicious activity that Apple is trying to keep out of its ecosystem. It also highlights the dangers of compromised financial software.
For cryptocurrency users, abandoning a single recovery phrase can make their entire wallet unrecoverable, so a growing list of imposters is testing just how much trust Apple’s App Store badge can inspire.
(Tag Translation) Bitcoin

