Apple Faces Lawsuit After Fake Crypto Wallets on App Store Allegedly Led to $1.8 Million in Losses

Apple Faces Lawsuit After Fake Crypto Wallets on App Store Allegedly Led to $1.8 Million in Losses

N
News Editor
2026-07-30 02:04:07
Apple’s App Store is facing renewed scrutiny after a lawsuit filed in California on July 24 alleged that three Bitcoin holders lost about $1.8 million after downloading fake Sparrow wallet apps. The complaint argues that Apple failed not only by allowing the apps onto the store, but by leaving them available after repeated warnings from both users and Sparrow founder Craig Raw, who had been reporting unauthorized mobile impersonations since early 2024 even though Sparrow has no official iPhone app. The filing also claims Apple boosted one of the fake apps through store recommendations and placement in a cryptocurrency app collection. The case lands against a broader backdrop. A Kaspersky Threat report released in April said researchers had identified 26 scam apps impersonating major crypto brands such as MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken and Bitpie. According to the report, the campaign had been active since at least autumn 2025 and may be linked to the attackers behind SparkKitty. The report described schemes that pushed users to phishing pages mimicking Apple’s App Store and tricked them into installing developer profiles, which then enabled trojanized wallet software outside normal App Store channels. Apple said it has removed the fake Sparrow apps and terminated the related developer accounts, while pointing to broader anti-fraud enforcement data it released last year.
AppleApp StoreFake WalletsSparrow WalletBitcoinCrypto ScamKaspersky

Apple’s App Store is under fresh pressure after a lawsuit filed in California on July 24 alleged that three Bitcoin holders lost roughly $1.8 million after downloading counterfeit cryptocurrency wallet apps. The plaintiffs say Apple failed to properly review the apps and did not remove them in time despite earlier warnings.

Apple Faces Lawsuit After Fake Crypto Wallets on App Store Allegedly Led to $1.8 Million in Losses 2

The report was written by Oluwapelumi Adejumo and translated by Saoirse for Foresight News.

The lawsuit centers on what Apple knew before the losses occurred

The key issue in the case is not only that the scam apps appeared on the App Store, but that Apple had allegedly been alerted to the risk before later victims were hit.

Craig Raw, founder of Sparrow, had been reporting unauthorized mobile wallet impersonations to Apple since early 2024. Sparrow itself only has a desktop version and no official iPhone app. On the plaintiffs’ telling, that should have made it relatively straightforward for Apple to identify iPhone apps using the Sparrow name as fakes.

Yet the complaint says variants using the Sparrow branding kept appearing on the App Store over the following year.

The first plaintiff, Jalen Delgado, said he downloaded one of the counterfeit apps in May 2025. After entering his seed phrase, he lost more than 1 BTC, which the complaint valued at about $120,000 at the time.

Two months later, the warnings became more specific. James Ramirez said that on July 25, 2025, he used another fake Sparrow wallet and lost 7.4 BTC, worth about $875,000. He said he reported both the app and the theft to Apple that same day.

Nine days later, Christopher Ellis found a Sparrow app in the App Store, entered his recovery seed phrase, and then lost crypto assets worth about $840,000.

That sequence is central to the plaintiffs’ case. They argue that by the time Ellis suffered his loss, Apple was no longer dealing with generic brand-impersonation complaints. It had, they say, already received a concrete report showing that a fake Sparrow wallet could lead to large Bitcoin thefts.

The complaint goes a step further, alleging that Apple did more than host the app. It says the platform amplified the fake Sparrow wallet through recommendation weighting and included it in a cryptocurrency app collection, which raised the app’s apparent credibility and widened its reach.

The filing states: “Users repeatedly alerted Apple that the App Store contained high-risk fraudulent applications. But Apple neither warned consumers that the App Store contained imitation wallets such as Sparrow nor informed users that these apps could easily lead to the theft of cryptocurrency, seed phrases, private keys, wallet accounts, and various forms of personal information.”

Apple said it has removed all of the fake Sparrow apps involved and terminated the associated developer accounts. The company also said it maintains a dedicated reporting channel and takes action when apps are found to violate store rules.

Craig Raw’s own experience has also become part of the argument against Apple. Last month, he said he had submitted a notice on iOS to tell users that Sparrow does not have an official mobile app. Apple initially judged that notice potentially misleading and even warned that his developer account could be banned, before later reversing that decision.

For the plaintiffs, that episode supports a broader claim: Apple not only failed to stop the impersonators, but at times struggled to distinguish legitimate developers from scammers using stolen branding.

Researchers had already identified broader fake-wallet activity on the App Store

The Sparrow dispute is only one example in a wider pattern of wallet impersonation scams affecting Apple users.

In a report released in April, Kaspersky Threat researchers said they had identified 26 scam apps impersonating well-known crypto brands. The list included MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie.

Kaspersky said the campaign had likely been active since at least autumn 2025 and was probably linked to the attackers behind the cybercrime group SparkKitty.

The method described in the report went beyond simply listing malicious wallets. Attackers used app redirects to send users to phishing pages designed to resemble Apple’s App Store, then tricked them into installing developer configuration profiles. Those profiles could then be used to bypass the App Store and install modified crypto wallet apps carrying trojans.

Once installed, the malware was built to capture the credentials that control user funds. In the case of hot wallets, trojans monitored wallet creation and seed recovery pages, allowing attackers to seize funds as soon as users entered a seed phrase. Cold-wallet users were also exposed to social-engineering tactics, with malware imitating hardware wallet interfaces and prompting users to type in recovery credentials that should never be entered into unfamiliar software.

The report said the campaign focused heavily on users of Apple’s China App Store, where a number of the impersonated mainstream wallets were not officially available in the first place. It also noted that the U.S. had seen multiple cases of large crypto losses tied to fake wallet apps.

One of those cases involved U.S. musician Garrett Dutton, known professionally as G. Love. In April, he said he downloaded what he believed was a legitimate Ledger wallet from the App Store and ultimately lost 5.9 BTC. After following the app’s instructions and entering his recovery seed phrase, Bitcoin worth about $424,000 was drained. Blockchain investigator ZachXBT later traced the stolen funds to a deposit address at crypto exchange KuCoin, which temporarily froze the account during the investigation.

That episode closely resembled the Sparrow case: users downloaded software in Apple’s ecosystem that borrowed the identity of a known wallet brand, trusted it, entered sensitive credentials, and then lost control of their assets.

Crypto scams are testing Apple’s security claims

These incidents cut into Apple’s long-running pitch that the App Store is a safe and trusted software marketplace. Apple has said apps go through multiple layers of review meant to protect users from scams, trojans, and other security threats. That argument has also been central to the company’s defense of its closed distribution model and tight control over software installation.

Apple has long argued that unrestricted sideloading would sharply weaken privacy and security protections on its devices, and that centralized review can intercept malicious software before it reaches users.

Crypto wallet scams expose a weak point in that model. Apps of this kind do not always need sophisticated malware to cause severe damage. A convincing interface can be enough to trigger irreversible financial loss.

Seed phrases confer full control over decentralized wallet assets. Once a user enters that phrase into malicious software, an attacker can transfer the funds to another address. Those transfers cannot be reversed, and there is no financial institution that can unwind the transaction. For crypto users, the App Store’s implied seal of trust carries unusual weight for that reason.

The plaintiffs in the Sparrow case say Apple’s repeated assurances about the reliability of its review process led users to assume that software on the App Store had been thoroughly vetted. They are seeking recovery of all stolen assets, compensatory damages, punitive damages, litigation costs, and repayment of the full losses. They also want Apple to improve its screening process for imitation apps, disclose its review standards, and add risk warnings for cryptocurrency apps.

Whether Apple will ultimately be held legally responsible remains unresolved. The report said Apple could push back on two grounds: that users should not rely entirely on the platform’s safety messaging, and that entering private wallet credentials into third-party software reflected user negligence.

Apple points to broader anti-fraud results

At the same time, Apple has cited its wider fraud-prevention record. According to data the company released last year, the App Store blocked more than $9 billion in potential fraudulent transactions from 2020 through 2024, with more than $2 billion blocked in 2024 alone.

Apple also said that in 2024 it rejected nearly 2 million app submissions for failing to meet standards covering security, reliability, and user experience. It banned more than 146,000 developer accounts for fraud and rejected another 139,000 developer enrollments.

Those figures show the scale of malicious activity targeting Apple’s ecosystem. They also highlight the cost of missing financial scam apps during review. For crypto users, exposing a single seed phrase can mean the permanent loss of wallet assets. The repeated appearance of fake wallets is forcing a harder look at how much trust Apple’s App Store endorsement still carries.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.