A federal judge in California has dismissed a class-action lawsuit against Apple Inc., ruling that the tech giant is not responsible for losses incurred by users who downloaded a fraudulent cryptocurrency wallet app from its App Store. The ruling, issued on September 2 by U.S. District Judge Phyllis J. Hamilton, upholds Apple’s immunity under Section 230 of the Communications Decency Act and its user agreement terms that disclaim liability for third-party applications.
Case Background: The Fake Toast Plus App
The lawsuit was filed by Hadona Diep, a cryptocurrency investor who claimed she lost approximately 474 XRP tokens—worth more than $5,000 at the time—after downloading a counterfeit version of the legitimate “Toast Plus” XRP wallet from the Apple App Store in January 2018. The fake app used a similar name and logo to the original, which was developed by the now-defunct Rippex. Diep initially transferred her XRP from the Bittrex exchange to her Rippex wallet, but later linked her private seed phrase to the fraudulent Toast Plus app in March 2021. When she checked her account in August 2021, she found her account had been deleted and her XRP vanished.
Co-plaintiff Ryumei Nagao also joined the suit, claiming a loss of $500,000 under similar circumstances. The plaintiffs argued that Apple negligently allowed the fraudulent app to remain in the App Store for an extended period, failing to implement adequate security checks to protect users.
Legal Reasoning: Section 230 Immunity and User Terms
Judge Hamilton sided with Apple on multiple legal grounds. First, she ruled that Apple qualifies as a “publisher” of third-party content under Section 230 of the Communications Decency Act, a federal law that broadly shields online platforms from liability for content created by others. Since the fake app was developed by an independent third party and merely hosted on Apple’s platform, Apple cannot be held liable for any harm caused by that content.
Second, the judge found that Diep failed to state viable claims under California’s and Maryland’s consumer privacy acts because she did not provide specific details about the time, place, and content of any alleged false representations made by Apple. General allegations that Apple “should have known” about the fake app were insufficient to reach the level of a deceptive practice under these statutes.
Third, Hamilton pointed to Apple’s standard App Store terms and conditions, which explicitly state that “Apple is not responsible for any damages arising out of or related to the use of third-party apps.” The court noted that Diep had agreed to these terms when she created her Apple ID and downloaded the app, thus contractually releasing Apple from liability.
Broader Implications for Crypto Users and Platform Accountability
The ruling reinforces the strong legal protection technology platforms have historically enjoyed under Section 230, particularly when it comes to user-generated or third-party content. While consumer advocates argue that app store operators like Apple should bear some responsibility for verifying the safety of apps they publish, courts have consistently held that platforms are not insurers of app quality—especially when the platform clearly disclaims liability in its terms of service.
For cryptocurrency investors, this case serves as a stark reminder to exercise extreme caution when downloading wallet apps. Impersonation scams remain common: fraudsters create copycat apps with names and logos nearly identical to legitimate products, hoping to trick users into revealing private keys or seed phrases. In this instance, the fake Toast Plus app exploited a user who had already been using a legitimate wallet, demonstrating that even experienced users can be vulnerable.
The decision also contrasts with other legal battles involving fake crypto apps. For example, a similar lawsuit against Google over a fraudulent crypto wallet on the Google Play Store is still pending. However, the legal landscape may shift if lawmakers decide to reform Section 230, which has faced bipartisan criticism in recent years for enabling harm on social media platforms. For now, Apple’s victory sets a precedent that may discourage similar claims against platform operators, but it does not eliminate the risk of future litigation if fraudsters become more sophisticated or if regulators impose stricter duty-of-care standards.
In the immediate aftermath, neither Diep’s nor Nagao’s attorney has announced an appeal. However, the plaintiffs could potentially seek to amend their complaint to include more specific allegations of misrepresentation or to challenge the contractual waiver. Legal observers note that while Section 230 offers broad immunity, it is not absolute; if Apple had been actively involved in designing or promoting the fake app, the outcome might differ.

