Apple Promoted Fake Wallet, Stealing $1.8M Despite Developer Warnings

Key Takeaways

A lawsuit alleges Apple promoted a fraudulent Sparrow wallet app, resulting in $1.8 million in stolen Bitcoin. Despite warnings from the legitimate developer and victims, the fake app remained in the store, challenging Apple's security claims.

Woofun AI reports that a federal lawsuit has emerged alleging Apple actively promoted a counterfeit Sparrow Bitcoin wallet within its App Store, leading to the theft of $1.8 million from users. The legal action centers on the claim that despite explicit warnings from the legitimate developer, Craig Raw, and direct reports from victims, the fraudulent application remained accessible and was even highlighted by the platform, directly contradicting Apple’s public assertions regarding its rigorous security screening processes.

The core conflict arises from a pattern of negligence that spans more than two years, during which fake Sparrow apps persisted in the marketplace. This specific incident follows closely on the heels of broader industry scrutiny, as researchers recently identified 26 distinct applications impersonating major crypto brands across Apple’s ecosystem. These cumulative failures are placing immense pressure on one of Apple’s foundational arguments for maintaining strict control over software distribution: the premise that pre-installation screening provides superior protection against fraud and malicious software compared to open ecosystems.

Sparrow, founded by Craig Raw, is technically a desktop-only product, meaning any iPhone app bearing its name should have been immediately identifiable as an impersonator without requiring complex technical investigation.

However, Raw had been flagging unauthorized mobile versions of his wallet since early 2024. According to the complaint, variants carrying the Sparrow name continued to surface inside the App Store over the following year, suggesting a systemic failure in Apple’s detection mechanisms to distinguish between legitimate brand extensions and outright counterfeits.

The first plaintiff cited in the lawsuit, Jalen Delgado, allegedly downloaded one of these deceptive apps in May 2025. After supplying his seed phrase to the application, he lost just over 1 BTC, valued at about $120,000 in the filing. This initial loss highlights the vulnerability of users who trust the App Store’s curation, as the interface provided no clear indication that the software was not affiliated with the genuine desktop wallet developer.

The alleged notice to Apple became more direct two months later, when James Ramirez says he lost 7.4 BTC, worth approximately $875,000, after using another Sparrow impersonator on July 25, 2025. Crucially, Ramirez reported both the application and the theft to Apple that same day. This direct reporting mechanism, which Apple promotes as a key feature of its safety net, failed to prevent subsequent losses, raising questions about the responsiveness and efficacy of the company’s internal review teams when faced with active fraud.

Woofun AI data shows that Christopher Ellis allegedly encountered a Sparrow app through the App Store nine days later. He entered his recovery phrase and lost crypto assets valued at roughly $840,000, according to the complaint. The complaint further claims Apple did more than merely distribute the app; it alleges the platform ranked the Sparrow impersonator and surfaced it within cryptocurrency app collections. This editorial promotion potentially increased the credibility and reach of software masquerading as an established wallet, leveraging Apple’s brand trust to amplify the scam’s impact.

Apple says it removed fraudulent Sparrow apps and terminated the developer accounts responsible for them, pointing to its reporting channels and asserting it acts when applications are found to breach App Store rules.

However, Raw’s experience illustrates the difficulty legitimate developers have faced in stopping the impersonations. Apple initially treated Raw’s submission as potentially deceptive and warned that his developer account could be closed, before later reversing course. This episode adds another layer to the lawsuit’s argument: Apple allegedly struggled not only to keep impersonators out but also to distinguish the genuine wallet developer from those misusing his brand.

The broader threat landscape was further illuminated by Kaspersky, which analyzed the SparkKitty campaign active since at least fall 2025. The attack was more elaborate than simply publishing a malicious wallet directly through the App Store. Kaspersky found that the applications could redirect victims to phishing pages designed to resemble Apple's marketplace and persuade them to install developer profiles. Those profiles could then be used to install trojanized versions of crypto wallets outside the App Store, targeting hot wallets by monitoring recovery screens for seed phrases and cold-wallet users by impersonating hardware wallet interfaces to steal credentials.

American musician Garrett Dutton, better known as G. Love, said in April that he lost 5.9 BTC after downloading what he believed was legitimate Ledger software from Apple's App Store. Dutton entered his recovery phrase when prompted by the application, resulting in the loss of Bitcoin worth roughly $424,000. The repeated incidents are increasingly colliding with how Apple markets its control over software distribution, challenging the company’s argument that allowing unrestricted sideloading would weaken privacy and security protections, while its centralized review process is meant to intercept dangerous software before it reaches customers.

The Sparrow plaintiffs argue that Apple's own representations encouraged them to believe software distributed through the App Store had been sufficiently vetted, and they are seeking reimbursement for their stolen assets, along with compensatory and punitive damages, restitution, and legal fees. During 2024, Apple said it rejected nearly 2 million app submissions that failed to meet standards, while terminating more than 146,000 developer accounts over fraud concerns and rejecting another 139,000 developer enrollment attempts. These figures highlight the scale of malicious activity Apple is attempting to keep outside its ecosystem, yet they also underscore the severe stakes when fraudulent financial software inevitably gets through.

Vote

Will Apple tighten app review after the fake wallet incident?

0 people voted

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions