Real Losses Forced Apple to Remove Fake DeFiLlama App

Key Takeaways

DeFiLlama developers intentionally lost funds to a fraudulent app to prove theft, finally triggering Apple’s removal. This highlights systemic App Store vulnerabilities, where scammers use closed entities and seed phrase phishing to steal millions from

Woofun AI reports that the DeFiLlama team executed a deliberate 'sacrifice' experiment, loading cryptocurrency into a real wallet and handing it over to a fake version of their own app to witness the instant theft of assets. This strategic loss, detailed by developer 0xngmi on X Corp, served as the catalyst for Apple to finally remove the fraudulent application after months of inaction. The incident underscores a critical failure in platform governance, where standard complaints proved ineffective until tangible financial harm was documented as evidence.

For months, the DeFiLlama team had filed repeated complaints with Apple regarding trademark infringement and impersonation, yet saw no progress in resolving the issue. The lack of response from the platform forced a strategic shift from legal appeals to empirical demonstration. It was only when the team used actual losses as concrete evidence that Apple's review process was finally triggered. This delay highlights the inefficiency of relying solely on intellectual property claims to combat digital fraud in closed ecosystems.

DeFi protocols rely heavily on data panels provided by platforms like DeFiLlama, which traders use as important references for decision-making. This level of trust has unfortunately made the brand a prime target for imitators seeking to exploit user confidence.

The tactics utilized by this fake app were quite crude, asking users to enter their seed phrase—the 12 or 24 words that control the wallet—and then emptied all assets inside. No legitimate wallet or data app would ever request a seed phrase, making this a glaring red flag for informed users. Yet, the badge associated with the app store gave it a level of credibility that phishing sites could never match. This perceived legitimacy is why vulnerabilities in iPhone wallets often allow attackers to succeed, as users trust the platform's vetting process.

Woofun AI data shows that the operators successfully passed Apple's identity verification, using a shoe store registered 40 years ago and already closed down as the developer account holder. This exploitation of legacy business records allows scammers to create a facade of legitimacy. The same group has attempted to imitate other major crypto brands, indicating a coordinated effort to target multiple high-value entities. To counter this, the DeFiLlama team built a chain of evidence by funding a one-time-use wallet, installing the fake app, entering their seed phrase, suffering actual losses, and then submitting the proof to Apple.

Such incidents are not isolated cases, as Kaspersky's research found that there were 26 fraudulent wallet apps on the App Store in April, many of which pretended to be Ledger, MetaMask, and Trust Wallet. Victims are often not careless; in April, a fake Ledger app caused musician G. Love to lose nearly 6 BTC. Phishing websites are equally difficult to guard against; in May, a fake Uniswap clone site stole around $400,000 from traders. These high-profile losses demonstrate that even sophisticated users are vulnerable to platform-endorsed fraud.

Meanwhile, at the end of July, three Bitcoin holders sued Apple, claiming that a fake Sparrow Wallet app caused them to lose a total of $1.8 million. It is clear that there is a misalignment in incentives: brands suffer reputational damage, users suffer financial losses, while the app store continues to collect commissions from transactions. Security teams have been pointing out the same weakness, with Binance's chief security officer recently stating that what really causes wallets to lose money these days are phishing and malware, rather than complex cryptographic attacks. Fake ads and phishing sites, including the recent Trezor phishing campaign, are the best proof of this systemic risk.

DeFiLlama even delayed the release of its iOS version by several months to prevent users from installing fake versions by mistake. This caution cost the project time and momentum, illustrating the operational burden placed on legitimate developers. Whether other teams will follow this 'self-stealing' evidence-gathering strategy depends largely on problems with Apple's review process, rather than the crypto industry itself. The reliance on self-inflicted loss to trigger platform action marks a troubling precedent for digital asset security.

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions