Apple’s tightly managed App Retailer is dealing with new scrutiny after three Bitcoin holders claimed they misplaced $1.8 million to faux cryptocurrency wallets. This provides to the rising listing of malicious pockets apps which have reached customers regardless of the corporate’s vetting course of.
The lawsuit, filed July 24 in California, accuses Apple of selling the App Retailer as a protected and trusted software program supply whereas failing to correctly assessment and take away functions that impersonate Sparrow Pockets.
The lawsuit follows greater than two-year-old warnings about faux Sparrow apps and comes months after researchers recognized 26 functions masquerading as main cryptocurrency manufacturers throughout Apple’s ecosystem.
These incidents add to Apple’s long-standing insistence on sustaining strict controls over software program distribution: Screening functions earlier than they attain customers gives larger safety in opposition to fraud and malicious software program.
Sparrow developer warns Apple greater than a yr forward of losses
Apple’s findings on this case are primarily based much less on the fraudulent app’s preliminary look and extra on what Apple allegedly knew earlier than subsequent victims have been harmed.
Sparrow founder Craig Uncooked has been warning of fraudulent exercise on the cellular model of his pockets since early 2024. As a result of Sparrow is a desktop-only product, no sophisticated technical analysis was required to establish the eponymous iPhone app as an impostor.
Nevertheless, the criticism says variants bearing the Sparrow identify continued to look within the App Retailer over the subsequent yr.
Jalen Delgado, the primary plaintiff named within the lawsuit, allegedly downloaded one among these apps in Might 2025. After offering the seed phrase, he misplaced simply over 1 BTC, which the criticism says was value about $120,000.
The purported discover to Apple turned extra direct two months later.
James Ramirez stated he misplaced 7.4 BTC (value about $875,000) after utilizing one other Sparrow impersonation on July 25, 2025. He reported each the appliance and the theft to Apple that day.
Christopher Ellis allegedly got here throughout the Sparrow app by means of the App Retailer 9 days later. He entered the restoration phrase and misplaced roughly $840,000 value of crypto belongings, in response to the criticism.
This collection of occasions is on the coronary heart of the plaintiffs’ lawsuit. They argue that on the time Mr. Ellis was focused, Apple was not simply coping with the model impersonation that had already been reported. The corporate has reportedly obtained a brand new report linking sure faux wallets to large-scale Bitcoin theft.
The criticism additional alleges that Apple did extra than simply distribute the app. The platform claims to have ranked Sparrow impersonators and surfaced them inside a set of crypto apps, probably rising the credibility and attain of present software program masquerading as wallets.
In response to the criticism:
“Regardless of a number of studies to Apple that its App Retailer was internet hosting fraudulent and harmful functions, Apple did not warn customers that spoofed pockets apps, together with the faux Sparrow software, have been showing on the App Retailer, posing a major danger of theft of cryptocurrencies, seed phrases, personal keys, pockets credentials, and different delicate account data.”
Apple introduced that it has eliminated the fraudulent Sparrow apps and terminated the developer accounts concerned with them.
The corporate additionally pointed to its reporting channels and stated it can take motion if an software is discovered to violate App Retailer guidelines.
However Uncooked’s expertise illustrates the issue respectable builders face in thwarting impersonation.
Final month, Uncooked revealed that it submitted a fundamental iOS itemizing aimed toward informing customers that Sparrow doesn’t have an official cellular model.
Uncooked stated Apple initially handled the submission as probably misleading and warned that developer accounts might be closed, however later reversed course.
This episode provides one other layer to the lawsuit’s claims. Apple reportedly struggled not solely to maintain out impersonators, but additionally to tell apart between real pockets builders and people abusing its model.
Apple’s App Retailer faux pockets downside extends past Sparrow
The Sparrow dispute is a part of a rising wave of crypto pockets impersonations focusing on Apple customers.
Kaspersky Risk Analysis introduced in April that it had recognized 26 fraudulent functions that imitated cryptocurrency manufacturers similar to MetaMask, Ledger, Belief Pockets, Coinbase, TokenPocket, imToken, and Bitpie.
The cybersecurity agency says the marketing campaign has been lively since not less than the autumn of 2025 and has been linked with some certainty to the attackers behind SparkKitty.
This assault was extra advanced than merely exposing a malicious pockets instantly by means of the App Retailer.
Kaspersky Lab has found that these functions can redirect victims to phishing pages that resemble Apple’s Market and induce them to put in developer profiles. These profiles might be used to put in Trojanized variations of cryptocurrency wallets exterior of the App Retailer.
As soon as put in, malicious software program targets the credentials that management a person’s belongings.
For decent wallets, the malware monitored the pockets restoration or creation display screen for the seed phrase. As soon as an attacker obtains these phrases, they are able to take management of the sufferer’s funds.
Chilly pockets customers confronted related social engineering threats. Malicious software program that impersonates the interface related to a {hardware} pockets can persuade victims to offer restoration credentials that ought to by no means be entered into unverified functions.
The marketing campaign primarily focused customers of Apple’s China App Retailer, and official iOS variations of a number of the spoofed wallets weren’t obtainable.
Nevertheless, the US has additionally skilled vital losses associated to faux pockets software program.
In April, American musician Garrett Dutton, higher often known as G. Love, stated he misplaced 5.9 BTC after downloading what he believed to be respectable ledger software program from Apple’s App Retailer.
Mr. Dutton adopted the appliance’s directions and entered his restoration phrase. His Bitcoins, value about $424,000 on the time, have been later transferred.
Blockchain investigator ZachXBT traced the stolen belongings to a deposit handle related to cryptocurrency change KuCoin and briefly frozen the suspect account whereas investigating the incident.
This episode is similar to the allegations on the heart of the Sparrow lawsuit. Customers encountered software program that handed on the id of a cryptocurrency pockets established by means of Apple’s ecosystem, trusted it, entered restoration credentials, and misplaced management of their belongings.
Cryptocurrency fraud challenges Apple’s App Retailer safety proposals
The repeated incidents more and more conflict with the way in which Apple advertises its management over software program distribution.
Apple describes the App Retailer as a “protected and trusted place” and says functions endure a assessment course of aimed toward defending customers from fraud, malware and different safety threats.
This promise has additionally supported Apple’s broader protection of its tightly managed ecosystem.
The corporate claims that permitting limitless sideloading may weaken gadget privateness and safety protections, whereas its centralized assessment course of permits probably harmful software program to be intercepted earlier than it reaches prospects.
Crypto wallets create a very troublesome take a look at for that mannequin as a result of an software doesn’t essentially require subtle malware to trigger irreversible loss.
Convincing imitation is sufficient.
A seed phrase sometimes controls the belongings related to a self-custodial pockets. As soon as a person enters these phrases into malicious software program, the attacker can switch belongings to an handle managed by the attacker, bypassing the financial institution or fee processor who can reverse the transaction.
For crypto customers, the legitimacy conveyed by app marketplaces is due to this fact significantly necessary.
The Sparrow plaintiffs argue that Apple’s personal representations led them to consider that the software program distributed by means of the App Retailer was adequately vetted. They’re in search of reimbursement of stolen belongings, together with compensatory and punitive damages, restitution and authorized prices.
It additionally calls on Apple to enhance and publish procedures for detecting fraudulent functions and introduce warnings concerning the dangers related to crypto apps.
Whether or not Apple bears authorized legal responsibility for the losses is unresolved, and the corporate might problem each the plaintiffs’ reliance on the corporate’s safety representations and the plaintiffs’ determination to enter delicate restoration credentials into third-party software program.
Apple additionally factors to the dimensions of threats its assessment course of is already stopping.
The corporate introduced final yr that the App Retailer blocked greater than $9 billion in potential fraudulent transactions from 2020 to 2024, together with greater than $2 billion in transactions in 2024 alone.
Apple introduced that in 2024, it can reject almost 2 million app functions that do not meet safety, reliability, and person expertise requirements, whereas suspending greater than 146,000 developer accounts and rejecting a further 139,000 developer registration makes an attempt as a result of fraud issues.
These numbers reveal the dimensions of malicious exercise that Apple is making an attempt to maintain out of its ecosystem. It additionally highlights the risks of compromised monetary software program.
For cryptocurrency customers, abandoning a single restoration phrase could make their total pockets unrecoverable, so a rising listing of imposters is testing simply how a lot belief Apple’s App Retailer badge can encourage.

