Sparrow Wallet and Apple: Apple accused of letting fake crypto app steal $1.8 million

Sparrow Wallet and Apple: Apple accused of letting fake crypto app steal $1.8 million

Apple Faces Lawsuit Over Fake Crypto Wallet App in App Store

A federal lawsuit filed in California’s Northern District last week accuses Apple of enabling a cryptocurrency scam through its App Store. Three victims James Ramirez, Christopher Ellis, and Jalen Delgado lost a combined $1.8 million after downloading a fraudulent version of Sparrow Wallet, a desktop-only crypto app that has never had an official iOS version.

The fake app, which appeared in Apple’s curated crypto collections, tricked users into entering their recovery phrases critical credentials that grant full access to crypto wallets. Instead of securing the data, the app transmitted it to scammers, who drained the victims’ Bitcoin holdings between May and August 2025. Losses ranged from $120,000 to $875,000 per user.

The real Sparrow Wallet developer, Craig Raw, had repeatedly warned Apple about the impersonation since early 2024, even submitting a placeholder app with warnings to deter users. Apple initially terminated Raw’s developer account in response before reversing the decision. The lawsuit alleges Apple failed to act swiftly, allowing multiple fake versions to persist despite complaints.

Apple’s official statement acknowledges that impersonation violates its guidelines and claims it removes such apps "swiftly." However, the plaintiffs argue the company misrepresented the App Store’s trustworthiness, citing fraudulent concealment and seeking damages under California law.

The incident reflects a broader trend: Kaspersky researchers recently identified 26 crypto wallet impersonators in Apple’s ecosystem, many exploiting enterprise distribution certificates to bypass security checks. While Apple reports terminating 193,000 developer accounts and rejecting 371,000 copycat submissions in 2025, the case underscores that even vetted app stores remain vulnerable to sophisticated scams.

Source: https://www.malwarebytes.com/blog/news/2026/07/apple-accused-of-letting-fake-crypto-app-steal-1-8-million

Sparrow Wallet TPRM report: https://www.rankiteo.com/company/sparrowfi

Apple TPRM report: https://www.rankiteo.com/company/apple

"id": "spaapp1785371243",
"linkid": "sparrowfi, apple",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '3 named victims (likely more)',
                        'industry': 'Technology / App Distribution',
                        'location': 'Cupertino, California, USA',
                        'name': 'Apple Inc.',
                        'size': 'Large (Fortune 500)',
                        'type': 'Technology Company'},
                       {'customers_affected': '3 victims',
                        'location': 'USA',
                        'name': 'James Ramirez, Christopher Ellis, Jalen '
                                'Delgado',
                        'type': 'Individuals'}],
 'attack_vector': 'Fraudulent mobile application (iOS App Store)',
 'customer_advisories': 'Users warned to verify app legitimacy before entering '
                        'sensitive credentials like recovery phrases.',
 'data_breach': {'data_exfiltration': 'Yes (transmitted to scammers)',
                 'number_of_records_exposed': 'Unknown (at least 3 victims)',
                 'personally_identifiable_information': 'Cryptocurrency wallet '
                                                        'credentials',
                 'sensitivity_of_data': 'High (grants full access to crypto '
                                        'wallets)',
                 'type_of_data_compromised': 'Cryptocurrency wallet recovery '
                                             'phrases'},
 'date_detected': '2024 (initial warnings)',
 'date_publicly_disclosed': '2025 (lawsuit filed)',
 'description': 'A federal lawsuit filed in California’s Northern District '
                'accuses Apple of enabling a cryptocurrency scam through its '
                'App Store. Three victims lost a combined $1.8 million after '
                'downloading a fraudulent version of Sparrow Wallet, a '
                'desktop-only crypto app that has never had an official iOS '
                'version. The fake app tricked users into entering their '
                'recovery phrases, which were transmitted to scammers, '
                'draining the victims’ Bitcoin holdings.',
 'impact': {'brand_reputation_impact': "Damage to Apple's App Store "
                                       'trustworthiness',
            'data_compromised': 'Cryptocurrency wallet recovery phrases',
            'financial_loss': '$1.8 million (combined losses)',
            'identity_theft_risk': 'High (recovery phrases grant full access '
                                   'to crypto wallets)',
            'legal_liabilities': 'Federal lawsuit filed under California law',
            'operational_impact': 'Loss of cryptocurrency assets for victims',
            'payment_information_risk': 'High (cryptocurrency theft)',
            'systems_affected': "Victims' cryptocurrency wallets"},
 'initial_access_broker': {'entry_point': 'Fraudulent iOS app in Apple App '
                                          'Store',
                           'high_value_targets': 'Cryptocurrency users'},
 'investigation_status': 'Ongoing (lawsuit pending)',
 'lessons_learned': 'Even vetted app stores remain vulnerable to sophisticated '
                    'scams, particularly those exploiting enterprise '
                    'distribution certificates. Proactive monitoring and '
                    'faster response to developer warnings are critical.',
 'motivation': 'Financial gain (cryptocurrency theft)',
 'post_incident_analysis': {'corrective_actions': 'Apple terminated fraudulent '
                                                  'apps and developer '
                                                  'accounts, but lawsuit '
                                                  'alleges insufficient '
                                                  'proactive measures.',
                            'root_causes': 'Lack of stringent vetting for apps '
                                           'in curated collections, '
                                           'exploitation of enterprise '
                                           'distribution certificates, delayed '
                                           'response to developer warnings.'},
 'recommendations': 'Enhance App Store vetting processes, improve detection of '
                    'impersonation apps, and implement stricter controls for '
                    'enterprise distribution certificates. Increase '
                    'transparency with users about app legitimacy.',
 'references': [{'source': 'Federal lawsuit (California’s Northern District)'},
                {'source': 'Kaspersky research on crypto wallet impersonators'},
                {'source': 'Apple’s official statement'}],
 'regulatory_compliance': {'legal_actions': 'Federal lawsuit filed in '
                                            'California’s Northern District'},
 'response': {'communication_strategy': 'Official statement acknowledging '
                                        'impersonation violations',
              'containment_measures': 'Apple claims to remove fraudulent apps '
                                      "'swiftly'",
              'remediation_measures': 'Termination of fraudulent apps and '
                                      'developer accounts'},
 'stakeholder_advisories': 'Apple acknowledges impersonation violations and '
                           'claims to remove fraudulent apps swiftly.',
 'threat_actor': 'Unknown (likely cybercriminals exploiting App Store '
                 'vulnerabilities)',
 'title': 'Apple Faces Lawsuit Over Fake Crypto Wallet App in App Store',
 'type': 'Scam / Fraudulent App',
 'vulnerability_exploited': 'Impersonation of legitimate app, lack of App '
                            'Store vetting for enterprise distribution '
                            'certificates'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.