Fake App Store Wallet Drained $1.8M; Apple Faces Lawsuit
Three plaintiffs are suing Apple after a fake Sparrow Wallet impersonator on the App Store harvested their seed phrases and drained $1.8 million in Bitcoin.
A fraudulent Sparrow Wallet impersonator sat in Apple’s App Store long enough to drain approximately $1.8 million in Bitcoin from three users. On July 24, those users filed suit in California, alleging Apple’s review process not only failed to catch the fake — it promoted it.
How it worked
The attack vector is not subtle. Sparrow Wallet is a legitimate, open-source desktop Bitcoin wallet. There is no official mobile version. The fake app listed in the App Store asked users to enter their seed phrase — the 12- or 24-word mnemonic that controls a cryptocurrency wallet. Users complied, the attackers transferred the funds, and the wallets were empty.
The losses:
- Jalen Delgado, May 1, 2025: approximately $120,000 (1.05 BTC)
- James Ramirez, July 25, 2025: approximately $875,000 (7.4 BTC)
- Christopher Ellis, August 3, 2025: approximately $840,000
Apple knew
Sparrow Wallet’s developer Craig Raw publicly warned on January 6, 2024, that a fake version of his app remained on the App Store despite prior reports. Apple left it up. According to the complaint filed July 24, Apple also promoted the fraudulent app inside curated cryptocurrency collections — an Apple-curated endorsement for a scam.
Each plaintiff reported the theft to Apple after losing funds. Nothing changed.
What to do
This is not a sophisticated supply-chain attack. It’s fraud dressed up in a legitimate developer category, and the defense is simple:
- Never enter a seed phrase into a mobile app. Any app that requests your seed phrase is either a cold-storage recovery tool running entirely offline or a theft mechanism. Sparrow Wallet is desktop-only; an iOS or Android app claiming to be Sparrow is not Sparrow.
- Check the developer name before downloading. App Store listings display the developer entity. Sparrow Wallet’s developer is Craig Raw. A different publisher name means a different app.
- Move significant holdings to hardware. Software wallets on internet-connected devices are the wrong place to hold meaningful amounts of cryptocurrency. A hardware wallet keeps the seed phrase off the network entirely.
- Report fakes when you see them. App Store’s “Report a Problem” workflow is the primary mechanism for flagging fraudulent apps. It failed here — but volume of reports does eventually surface fake listings for review.
Apple’s approval model creates a false assurance. The App Store review process catches some malware but not all fraud, and it creates an environment where users reasonably assume that listed apps are safe. They’re not, not reliably. This case is a useful corrective on that assumption.
The lawsuit asks the court to order Apple to improve its fraud detection procedures and disclose those improvements publicly. Whether that happens or not, the $1.8 million is gone. Seed phrases are unrecoverable by design.
For security teams managing mobile device policies: consider whether your MDM blocks sideloading of financial apps, and consider whether user training addresses seed phrase hygiene specifically — not just generic “don’t click links” messaging.
Source: BleepingComputer, July 27, 2026
Related coverage: Apple fixes Hide My Email leak, year after disclosure
Found this useful? Share it.

