← Blog · · df00tech

Apple Sued Over Fake Sparrow Wallet App on App Store Linked to $1.8M Bitcoin Theft

security-news breach

What happened

According to BleepingComputer, Apple is facing a lawsuit from three plaintiffs who allege that a fraudulent app impersonating the Sparrow Wallet cryptocurrency wallet was distributed through the official App Store. The plaintiffs claim that downloading and using the fake app resulted in the theft of approximately $1.8 million in Bitcoin. Details of the suit, including specific allegations against Apple's app review process, are still emerging.

Why it matters for defenders

This case highlights the ongoing risk of trojanized or impersonation apps reaching official mobile app stores, including Apple's App Store, which is generally regarded as a more tightly curated distribution channel than third-party sources. For organizations and individuals holding cryptocurrency, it underscores that app store presence and official-looking branding are not reliable indicators of legitimacy. It also raises questions about platform liability and the effectiveness of app review processes for financial and wallet applications specifically.

What defenders should watch for or do now

  • Advise users and employees to verify wallet and financial apps directly against the official project's website or GitHub before installing, rather than trusting App Store search results alone.
  • Encourage use of hardware wallets or multi-signature setups for significant cryptocurrency holdings, reducing reliance on any single mobile application.
  • Monitor for phishing or social engineering campaigns that may direct victims toward fake wallet apps via search ads, social media, or spoofed links.
  • Security teams supporting users with crypto exposure should consider awareness messaging about verifying app publisher identity and checking for unusual permission requests in wallet apps.
  • Watch for follow-up reporting that may clarify how the fake app evaded App Store review, as this could inform broader guidance on mobile app vetting.

Developing story

This is a developing legal matter and details of the underlying technical compromise are limited at this time. For the original report, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.