A “Safe” App Store That Wasn’t
The fake Sparrow Wallet incident is a case in which a counterfeit crypto wallet app passed App Store security checks, posed as a trusted tool, and then drained user funds, revealing how a closed, curated marketplace can still host high‑impact financial scams and leave victims with little practical recourse.
Three crypto investors say they lost a combined USD 1.8 million (approx. RM8.3 million) in Bitcoin after downloading a fake crypto wallet app that impersonated Sparrow Wallet on the App Store. The attackers’ method was crude but effective: once users installed the counterfeit Sparrow Wallet and entered their seed phrases, their coins were drained. The victims argue they trusted the app because Apple promotes its store as a “safe and trusted” marketplace, yet this fake crypto wallet app not only passed the Apple app review process but was featured in curated crypto collections, giving it an aura of legitimacy.
If users cannot rely on the platform’s basic promise that obvious imposters will be filtered out, then the App Store security scam here is not a one‑off mistake—it is a systemic warning.

How a Counterfeit Sparrow Wallet Beat the Apple App Review Process
The most alarming part of this story is not the scam itself; it is how long it was allowed to operate in plain sight. The counterfeit Sparrow Wallet ran on the App Store between May and August 2025, even though the real Sparrow Wallet is a desktop‑only Bitcoin tool and has no official iOS app. That should have been an instant red flag for any meaningful Apple app review process.
One plaintiff, Jalen Delgado, reportedly lost about USD 120,000 (approx. RM552,000) in May 2025 after entering his seed phrase into the counterfeit app. Another, James Ramirez, lost roughly USD 875,000 (approx. RM4 million) in July and reported the fraud to Apple that same day. Yet the fake app stayed live, and on 3 August, Christopher Ellis downloaded it and lost about USD 840,000 (approx. RM3.9 million). That means the app remained available for at least nine days after a major complaint, long enough for another victim to be hit.
This is not an obscure edge case. Hosting such a high‑profile financial scam undermines Apple’s core argument that strict control of iOS is necessary to keep users safe and highlights a real gap in manual review and monitoring processes.
Warnings Ignored and a Pattern of Slow Response
The lawsuit paints a picture of Apple not only missing a counterfeit Sparrow Wallet during review, but also mishandling warnings that could have limited the damage. Craig Raw, the real Sparrow Wallet creator, says he spent years flagging copycats on the Store without success. In January 2024, he publicly complained that a scam “Sparrow Wallet” app remained live weeks after being reported.
When Raw tried to publish a text‑only app to warn iOS users that Sparrow Wallet is desktop‑only, Apple initially flagged his developer account for “dishonest activity” before reversing course. That is not a protective reflex; it is a perverse incentive where the scammer gets distribution and the real developer gets punished. Meanwhile, a similar fake wallet incident—this time mimicking Ledger Live—had already drained USD 9.5 million (approx. RM43.7 million) from Mac users months earlier.
Apple responds by pointing to big numbers: it claims to have blocked over USD 2.2 billion (approx. RM10.1 billion) in fraudulent transactions, shut down 193,000 malicious developer accounts, and rejected more than 371,000 misleading or copycat submissions in 2025. Those achievements are real, but they do not excuse failures that slip through the net—especially when prior warnings were ignored.
Liability in a Closed Ecosystem
The plaintiffs now accuse Apple of false advertising and consumer law violations, seeking reimbursement of their Bitcoin losses and punitive damages. They also want a court order forcing Apple to display explicit warnings about fake apps in the store. This is more than a compensation fight; it is a direct challenge to the idea that platform approval equals safety.
Because Apple keeps its platform closed and blocks alternative storefronts, users have little recourse when a scam app bypasses platform security. The lawsuit argues that if a company insists on total control in the name of safety, that control comes with a strict responsibility to catch obvious impersonators. If courts agree, Apple may be forced to slow down app publishing with heavier manual checks, require stronger identity verification for financial app developers, or even limit open‑source crypto tools altogether—changes that could drag on innovation in the entire marketplace.
In other words, Apple’s strongest defense against antitrust pressure—“we keep users safe”—is now on trial against the reality of this App Store security scam.
How Users Can Protect Themselves from the Next Fake Crypto Wallet App
The harsh truth is that storefront approval is not a guarantee of safety, especially for crypto wallets. Investors cannot outsource all due diligence to a platform that has already hosted a counterfeit Sparrow Wallet and a fake Ledger Live. If you treat the App Store badge as a seal of security, you are playing a game whose odds you do not control.
- Verify the app from the source: before downloading any wallet, confirm on the developer’s official website that a mobile version exists and is linked directly to the store listing.
- Treat seed phrases as offline only: never type your recovery phrase into a new or unverified mobile app—assume any unexpected request for a seed is a theft attempt.
- Check for obvious red flags: poor branding, missing links to a real project, or a mobile app for a tool advertised as desktop‑only should be enough to walk away.
Until platforms prove they can reliably keep out fakes, self‑custody of crypto must also mean self‑custody of security decisions. The Sparrow case is not an argument to abandon app stores, but a reminder to stop confusing convenience with protection.





