A “Safe and Trusted” Store That Wasn’t
The Apple App Store security lawsuit over a fake crypto wallet app centers on claims that Apple’s supposedly safe and trusted marketplace allowed a malicious Sparrow Wallet impersonator to reach users, steal their seed phrases, and drain their Bitcoin, exposing serious weaknesses in how high-risk financial apps are reviewed and approved.
Three crypto users lost a combined USD 1.8 million (approx. RM8.3 million) in Bitcoin through a counterfeit Sparrow Wallet listed in the App Store’s cryptocurrency section. The app appeared between May and August 2025, posing as a mobile version of Sparrow Wallet even though the genuine wallet only exists on desktop platforms. Once installed, it prompted users to enter their recovery seed phrases, giving attackers everything they needed to empty the victims’ wallets. This was not some shady sideloaded software—it was a featured app inside Apple’s walled garden. That is the central problem: when a platform sells trust as a product, a single cryptocurrency scam app is not a glitch, it is a broken promise.

How a Fake Sparrow Wallet Passed Apple’s Review
The most troubling part of this case is not that criminals created a fake crypto wallet app; it is that the Apple app review process blessed it with legitimacy. The counterfeit app was not buried in search results but surfaced in curated cryptocurrency collections, which for many users reads as an Apple-backed stamp of approval. Meanwhile, Apple “neglected to block alternative storefronts” pretending to be Sparrow Wallet despite the project having a single, well-known developer.
That developer, Craig Raw, says he spent years flagging copycats to Apple with little success. When he tried to upload a simple information-only iOS app warning that there is no official Sparrow Wallet for mobile, Apple temporarily threatened his developer account for “dishonest activity.” In effect, the platform punished the real developer while approving the impersonators. If this is how a supposedly tightly controlled store handles a single well-known wallet, it is hard to argue that the current system is fit for purpose in high-risk financial categories.

The Human Cost: When “Trusted” Channels Go Wrong
Behind the legal arguments are users who believed doing the cautious thing—downloading from the official App Store—would protect them. The three plaintiffs say they lost USD 875,000 (approx. RM4.0 million), USD 840,000 (approx. RM3.9 million), and USD 120,000 (approx. RM550,000) in Bitcoin after following in-app prompts to enter their seed phrases, only to see their savings vanish. “Victims, thinking they were using the official app, entered their details into the system and immediately lost their savings.”
That experience cuts against Apple’s branding of the App Store as a “safe and trusted” environment. Users did what years of security advice told them: avoid random downloads, stick to official channels. Yet it was the official channel that delivered the cryptocurrency scam app straight to them. When the store’s trust halo encourages people to lower their guard, the bar for vetting high-risk financial and crypto applications must be far higher than it is today.
Apple’s Defense: Impressive Numbers, Incomplete Answer
Apple’s response leans on scale and statistics. The company says it removed the fake Sparrow Wallet app, permanently terminated the associated developer accounts, and points to forms that developers and users can use to report fraud or copyright issues. It also highlights that in 2025 it blocked over USD 2.2 billion (approx. RM10.1 billion) in fraudulent app transactions and shut down 193,000 malicious developer accounts. As a quotable defense, those numbers sound impressive: “In 2025 alone, Apple shut down 193,000 malicious developer accounts and prevented more than USD 2.2 billion in potentially fraudulent transactions.”
But those aggregate figures miss the point of this App Store security lawsuit. The issue is not whether Apple catches many bad actors; it is that it missed one extraordinarily harmful cryptocurrency scam app while marketing the store as safe. For financial and crypto apps, “mostly secure” is not enough. Users are not evaluating every app like a security researcher—they are outsourcing that judgment to Apple. When the gatekeeper trades on that trust, it inherits a higher duty of care, especially when the potential loss runs into hundreds of thousands of dollars per user.
What This Case Demands from the Future of App Store Security
The plaintiffs accuse Apple of false advertising and consumer law violations and are seeking reimbursement of their Bitcoin losses plus punitive damages, as well as a court order forcing clearer warnings about fake apps in the store. Whether the court accepts Apple’s statistics-heavy defense, and whether the victims recover any of their lost Bitcoin, will be decided in the legal battle ahead. Regardless of the verdict, the message for platform operators should be clear: curated app stores must stop treating high-risk financial categories like any other software shelf.
At minimum, crypto and other high-stakes financial apps should face tighter identity checks, explicit verification badges for official publishers, and blunt warnings whenever there is no official mobile app. Apple prides itself on controlling the full stack; that control comes with responsibility. When a fake crypto wallet app can impersonate a well-known project for months and cost users USD 1.8 million (approx. RM8.3 million), the “safe and trusted” label is not marketing—it is a liability.






