
Fake iPhone Wallet App Stole $1.8M in Bitcoin
Three crypto investors sued Apple after allegedly losing about $1.8 million in Bitcoin to an iPhone app that impersonated the legitimate (desktop-only) Sparrow…
Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users into entering their wallet recovery phrase, then criminals used it to drain about $1.8 million in Bitcoin. The case highlights how app-store listings and lookalike apps can be used as a convincing social-engineering lure.
Victims believed they were installing a legitimate crypto wallet app called Sparrow Wallet from a mobile app store. The app requested a recovery phrase, the 12 or 24 word string that restores access to a crypto wallet, framed as a normal setup or restore step. Once entered, that phrase was passed directly to the operators behind the scheme rather than kept private on the device. With the recovery phrase in hand, the attackers could access and drain the associated wallets. Three victims reported combined losses of about $1.8 million between May and August 2025.
The scheme worked because it exploited trust in app marketplace listings rather than a technical vulnerability. The real Sparrow Wallet is a desktop-only application for Windows, macOS, and Linux and has never had an official iPhone app, so any iOS listing using that name was inherently a lookalike. Because the fake app appeared in a mainstream app marketplace, users had little reason to question its legitimacy before entering sensitive recovery data. Some variations of this pattern also redirect users to a convincing fake App Store webpage and prompt installation through enterprise distribution certificates intended for internal company apps, adding another layer that can make a fraudulent app feel authorized.
Defenders and individual users who hold crypto assets should treat recovery phrases as the keys to the vault: once someone else has the phrase, they have full access to the wallet, and no legitimate support process should require typing it into an app to "restore" access. Organizations should encourage employees and executives with personal crypto holdings to download wallet software only through links from the developer's official website, rather than relying on an app store listing as proof of authenticity. IT and helpdesk teams supporting mobile devices should also be aware that fake cryptocurrency apps are a recognized trend, sometimes distributed through fake store webpages or misused enterprise certificates, and should factor this into guidance given to staff who manage digital assets on company or personal devices.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The app impersonated the real Sparrow Wallet and prompted users to enter their 12 or 24 word recovery phrase, which the app then handed to the criminals running the scam, giving them access to victims' wallets.
No. The real Sparrow Wallet is a desktop application for Windows, macOS, and Linux and has never had an official iPhone app, which is a key sign the App Store listing was a lookalike.
Researchers note some scams direct users to a convincing fake App Store webpage and prompt them to install another version of the app that abuses enterprise distribution certificates meant for internal company apps.
Verify apps through the developer's official website rather than trusting an App Store listing alone, and never enter a recovery phrase into an app unless you are certain it is legitimate.
An iPhone “Sparrow Wallet” app looked legit, and helped steal about $1.8 million in Bitcoin. Victims downloaded a fake “Sparrow Wallet” for iPhone. During setup it said, “Restore your Sparrow Wallet: enter your 12 or 24-word recovery phrase.” The app just handed those words straight to criminals, who drained the wallets. Here’s the catch: the real Sparrow Wallet is desktop-only, Windows, macOS, Linux. It has never had an official iPhone app. Other scams even send you to a fake App Store webpage or an enterprise install page, then ask for your seed phrase or private key. Treat your recovery phrase like the keys to the vault: if an app asks for it, pause and go to the wallet’s official website to confirm that app is real before you type a single word.

Three crypto investors sued Apple after allegedly losing about $1.8 million in Bitcoin to an iPhone app that impersonated the legitimate (desktop-only) Sparrow…

A real malware campaign called OkoBot is infecting Windows PCs and then showing a fake “recovery phrase” prompt inside legitimate Ledger and Trezor desktop…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

Apple warns that scammers are placing unsolicited FaceTime calls and sending urgent-looking messages that appear to come from “Apple Support” or a bank. The…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked…