Fake iPhone Crypto Wallet Stole $1.8M

Malwarebytes · Medium sophistication
Last updated July 30, 2026

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users into entering their wallet recovery phrase, then criminals used it to drain about $1.8 million in Bitcoin. The case highlights how app-store listings and lookalike apps can be used as a convincing social-engineering lure.

How the attack worked

Victims believed they were installing a legitimate crypto wallet app called Sparrow Wallet from a mobile app store. The app requested a recovery phrase, the 12 or 24 word string that restores access to a crypto wallet, framed as a normal setup or restore step. Once entered, that phrase was passed directly to the operators behind the scheme rather than kept private on the device. With the recovery phrase in hand, the attackers could access and drain the associated wallets. Three victims reported combined losses of about $1.8 million between May and August 2025.

Why it succeeded

The scheme worked because it exploited trust in app marketplace listings rather than a technical vulnerability. The real Sparrow Wallet is a desktop-only application for Windows, macOS, and Linux and has never had an official iPhone app, so any iOS listing using that name was inherently a lookalike. Because the fake app appeared in a mainstream app marketplace, users had little reason to question its legitimacy before entering sensitive recovery data. Some variations of this pattern also redirect users to a convincing fake App Store webpage and prompt installation through enterprise distribution certificates intended for internal company apps, adding another layer that can make a fraudulent app feel authorized.

What to watch for

  • A crypto wallet app requesting a full recovery phrase or seed phrase during setup, especially unprompted
  • An app claiming to be a known desktop-only product suddenly available on mobile
  • Install prompts that redirect away from the official app store to a separate webpage
  • Requests to install an app version via enterprise distribution rather than the standard store process

How to build resistance

Defenders and individual users who hold crypto assets should treat recovery phrases as the keys to the vault: once someone else has the phrase, they have full access to the wallet, and no legitimate support process should require typing it into an app to "restore" access. Organizations should encourage employees and executives with personal crypto holdings to download wallet software only through links from the developer's official website, rather than relying on an app store listing as proof of authenticity. IT and helpdesk teams supporting mobile devices should also be aware that fake cryptocurrency apps are a recognized trend, sometimes distributed through fake store webpages or misused enterprise certificates, and should factor this into guidance given to staff who manage digital assets on company or personal devices.

Key findings

  • A fake “Sparrow Wallet” iOS app impersonated the real Sparrow Wallet, which is desktop-only.
  • The fake app prompted users to enter their wallet recovery phrase, then “handed it to the criminals,” enabling theft.
  • Three victims allege losses of about $875,000, $840,000, and $120,000 (combined $1.8M) between May and August 2025.
  • Researchers note a broader trend: iOS crypto-wallet impersonators that target “seed phrases and recovery keys,” sometimes via fake App Store webpages and enterprise certificates.

Who’s being targeted

  • Commonly targeted roles: Finance, Executives, All employees (mobile users), IT / Helpdesk (mobile device support).
  • Affected industries: Cryptocurrency / Digital assets, Consumer finance, Technology platforms / App marketplaces.
  • Attack channels: website.
  • Impersonated: Sparrow Wallet (legitimate desktop wallet), App Store listing page (convincing lookalike) and a crypto wallet brand.

Red flags to watch for

  • The legitimate product is not actually available on iOS
  • A wallet app asking for a full recovery phrase can be abused if the app is not genuine
  • The app is a lookalike/impersonator even though it appears in an app marketplace
  • Redirect to a ‘convincing fake App Store webpage’ instead of the real store
  • Prompt to install via enterprise distribution for a consumer app
  • Requests for recovery phrases/private keys during onboarding
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake Sparrow Wallet app steal cryptocurrency?

The app impersonated the real Sparrow Wallet and prompted users to enter their 12 or 24 word recovery phrase, which the app then handed to the criminals running the scam, giving them access to victims' wallets.

Is Sparrow Wallet available on iPhone?

No. The real Sparrow Wallet is a desktop application for Windows, macOS, and Linux and has never had an official iPhone app, which is a key sign the App Store listing was a lookalike.

What other tricks do fake crypto wallet apps use?

Researchers note some scams direct users to a convincing fake App Store webpage and prompt them to install another version of the app that abuses enterprise distribution certificates meant for internal company apps.

How can I avoid falling for a fake wallet app?

Verify apps through the developer's official website rather than trusting an App Store listing alone, and never enter a recovery phrase into an app unless you are certain it is legitimate.

Read the video transcript

An iPhone “Sparrow Wallet” app looked legit, and helped steal about $1.8 million in Bitcoin. Victims downloaded a fake “Sparrow Wallet” for iPhone. During setup it said, “Restore your Sparrow Wallet: enter your 12 or 24-word recovery phrase.” The app just handed those words straight to criminals, who drained the wallets. Here’s the catch: the real Sparrow Wallet is desktop-only, Windows, macOS, Linux. It has never had an official iPhone app. Other scams even send you to a fake App Store webpage or an enterprise install page, then ask for your seed phrase or private key. Treat your recovery phrase like the keys to the vault: if an app asks for it, pause and go to the wallet’s official website to confirm that app is real before you type a single word.

Similar attacks