
Fake iPhone Crypto Wallet Stole $1.8M
Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…
Three crypto investors sued Apple after allegedly losing about $1.8 million in Bitcoin to an iPhone app that impersonated the legitimate (desktop-only) Sparrow Wallet. The victims trusted the app because it was available in the App Store, then entered their wallet “seed phrase” into the counterfeit app, allowing the thieves to steal funds. The case highlights that app-store listing/approval can be abused by scammers and that seed phrases should never be entered into unverified apps.
A counterfeit iPhone app impersonated Sparrow Wallet, a legitimate, open-source Bitcoin wallet that actually only operates on desktop systems. Because the real product has no official mobile version, the existence of a mobile app using the same name and branding created a false sense of legitimacy for anyone searching an app store for a way to manage their Bitcoin on the go.
Once installed, the fake app prompted users to import their wallet by entering their secret seed phrase, the recovery credential that provides full access to a cryptocurrency wallet. Victims who entered this information into the counterfeit interface effectively handed control of their funds directly to the attackers. Reported losses across affected investors totaled approximately $1.8 million.
This attack succeeded largely because of trust transference: users assumed that an app available in a reputable app store had been vetted and was safe to use. That assumption, combined with the well-known Sparrow Wallet brand name, made the fake listing appear credible without requiring any direct outreach or phishing message.
The case also shows how reporting alone does not guarantee rapid removal. One victim reported the app to Apple, but it allegedly remained listed long enough for additional victims to download it and lose funds, allowing the impersonation to continue affecting new targets over time.
Organizations and individuals handling cryptocurrency or digital assets should treat any request for a seed phrase as an extreme risk, regardless of where the request originates. Before downloading any financial or wallet-related app, independently verify on the vendor's own website whether an official mobile version actually exists.
Finance teams, executives, and anyone involved in procurement or vendor/app approval should build habits of cross-checking app authenticity beyond store listings alone, since app-store approval is not proof of safety. Recognizing brand impersonation patterns, especially when a legitimate product lacks a mobile offering, is a practical first line of defense against this type of social engineering.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The app impersonated Sparrow Wallet, a legitimate desktop-only Bitcoin wallet, and prompted victims to enter their secret seed phrase to import funds, which gave attackers access to their wallets.
App-store approval does not guarantee an app is legitimate; storefront listing is not a guarantee of safety, so users need to independently verify an official app exists on the vendor's own website.
Never enter a wallet recovery phrase or seed phrase into an unverified app, and be suspicious of mobile apps claiming to offer a product that is only available on desktop.
According to the findings, one victim reported the fraud to Apple but the app allegedly remained listed long enough for additional victims to install it and lose funds.
Three crypto investors lost about $1.8 million to a fake iPhone app that looked like Sparrow Wallet. The trick? Sparrow Wallet is desktop‑only, but this copycat iPhone app asked people to 'import your wallet' by typing their secret seed phrase, then the Bitcoin was gone. Here’s the aha: being in the App Store did NOT mean it was safe. One victim even reported the fraud, and the fake app still stayed up while more people lost money. Your move: if any app asks for a wallet recovery or seed phrase, stop and verify the official app from the vendor’s website before you type a single word.

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a…