A lawsuit alleges a counterfeit “Sparrow Wallet” app was allowed to remain in Apple’s App Store for months, leading investors to lose about $1.8M in Bitcoin. Victims reportedly entered their wallet “seed phrases” into the fake app, letting the scammer take over their funds. The case is a reminder for organisations that app-store approval and other “curated” marketplaces reduce risk but do not replace internal due diligence.
Key findings
- Plaintiffs allege Apple hosted a fake cryptocurrency wallet app for months despite warnings.
- The counterfeit app impersonated “Sparrow Wallet,” which “has never had an official iOS release.”
- Victims allegedly lost funds after they “enter[ed] their wallet seed phrases into the fraudulent app.”
- The developer of the real Sparrow Wallet warned about copycats “as early as January 2024.”
- The article argues marketplace curation lowers risk but is not a substitute for independent verification and third-party risk management.
Who’s being targeted
- Commonly targeted roles: Finance/Treasury, Executives, Procurement/Vendor Management, IT & Security leadership, Employees who install apps or approve software.
- Affected industries: Financial services / cryptocurrency users, Technology platforms / app marketplaces, Any organisation relying on software marketplaces (plugins, extensions, package registries).
- Attack channels: website.
- Impersonated: Sparrow Wallet (legitimate Bitcoin wallet).
Awareness takeaways
- Treat app-store or marketplace approval as a starting point, not proof an app is safe, especially for software that handles credentials or money.
- Train staff never to enter high-value secrets (like wallet seed phrases or recovery codes) into an app unless the publisher and official release channels are verified.
- Use independent verification for any software that can access financial assets or sensitive accounts, even if it appears in a ‘curated’ ecosystem.
- Strengthen third-party risk management: schedule recurring reviews and require incident-history disclosure from suppliers, not one-time onboarding checks.
Red flags to watch for
- The brand being impersonated “has never had an official iOS release”
- The app requests a wallet “seed phrase” (high-risk secret) during setup
- Public warnings existed about “copycat listings”
Read the video transcript
A fake Sparrow Wallet app sat in Apple’s App Store for months… and people lost about $1.8 million in Bitcoin. Here’s the trick: a counterfeit version of Sparrow Wallet, which has never had an official iOS release, asked users to enter their wallet seed phrase, then drained their coins. Aha moment: platform approval is not a security control. Apple had been warned about copycat Sparrow Wallet listings as early as January 2024, and the fake app still stayed up. Your move: if any app asks for a wallet seed phrase or recovery code, stop and independently verify the publisher and official release channel before anyone types a single word.