Fake Sparrow Wallet App Stole $1.8M via App Store

TechRepublic Security · Medium sophistication
Last updated August 4, 2026

A lawsuit alleges a counterfeit “Sparrow Wallet” app was allowed to remain in Apple’s App Store for months, leading investors to lose about $1.8M in Bitcoin. Victims reportedly entered their wallet “seed phrases” into the fake app, letting the scammer take over their funds. The case is a reminder for organisations that app-store approval and other “curated” marketplaces reduce risk but do not replace internal due diligence.

Key findings

  • Plaintiffs allege Apple hosted a fake cryptocurrency wallet app for months despite warnings.
  • The counterfeit app impersonated “Sparrow Wallet,” which “has never had an official iOS release.”
  • Victims allegedly lost funds after they “enter[ed] their wallet seed phrases into the fraudulent app.”
  • The developer of the real Sparrow Wallet warned about copycats “as early as January 2024.”
  • The article argues marketplace curation lowers risk but is not a substitute for independent verification and third-party risk management.

Who’s being targeted

  • Commonly targeted roles: Finance/Treasury, Executives, Procurement/Vendor Management, IT & Security leadership, Employees who install apps or approve software.
  • Affected industries: Financial services / cryptocurrency users, Technology platforms / app marketplaces, Any organisation relying on software marketplaces (plugins, extensions, package registries).
  • Attack channels: website.
  • Impersonated: Sparrow Wallet (legitimate Bitcoin wallet).

Awareness takeaways

  • Treat app-store or marketplace approval as a starting point, not proof an app is safe, especially for software that handles credentials or money.
  • Train staff never to enter high-value secrets (like wallet seed phrases or recovery codes) into an app unless the publisher and official release channels are verified.
  • Use independent verification for any software that can access financial assets or sensitive accounts, even if it appears in a ‘curated’ ecosystem.
  • Strengthen third-party risk management: schedule recurring reviews and require incident-history disclosure from suppliers, not one-time onboarding checks.

Red flags to watch for

  • The brand being impersonated “has never had an official iOS release”
  • The app requests a wallet “seed phrase” (high-risk secret) during setup
  • Public warnings existed about “copycat listings”
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

A fake Sparrow Wallet app sat in Apple’s App Store for months… and people lost about $1.8 million in Bitcoin. Here’s the trick: a counterfeit version of Sparrow Wallet, which has never had an official iOS release, asked users to enter their wallet seed phrase, then drained their coins. Aha moment: platform approval is not a security control. Apple had been warned about copycat Sparrow Wallet listings as early as January 2024, and the fake app still stayed up. Your move: if any app asks for a wallet seed phrase or recovery code, stop and independently verify the publisher and official release channel before anyone types a single word.

Similar attacks

Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026
Malicious Calendar Invites Surge With Malware Links

Malicious Calendar Invites Surge With Malware Links

Attackers are sending fake calendar meeting invites that can be automatically added to a victim’s calendar, even if the email is blocked. A documented example used a Google Calendar invite with a financial “invoice credit” lure to drive victims to a hosted webpage and download a malicious…

September 18, 2026
HBO Max Reddit Account Hijacked for ClickFix Malware Ads

HBO Max Reddit Account Hijacked for ClickFix Malware Ads

Attackers took over the verified official HBO Max Reddit account and used it to run a 48-hour wave of malicious ads. The ads sent people to lookalike download sites that tricked them into copying and running commands, leading to information-stealing malware on both macOS and Windows. Researchers…

September 15, 2026