Fake Sparrow Wallet App Stole $1.8M via App Store

TechRepublic Security · Medium sophistication
Last updated August 4, 2026

A lawsuit alleges a counterfeit “Sparrow Wallet” app was allowed to remain in Apple’s App Store for months, leading investors to lose about $1.8M in Bitcoin. Victims reportedly entered their wallet “seed phrases” into the fake app, letting the scammer take over their funds. The case is a reminder for organisations that app-store approval and other “curated” marketplaces reduce risk but do not replace internal due diligence.

Key findings

  • Plaintiffs allege Apple hosted a fake cryptocurrency wallet app for months despite warnings.
  • The counterfeit app impersonated “Sparrow Wallet,” which “has never had an official iOS release.”
  • Victims allegedly lost funds after they “enter[ed] their wallet seed phrases into the fraudulent app.”
  • The developer of the real Sparrow Wallet warned about copycats “as early as January 2024.”
  • The article argues marketplace curation lowers risk but is not a substitute for independent verification and third-party risk management.

Who’s being targeted

  • Commonly targeted roles: Finance/Treasury, Executives, Procurement/Vendor Management, IT & Security leadership, Employees who install apps or approve software.
  • Affected industries: Financial services / cryptocurrency users, Technology platforms / app marketplaces, Any organisation relying on software marketplaces (plugins, extensions, package registries).
  • Attack channels: website.
  • Impersonated: Sparrow Wallet (legitimate Bitcoin wallet).

Awareness takeaways

  • Treat app-store or marketplace approval as a starting point, not proof an app is safe, especially for software that handles credentials or money.
  • Train staff never to enter high-value secrets (like wallet seed phrases or recovery codes) into an app unless the publisher and official release channels are verified.
  • Use independent verification for any software that can access financial assets or sensitive accounts, even if it appears in a ‘curated’ ecosystem.
  • Strengthen third-party risk management: schedule recurring reviews and require incident-history disclosure from suppliers, not one-time onboarding checks.

Red flags to watch for

  • The brand being impersonated “has never had an official iOS release”
  • The app requests a wallet “seed phrase” (high-risk secret) during setup
  • Public warnings existed about “copycat listings”
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

A fake Sparrow Wallet app sat in Apple’s App Store for months… and people lost about $1.8 million in Bitcoin. Here’s the trick: a counterfeit version of Sparrow Wallet, which has never had an official iOS release, asked users to enter their wallet seed phrase, then drained their coins. Aha moment: platform approval is not a security control. Apple had been warned about copycat Sparrow Wallet listings as early as January 2024, and the fake app still stayed up. Your move: if any app asks for a wallet seed phrase or recovery code, stop and independently verify the publisher and official release channel before anyone types a single word.

Similar attacks

Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake $149.99 Apple/Amazon Charge Popup Scam

Fake $149.99 Apple/Amazon Charge Popup Scam

A scam campaign uses full-screen browser popups impersonating Apple Support or Amazon to claim an “unauthorized” $149.99 charge and pressure victims to call a phone number. Callers reach a live scammer posing as support who tries to gain remote access or steal payment/account details, sometimes…

August 6, 2026
ClickFix Uses Fingerprinting to Target Mac Users

ClickFix Uses Fingerprinting to Target Mac Users

Microsoft tracked a real macOS ClickFix campaign using 250+ domains that fingerprint visitors to hide malicious pages from security scanners. Selected Mac users are shown a fake “Download for macOS” lure and prompted to copy/paste an obfuscated command into Terminal, which then pulls down scripts…

August 5, 2026
Cloaked Mac ClickFix Sites Push Terminal Infostealers

Cloaked Mac ClickFix Sites Push Terminal Infostealers

Microsoft Threat Intelligence tracked a real macOS “ClickFix” campaign that uses look‑alike domains to trick Mac users into copying and running a Terminal command. The operation now hides the malicious “Download for macOS” lure behind server-side browser fingerprinting, showing benign decoy pages…

August 5, 2026
Fake iPhone Wallet App Stole $1.8M in Bitcoin

Fake iPhone Wallet App Stole $1.8M in Bitcoin

Three crypto investors sued Apple after allegedly losing about $1.8 million in Bitcoin to an iPhone app that impersonated the legitimate (desktop-only) Sparrow Wallet. The victims trusted the app because it was available in the App Store, then entered their wallet “seed phrase” into the counterfeit…

July 30, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026