Home
Blog
Apple faces court over fraudulent cryptocurrency wallet in App Store

Apple faces court over fraudulent cryptocurrency wallet in App Store

Paul Ducklin
08/05/2026
Share this article:

Whom to trust?

If you’re a fan of cryptocurrencies, including Bitcoin, how much value in BTC do you keep ready to transfer at a moment’s notice from your mobile phone?

Given that stolen cryptocoins are somewhere between very difficult and impossible to recover in the event of a hack, a crack, or even an honest mistake, many users choose to limit the amount available for a mobile phone app to transfer silently.

And many – indeed, most users, we hope – take great care when choosing apps to help them manage their cryptocurrency stash, given that fraudulent apps that closely resemble the look and feel of the real thing are easy to create these days.

One cryptocurrency wallet project that claims to address cryptocurrency security, and to provide what the project’s website describes as financial self sovereignty is Sparrow Wallet, an open-source toolkit that provides desktop software for managing cryptocoin holdings.

For maximum control over the app, you can download the Sparrow Wallet source code, review it, test it, build it, and install it for yourself, but that means fetching and inspecting nearly 100,000 lines of Java code and various related files, as well as more than 50 external modules.

Most users therefore probably rely on the pre-built binary distributions from GitHub, which are available for Windows, macOS, and various flavors of Linux.

There aren’t any official mobile phone builds, not least because the project explicitly describes itself as a “desktop Bitcoin Wallet focused on security and privacy.”

There’s certainly no iOS version available for Apple iPhone users, because self-built iPhone apps are off-limits to consumers.

Apple prevents regular users from installing apps from anywhere other than the company’s own App Store.

Although restricting iPhone users to the App Store benefits Apple commercially, it does gives the company a chance to vet and verify apps before they’re accepted.

Indeed, Apple keenly talks up the cybersecurity benefits of this “walled garden” approach:

Apple faces court over fraudulent cryptocurrency wallet in App Store - SolCyber

The apps you love.
From a place you can trust.

 For over a decade, the App Store has 
proved to be a safe and trusted place 
to discover and download apps.

Many a slip ‘twixt cup and lip

Sadly, for all that Apple explicitly states that the App Store [ensures] that the apps we offer are held to the highest standards for privacy, security, and content, fraudulent apps regularly get through Apple’s vetting processes.

Scammers and cybercriminals who figure out how sneak their rogue apps into the App Store automatically acquire a stamp of approval from Apple itself, and stand to make huge amounts of money.

These fraudulent apps frequently appropriate the brand names and even the logos of official products and services, thus giving themselves a look that is surprisingly believable, and ensuring that they’ll show up when users search for a legitimate company, brand, or app.

Well, three cryptocoin enthusiasts named James Ramirez, Christopher Ellis, and Jalen Delgado have filed documents with the US District Court in San Jose (a city in Silicon Valley) claiming that they found what looked like the Sparrow Wallet app on the App Store, installed it․․․

․․․and quickly saw cryptocurrency to the value of $875,000, $840,000, and $120,000 respectively vanish from their wallets.

As previously explained, there is no official iPhone or iPad version of the Sparrow Wallet app, which offers pre-compiled versions only for macOS, Windows, and Linux.

The plaintiffs in this case are therefore holding Apple responsible for their financial misfortune, seeking restitution and damages on eight counts, volubly spelled out, headlined in capital letters, and legalistically enumerated with medieval Latin numerals:

   I. VIOLATIONS OF CONSUMERS LEGAL 
          REMEDIES ACT OF CALIFORNIA
   II. VIOLATION OF THE LOUISIANA 
          UNFAIR TRADE PRACTICES AND 
          CONSUMER PROTECTION LAW
   III. VIOLATION OF MASSACHUSETTS 
          GENERAL LAWS 
   IV. FRAUDULENT MISREPRESENTATION
   V. FRAUDULENT CONCEALMENT
   VI. NEGLIGENT MISREPRESENTATION
   VII. STRICT PRODUCTS LIABILITY – 
          FAILURE TO WARN
   VIII. NEGLIGENT FAILURE TO WARN

Missed warnings

Fascinatingly, the creator and maintainer of Sparrow Wallet himself warned more than two years ago on social media about bogus apps on the App Store using his project’s name to lure victims, claiming that one of them remained online even after he and others had reported it:

Apple faces court over fraudulent cryptocurrency wallet in App Store - SolCyber

The developer even tried to create an official Sparrow Wallet app to serve as a warning about scam apps misusing his name and icons, but to no avail:

Apple faces court over fraudulent cryptocurrency wallet in App Store - SolCyber

Ironically, Craig Raw claims, Apple rejected it for having “placeholder content” (which, you can argue, was its very purpose – to hold a place for the name of his project), and merely “demonstrating a concept” (which, you can argue, was exactly what it was supposed to do – the concept being that no functional Sparrow Wallet app could ever legitimately exist).

In the court filing, James Ramirez claims that he reported the app he’d downloaded to Apple as soon as he “realized that his cryptocurrency had been transferred to a scammer and that the Sparrow App was not a legitimate Sparrow App as was presented in the App Store.”

According to the filing, Ramirez reported the app on the same day he downloaded and used it (2025-07-25), but “to date, no one from Apple has reached out to Plaintiff Ramirez regarding his initial July 25, 2025, or any subsequent, report regarding the Sparrow App.”

Christopher Ellis, it seems, downloaded and used the same app from the same alleged scammers on 2025-08-03.

As the court document thunders in indignation, this was “just over a week after Plaintiff had Ramirez had reported, and Apple was on notice, of the fraudulent Sparrow App and corresponding risk of tremendous risk Apple customers faced.”

This robust and dramatically lawyerly verbiage continues, with the filing summarizing the harm apparently caused to the the plaintiffs as follows:

Because of Apple’s prolific misrepresentations regarding the safety and vetting of the apps hosted in the Apple App Store, Plaintiffs Ramirez, Ellis, and Delgado have suffered significant losses and resulting injuries.

But for Apple’s negligent and fraudulent misrepresentations, failure to warn, and the deceptive design of the App Store, Plaintiffs would not have suffered significant loss and resulting injuries.

Fighting words!

What to do?

  • Always go to app creators’ official websites to find a link to their mobile apps. Craig Raw’s advice above holds for any branded app you want to install, not just cryptocoin or financial apps. Even though vendors are not allowed to provide a direct download for Apple App Store apps, and are strongly discouraged from doing so for Google Play Store software, you should expect to find links that identify the vendor’s official app for both online stores.
  • Avoid apps you install on a whim, hoping that you might think of something useful to do with them later. Even if they’re not malicious, they may be collecting and uploading data whether you use them or not.
  • Ignore App Store and Play Store reviews, which could have been written by anyone and often were. Take advice from human experts whom you know and trust instead.
  • Remove apps and their associated data if you haven’t used them for a while. They may continue collecting and uploading data that you no longer need or want to share.
  • Never let yourself be lured into signing up for iPhone apps under non-standard conditions. Some scammers try to trick you into installing unofficial apps in backhanded ways, notably via Apple’s TestFlight system that’s intended for well-informed developers and testers of unfinished apps, or via MDM (mobile device management), where you allow someone else to take full control of your phone as though you were one of their employees and the phone were owned by them.
  • Consider mobile protection software that goes beyond traditional device management tools, which control your phone’s configuration, but don’t hunt for spyware, malware and other implanted badness.

Apple faces court over fraudulent cryptocurrency wallet in App Store - SolCyber

Scammers who abuse the TestFlight system or Apple’s MDM enrollment typically do so by pitching the unusual level of risk as a “benefit,” telling you that you’re an “early adopter” with “special benefits,” such as early access to a newly-launched cryptocurrency or an investment program. They’ll often also advise you not to tell your friends and family about your “special access” by claiming that this would needlessly dilute your “early adoption” advantage, and thus that secrecy is to your advantage. But the real “advantage” is theirs – they don’t want friends and family trying to warn you that you’re plunging yourself into a scam.


Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!

Apple faces court over fraudulent cryptocurrency wallet in App Store - SolCyber


More About Duck

Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

Paul Ducklin
Paul Ducklin
08/05/2026
Share this article:

Table of contents:

The world doesn’t need another traditional MSSP 
or MDR or XDR.

What it requires is practicality and reason.

Related articles

Choose identity-first managed security.

We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
No more paying for useless bells and whistles.
No more time wasted on endless security alerts.
No more juggling multiple technologies and contracts.

Follow us!

Subscribe

Join our newsletter to stay up to date on features and releases.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.

©
2026
SolCyber. All rights reserved
|
Made with
by
Jason Pittock

I am interested in
SolCyber DPM++

I am interested in
SolCyber XDR++™

I am interested in
SolCyber MDR++™

I am interested in
SolCyber Extended Coverage™

I am interested in
SolCyber Foundational Coverage™

I am interested in a
Free Demo

14650