Key highlights:
- Apple faces lawsuit over fake crypto wallet app that stole nearly $2 million from users.
- The lawsuit argues Apple’s marketing around App Store security gave users a false sense of safety.
- Despite strict guardrails, bad actors are sidestepping Apple’s security measures to steal cryptocurrencies.
Three Apple users have sued the iPhone maker, alleging its App Store security measures failed to stop a fraudulent crypto wallet that stole over $1.8 million worth of Bitcoin. In recent months, crypto scams have reached frenetic levels, with Q3 on course to be the worst quarter for security breach incidents.
Apple dragged to court over alleged fake Bitcoin wallet scam
The lawsuit, filed on Friday in the US District Court for the Northern District of California, claims the plaintiffs downloaded a fraudulent app posing as Sparrow Wallet, a popular Bitcoin wallet.
According to the complaint, James Ramirez lost $875,000 while Christopher Ellis lost around $840,000. Meanwhile, Jalen Delgado lost $120,000, with the trio transferring their BTC to the fake wallet.
The trio argues they relied on Apple’s App Store review process and security claims when downloading the “fake” Sparrow Wallet mobile app. In their submission, they accused Apple of failing to detect and remove the impersonating mobile app before it reached consumers.
The complaint alleged that Apple has consistently marketed its ecosystem as more secure by reviewing every app before publication while discouraging third-party app stores and sideloading. The lawsuit claims those assurances created an expectation that fraudulent applications would not appear on the App Store.
Meanwhile, the filing cites previous public criticism from Sparrow Wallet creator Craig Raw, who warned that fake versions of his wallet had appeared on Apple’s app marketplace. The trio is seeking a jury trial and compensation for their alleged losses while pushing for orders against Apple to provide stronger warnings on its App Store.
Apple defends its app review process as hackers sidestep guardrails
While Apple did not comment directly on the lawsuit, the iPhone maker defended its App Store security measures in a statement. The company said apps that impersonate legitimate developers violate its App Store guidelines and that it removes such apps when discovered.
Apple added that no fake Sparrow Wallet apps are currently available on the App Store. The iPhone maker also pointed to its latest App Store fraud analysis, revealing that it rejected nearly 400,000 app submissions for spam and copying existing apps.
Despite the tight rules, on-chain security firm SlowMist revealed a vicious MacOS malware targeting crypto wallets and Telegram accounts. The malware can replace Ledger and Trezor apps with phishing versions to steal recovery phrases from unsuspecting users.
Cybersecurity firm Check Point identified malware in the Apple App Store and Google Play, scanning users’ photos for crypto wallet seed phrases. Dubbed SparkKitty, Check Point disclosed that the malware hides inside apps disguised as crypto tools and messaging platforms.
Zooming out, the cryptocurrency ecosystem is facing a slew of security exploits, with Q2 becoming the worst quarter on record for breach incidents. A series of high-profile account takeovers on X have tricked users into investing in scam crypto projects while AI use in the hands of bad actors has amplified the threat.
Source:: Apple Sued Over $1.8M Fake Bitcoin Wallet Scam in App Store