Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them
Apple’s App Store enabled the theft of $1.8 million in Bitcoin through fake wallet apps bearing the Sparrow brand, according to a lawsuit filed in California on July 24. The case alleges that Apple not only failed to remove impersonators after a year of warnings from Sparrow’s developer, but actively promoted the fraudulent apps within the store’s cryptocurrency collections, directly undermining the company’s core justification for maintaining a closed, curated app ecosystem.
- Three Bitcoin holders lost a combined $1.8 million to fake Sparrow wallet apps that Apple’s App Store promoted despite over one year of warnings from Sparrow founder Craig Raw.
- James Ramirez lost 7.4 BTC (worth approximately $875,000) on July 25, 2025, one day after reporting a Sparrow impersonator to Apple, suggesting the company had direct notice before a major theft.
- A separate investigation identified 26 applications impersonating major crypto brands across Apple’s ecosystem, raising questions about whether the App Store’s vaunted screening process adequately protects against financial fraud.
- $1.8M Combined losses from three Bitcoin holders targeted by fake Sparrow wallet apps on App Store
- 12+ months Duration of warnings from Sparrow developer before the largest theft occurred in July 2025
- 26 Malicious applications impersonating major crypto brands identified across Apple’s ecosystem
The lawsuit, filed in California Superior Court, directly challenges one of Apple’s most enduring regulatory arguments: that its tightly controlled App Store distribution model protects users from fraud and malicious software better than open-source alternatives. Instead, the case presents evidence that Apple’s curation failed at precisely the moment it should have succeeded.
Unlike malware that requires sophisticated technical analysis to identify, a fake Sparrow wallet app should have been trivial to remove, since Sparrow is a desktop-only product with no legitimate iPhone version.
Yet the complaint alleges that multiple impersonators not only persisted in the store but were algorithmically surfaced to users through featured cryptocurrency collections, effectively giving fraudulent apps the credibility of Apple’s own editorial endorsement.
The timing of the thefts adds critical legal weight to the complaint. Jalen Delgado downloaded a fake Sparrow app in May 2025 and lost just over 1 BTC, valued at approximately $120,000. Two months later, James Ramirez reported both the fraudulent app and his theft to Apple on July 25, 2025, after losing 7.4 BTC worth roughly $875,000.
Nine days after that report, Christopher Ellis allegedly encountered another Sparrow impersonator through the App Store, entered his recovery phrase, and lost approximately $840,000 in crypto assets.
The plaintiffs’ argument hinges on this sequence: Apple had moved from merely tolerating brand impersonation to receiving specific notice linking a particular fake wallet to a major Bitcoin theft, yet failed to prevent the same outcome from recurring within days.
Sparrow Developer Warned Apple for Over a Year Before July 2025 Theft Wave
Craig Raw, founder of Sparrow Wallet, began flagging unauthorized mobile versions of his desktop application to Apple in early 2024, according to the complaint. Since Sparrow exists exclusively as a desktop product, any iPhone or Android app bearing the Sparrow name is, by definition, fraudulent.
The simplicity of this distinction should have made removal straightforward, requiring no specialized cryptographic expertise or investigation into wallet functionality.
Yet the lawsuit alleges that fake Sparrow apps continued to proliferate across the App Store throughout 2024 and into 2025, suggesting either systematic inattention to Raw’s reports or a failure in Apple’s review infrastructure to act on them.
The complaint characterizes Apple’s conduct as compounding the harm through active promotion. Rather than passively hosting the fraudulent apps, Apple allegedly ranked the Sparrow impersonators and featured them within in-app curated collections focused on cryptocurrency tools.
This editorial placement would naturally increase the credibility and visibility of software designed to deceive users into believing they were downloading an official wallet. For users unfamiliar with Sparrow’s desktop-only status, an app prominently displayed in Apple’s own cryptocurrency collections would appear vetted and trustworthy.
The algorithmic promotion transformed what might have been a neglected imposter into a seemingly sanctioned financial tool.
The gap between Raw’s early warnings and the July 2025 thefts, spanning more than 18 months, forms the core of the negligence claim against Apple.
Broader App Store Screening Failures Extend Beyond Sparrow to 26 Impersonated Crypto Brands
The Sparrow case is not an isolated incident. Researchers have documented at least 26 applications impersonating major cryptocurrency brands circulating within Apple’s App Store ecosystem. This finding suggests a systemic gap between Apple’s public claims about rigorous app review and its actual implementation.
For institutional investors evaluating custody solutions and wallet providers, the discovery that counterfeit versions of established brands can persist on the world’s largest mobile app store undermines confidence in user protection mechanisms across the entire fintech stack.
Apple has long justified its restrictive App Store policies by arguing that human review and algorithmic screening provide superior protection against fraud compared to open source distribution models favored by some blockchain projects.
That argument, central to regulatory approval and investor confidence in iOS as a platform for financial applications, rests on the assumption that bad actors are reliably identified and removed before reaching users.
The existence of 26 impersonators suggests either insufficient reviewer training in cryptocurrency security basics, inadequate staffing for the volume of submissions, or insufficient investment in automated detection of simple brand impersonation.
None of these explanations are reassuring for financial institutions considering iOS deployment or for institutional clients whose employees access crypto assets through mobile wallets.
The case also reveals a potential gap in Apple’s escalation procedures. When an app developer reports brand impersonation directly to Apple, and when that impersonation is linked to quantifiable financial theft, the company has concrete evidence justifying rapid removal.
The fact that additional victims encountered fake Sparrow apps days after Ramirez’s report suggests that either the report failed to reach the relevant review team, or it was received but not treated as urgent despite the documented theft. Both scenarios indicate procedural failure at a level beyond simple technical oversight.
Apple’s Promotion of Fraudulent Apps Within Curated Collections Raises Liability Questions
A particularly damaging allegation in the complaint is that Apple did not merely distribute the fake Sparrow apps, but actively promoted them. The lawsuit specifically claims that Apple ranked the impersonators and featured them within cryptocurrency app collections, effectively using Apple’s own editorial credibility to enhance the deceptive appearance of fraudulent software.
This distinction matters legally and strategically. Passive hosting of malicious content sometimes falls within platform immunity protections; active promotion and editorial curation does not. By featuring these apps in curated collections, Apple moved from being a neutral distributor to a recommender, significantly increasing liability exposure.
The promotional mechanism also explains why the thefts accelerated in July 2025. Users discovering a fake Sparrow app through organic search or word-of-mouth might reasonably verify its legitimacy. Users discovering it through Apple’s own featured collections have a reasonable expectation that Apple has performed basic due diligence.
The algorithmic promotion effectively weaponized Apple’s brand trust against its users. For institutional custody providers and blockchain platforms, this raises questions about whether their own brands can be reliably protected within the iOS ecosystem, and whether users will hold Apple accountable for fraudulent impersonators rather than the legitimate company behind the original brand.
The complaint alleges that despite multiple reports of fraudulent apps, Apple failed to warn consumers about the existence of spoofed wallet applications.
Lawsuit Tests Whether App Store Curation Model Protects or Endangers Financial Assets
Apple’s App Store model has weathered decades of regulatory scrutiny partly because it presents a coherent tradeoff: tight control limits user choice but increases security. Regulators have accepted this argument in evaluating antitrust concerns, often concluding that while the closed ecosystem creates commercial disadvantages for competitors, it does provide genuine consumer protection benefits. The Sparrow case directly tests whether that protection actually exists in practice, particularly for high-value financial transactions. If Apple can simultaneously maintain control over which apps are distributed, curate collections to feature specific apps, and yet fail to
