DeFiLlama founder drained his own wallet to get Apple to pull a fake app
The founder of DeFiLlama deliberately drained his own wallet through a fraudulent app to force Apple to remove it after the company ignored months of formal abuse complaints. The incident exposes a critical vulnerability in app store security vetting that institutional crypto platforms cannot afford to ignore as they scale user acquisition.
- 0xngmi funded a wallet, downloaded the fake DeFiLlama app, confirmed it stole the funds, then reported proof to Apple, which removed the app within days.
- Apple’s identity verification failed to catch scammers who registered under a defunct shoe-shine business incorporated 40 years prior with no current operations.
- DeFiLlama delayed its real app launch by months to ensure users wouldn’t accidentally download a scam, adding significant go-to-market friction.
- Months of impersonation complaints DeFiLlama filed before resorting to self-funded proof of theft
- Days Apple took to remove the app after receiving evidence of actual fund theft by the user
- $550,000 lost by Hyperliquid trader via cloned exchange from paid Google ad on same date
On August 15, 2026, 0xngmi, the pseudonymous founder of DeFiLlama, disclosed an extraordinary step he had taken to protect users: he loaded a cryptocurrency wallet with funds, installed a counterfeit version of his own platform from Apple’s App Store, watched it drain the money, and only then reported the theft to Apple as proof of the scam. The app was removed within days.
The revelation underscores a systemic failure in how major platforms enforce identity verification and trademark protection, a failure that poses direct operational and reputational risk to institutional-grade crypto platforms seeking mainstream adoption.
DeFiLlama’s experience is not isolated. On the same date 0xngmi published his account, a Hyperliquid trader lost approximately 550,000 USDC after clicking a paid Google ad directing them to a cloned version of the exchange. In May 2026, scammers extracted more than 400,000 from Uniswap users through fake Google ad listings alone, with roughly 146 ETH subsequently traced to two attacker addresses.
These incidents reflect a widening gap between the volume of impersonation attempts and the speed at which major platforms, Apple, Google, and ad networks, respond to reports from the projects themselves.
Apple ignored months of formal trademark complaints before proof of theft prompted removal
DeFiLlama’s team had submitted multiple reports to Apple through both the company’s official abuse channel and its trademark complaint process over a period of months, flagging the fake app as an impersonation and trademark violation. None of those reports resulted in action. The fake app remained live on the App Store, available for download to users searching for legitimate DeFiLlama services.
0xngmi described the counterfeit as a basic replica of DeFiLlama’s interface, built with minimal engineering effort, he used the term “vibecoded” to characterize its crude construction. The sole purpose was clear: prompt users to enter their seed phrase, the secret recovery words that grant complete control over a cryptocurrency wallet.
Once obtained, attackers can drain all assets without requiring additional authentication or victim action.
The scammers behind the fake app, according to 0xngmi’s account, had developed a systematic approach to bypass Apple’s identity checks. They registered lookalike apps for multiple major crypto brands, cycling through shell entities to pass verification.
In DeFiLlama’s case specifically, they completed Apple’s know-your-customer process by registering under a shoe-shine business that had been incorporated approximately 40 years earlier and was no longer operational. This suggests the attackers had acquired or reused dormant business registrations to satisfy Apple’s automated or manual review processes.
DeFiLlama delayed its app launch months to prevent users from accidentally downloading the counterfeit
The discovery forced DeFiLlama into an unusual position: the team decided to postpone the official app launch indefinitely until every fraudulent version had been removed from the App Store.
The cost was direct, lost time and delayed access for legitimate users, but the alternative was worse: users arriving at the platform for the first time via app store search could easily land on the scam instead.
This delay reflects a broader defensive posture DeFiLlama has already embedded into its operations. The platform operates LlamaSearch, a curated directory of verified crypto domains, built precisely because search results and app store listings are routinely manipulated to serve fraudulent versions of legitimate platforms.
The tool is a symptom of market dysfunction, not innovation, it exists because the underlying platforms (Google Search, the App Store, ad networks) cannot or will not effectively prevent impersonation at scale.
For institutional investors and platforms evaluating user acquisition strategies, the DeFiLlama case illustrates a hidden cost in the crypto sector’s growth: the burden of defensive verification falls entirely on legitimate projects, not on the platforms hosting them.
Apple, Google, and ad networks generate revenue from the apps and ads they host, but they do not bear the reputational or financial cost when those ads or apps are fraudulent. This asymmetry creates perverse incentives.
Scammers are exploiting dead business registrations to bypass identity verification at scale
The most technically interesting detail in 0xngmi’s disclosure is the method by which the scammers passed Apple’s identity verification: they used a defunct business entity. This suggests several possibilities.
Either Apple’s identity checks rely primarily on registered business records without validation that the business is actually operating, or the scammers had obtained legitimate incorporation documents from an existing but inactive entity. Either way, the loophole is systematic enough to have been weaponized against multiple crypto platforms simultaneously.
The pattern matches what researchers have observed across ad platforms. A Hyperliquid trader lost 550,000 USDC in August 2026 after a paid Google ad directed them to a cloned exchange. In May 2026, multiple Uniswap users were similarly targeted through fraudulent Google ads.
Cryptopolitan also documented a fake Hyperliquid app on Google Play Store in November 2025, suggesting that both the App Store and Google Play are targeting the same users with overlapping attack surfaces.
The fact that these scams operate in parallel across multiple platforms, the App Store, Google Play, Google Ads, indicates that attackers have built replicable infrastructure. They are not running opportunistic campaigns against individual platforms. Instead, they are operating a systematic fraud network that treats all platforms as interchangeable distribution channels.
From this perspective, a single removal from the App Store is a victory but not a solution.
What institutional platforms must monitor as app store enforcement remains inconsistent
0xngmi’s disclosure was partly a call to action for other crypto teams. He wrote that he was publicizing the episode so other projects “don’t waste time like us”, meaning they should not expect Apple to act on trademark and impersonation reports alone. The implicit advice was to document actual theft and report that instead.
This creates a difficult position for institutional platforms considering app store distribution. They face a choice: either launch apps knowing that fraudulent versions may persist on the same platform, potentially cannibalizing user acquisition and damaging brand trust, or delay launch indefinitely while waiting for platforms to enforce their own policies.
Some platforms, like DeFiLlama, have chosen the latter. Others may choose to avoid the app store entirely and direct users to web-based platforms instead.
For platforms that do launch apps, the DeFiLlama case also highlights a secondary risk: the fake app may outrank or appear adjacent to the legitimate one in search results, meaning users who find the real app may still accidentally download the counterfeit. This is not a theoretical risk. It is currently happening at scale across multiple platforms.
The open question now is whether Apple, Google, and ad networks will tighten identity verification requirements in response to coordinated pressure from the crypto industry, or whether institutional platforms will continue to treat app store impersonation as an unsolved friction cost of user acquisition. 0xngmi’s disclosure did not yield any public statement from Apple regarding changes to its review process, and the incident remains unresolved as a systemic problem. Any platform planning a major app store launch should monitor whether Apple or Google announce enforcement changes in the coming
