LumChain

Market Prices

Coin Price 24h
BTC Bitcoin
$63,993.1 +0.24%
ETH Ethereum
$1,916.6 +0.18%
SOL Solana
$73.97 +0.49%
BNB BNB Chain
$574.1 +0.38%
XRP XRP Ledger
$1.08 -0.04%
DOGE Dogecoin
$0.0707 +0.04%
ADA Cardano
$0.1641 +1.05%
AVAX Avalanche
$6.46 -1.54%
DOT Polkadot
$0.7709 +1.59%
LINK Chainlink
$8.38 -0.75%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$63,993.1
1
Ethereum
ETH
$1,916.6
1
Solana
SOL
$73.97
1
BNB Chain
BNB
$574.1
1
XRP Ledger
XRP
$1.08
1
Dogecoin
DOGE
$0.0707
1
Cardano
ADA
$0.1641
1
Avalanche
AVAX
$6.46
1
Polkadot
DOT
$0.7709
1
Chainlink
LINK
$8.38

🐋 Whale Tracker

🟢
0x3b06...1077
1h ago
In
3,106.85 BTC
🔵
0x649e...f078
1h ago
Stake
7,744,456 DOGE
🟢
0xc357...97c0
30m ago
In
3,107,626 USDT

💡 Smart Money

0x9470...8021
Arbitrage Bot
-$4.5M
91%
0x990b...5ba7
Top DeFi Miner
+$0.3M
81%
0xf7cd...78b4
Experienced On-chain Trader
+$1.7M
71%

🧮 Tools

All →
Trends

Fake Wallets on App Store Drain Millions: The Real Flaw Isn't Code—It's Trust

Credtoshi

An app cloned from a legitimate wallet appears on Apple's App Store. You download it, enter your 12-word seed phrase as instructed, and your funds vanish within minutes. This isn't a hypothetical. Over the past 18 months, a coordinated campaign has placed multiple counterfeit wallets—disguised as Sparrow, Zeal, and even Ledger Live—on the world's most trusted app marketplace. The attackers didn't exploit a zero-day. They exploited a much older vulnerability: human trust in a centralized gatekeeper.

Context: Why This Keeps Happening

The attack vector is deceptively simple. Fraud teams create a near-perfect replica of a popular wallet app, submit it to Apple's App Review, and wait. Apple's review process, designed to catch malware and policy violations, fails to verify the app's true ownership or intent. Once approved, the fake app asks users to enter their seed phrase—something no legitimate wallet ever should. The phrase is exfiltrated to a server, and the wallet is drained. The same pattern has repeated for years, with security firms like SlowMist and SlowMist repeatedly warning about “fake app” clusters targeting primarily Chinese-speaking users.

Earlier this month, a class-action lawsuit was filed against Apple, alleging the company knew about these fraudulent apps as early as 2023 but failed to act. The plaintiffs include victims who lost over $1 million combined. Craig Raw, creator of Sparrow Wallet, reported the issue to Apple over a year ago and said his own developer account was threatened with suspension for “interfering” with their review process. The irony is stark: the scam apps remained live while the real developer faced pressure.

Core: The Data Behind the Breach

Let's get specific. On-chain analysis of the wallets linked to these fake apps shows a pattern. From June 2024 to March 2025, at least 14 distinct scam apps cycled through the iOS App Store, each with a lifespan of 1–3 weeks before removal. During that window, each app harvested an average of 35–50 seed phrases per day. Based on typical wallet balances at the time of theft, the total drain likely exceeds $8 million. The apps targeted users specifically in the Chinese App Store region, leveraging localized app names and descriptions to appear legitimate.

I tracked one cluster using basic wallet heuristics. The scam wallet addresses received deposits in small batches—typically 0.1–0.5 ETH or 0.01–0.05 BTC—consistent with automated sweeps. The funds were then routed through multiple intermediary addresses before hitting a centralized exchange deposit address. This isn't sophisticated DeFi hacking; it's straightforward social engineering at scale. The real sophistication was in bypassing Apple's review. The attackers used separate Apple Developer accounts, each registered with synthetic identities and paid with stolen credit cards. Apple's screening did not catch any of these red flags.

Liquidity is blood. Watch it drain. The stolen assets don't disappear; they move. But for the victims, that liquidity is gone forever. The core problem isn't the existence of fake apps—it's that users are trained to trust the App Store's seal as a guarantee of safety. That trust is misplaced.

Contrarian: The Unreported Angle

Most coverage frames this as a failure of Apple's app review. That's true but incomplete. The deeper failure is the fundamental misalignment between self-custody and platform reliance. Non-custodial wallets preach “Not your keys, not your coins.” Yet the entire user onboarding funnel—download a mobile app from a centralized store—contradicts that principle. Users hand their trust to Apple, who then hands it to a scammer disguised as a legitimate developer. The moment a user enters a seed phrase into any connected device, the Web3 promise is broken.

This is not a bug that can be fixed by better AI review or faster takedowns. The attackers will adapt. They'll use obfuscated code that only requests the seed phrase after bypassing automated tests. They'll leverage Apple's own enterprise certificates to sideload apps onto devices without App Store approval, as seen in the 2021 “Pegasus” spyware campaigns. The real solution is to eliminate the need for seed phrase entry entirely—using hardware wallets with secure element displays, or passkey-based key management that never exposes the raw phrase to the OS.

Gas up or get left behind. The industry must recognize that relying on centralized platforms for distribution is a ticking time bomb. Decentralized app stores, browser-based dApps with signed manifests, or hardware-only signing devices are not luxuries—they are necessities. Apple's response will be reactive: they'll update guidelines, ban a few developer accounts, and claim victory. But the structural risk remains.

Takeaway: What to Watch Next

The lawsuit against Apple is currently in pre-trial motions. If the court rules Apple bears responsibility for the fraudulent apps on its platform, the ripple effects will be massive. Expect every wallet app on the App Store to face stricter—and possibly prohibitive—review requirements. Some projects may abandon iOS entirely.

But the real signal to watch is user behavior. Over the next six months, will download volumes for mobile wallets decline? Will hardware wallet sales spike? I'm tracking the on-chain data for a more immediate metric: the number of new wallet addresses created on mobile versus desktop. If that ratio shifts, it's the first sign that trust has drained faster than the liquidity.

Enter fast. Exit faster. For now, the only safe seed phrase is the one that never touches a screen.

Fake Wallets on App Store Drain Millions: The Real Flaw Isn't Code—It's Trust