Login
Sign Up
Woofun AI reports that a class-action lawsuit filed in California on July 24 accuses Apple of negligence regarding the App Store, citing $1.8 million in losses from fake Sparrow wallet apps involving plaintiffs Craig Raw, Jalen Delgado, James Ramirez, and Christopher Ellis.
The timeline of financial devastation began in May 2025 when Jalen Delgado downloaded a counterfeit application, resulting in the theft of one Bitcoin valued at approximately $120,000 after he entered his seed phrase. The situation escalated on July 25, 2025, when James Ramirez lost 7.4 Bitcoins worth roughly $875,000 to another variant of the fake Sparrow wallet, reporting the incident to Apple immediately. Nine days later, Christopher Ellis suffered a similar fate, losing cryptocurrency assets valued at about $840,000 after inputting his recovery seed phrase into a malicious app found on the platform.
Plaintiffs argue that Apple’s liability stems not merely from the presence of these apps but from its active promotion and failure to act on prior warnings. The lawsuit alleges that Apple provided preferential traffic recommendations to these fraudulent applications and included them in curated cryptocurrency app collections, thereby lending them an aura of legitimacy. Users repeatedly informed Apple that these high-risk apps could lead to the theft of cryptocurrencies, seed phrases, private keys, wallet accounts, and various privacy details, yet no consumer warnings were issued.
Apple’s defense centers on its claim that it removed the implicated fake Sparrow apps and banned the corresponding developer accounts, citing dedicated reporting channels for rule violations.
However, the experience of Craig Raw, the founder of the legitimate Sparrow wallet, complicates this narrative. Raw had been reporting unauthorized mobile imitations since early 2024, noting that since Sparrow only existed as a desktop application, identifying iPhone clones should have been straightforward. Despite this, variants persisted throughout the year, and when Raw recently attempted to inform iOS platform users that no official mobile version existed, Apple initially deemed the information misleading and threatened to ban his developer account before reversing the decision.
The scope of the threat extends far beyond the Sparrow brand, as evidenced by a broader ecosystem analysis. In April, Kaspersky’s Threat Research team released a report identifying 26 scam apps within the Apple ecosystem that imitated popular cryptocurrency brands. These fraudulent applications targeted major industry players including MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie, indicating a systematic effort to exploit user trust in established financial tools.
Woofun AI data shows that Kaspersky attributes these activities to the SparkKitty threat group, noting that their operations have been active since at least fall 2025. The attack vectors are sophisticated, utilizing app redirects to lure users to phishing websites that mimic the Apple App Store interface. These sites prompt victims to install developer profiles, which allow scammers to bypass standard App Store reviews and install modified cryptocurrency wallets containing Trojans. This method is particularly prevalent among users of the Chinese App Store, where many mainstream wallets are unavailable, forcing reliance on less vetted alternatives.
A prominent case study illustrating this risk involves American musician Garrett Dutton, known professionally as G. Love, who revealed in April that he lost 5.9 Bitcoins worth approximately $424,000. Dutton downloaded what he believed was the genuine Ledger wallet from the App Store and followed instructions to enter his recovery seed phrase, resulting in the immediate transfer of funds. Blockchain investigator ZachXBT traced the stolen assets to a deposit address on the cryptocurrency exchange KuCoin, which temporarily froze the involved account during the investigation, highlighting the technical feasibility of tracking such thefts despite the initial loss.
These incidents directly challenge Apple’s core security narrative, which positions the App Store as a "safe and reliable software platform" protected by multiple layers of review. Apple argues that its closed ecosystem and prohibition of sideloading are essential to intercepting threats like Trojans and scams before they reach users.
However, cryptocurrency wallets present a unique vulnerability: they do not require complex malware to cause harm. A convincing interface is sufficient to trick users into surrendering control of decentralized wallet assets, leading to irreversible financial losses that no financial institution can reverse.
The plaintiffs are seeking punitive damages, litigation costs, and the return of all lost funds, alongside demands for improved detection processes and public review guidelines. Apple counters with historical security statistics, claiming that from 2020 to 2024, the App Store blocked potential fraudulent transactions totaling over $9 billion, with $2 billion blocked in 2024 alone. In that same year, Apple rejected nearly 2 million app submission requests, banned over 146,000 developer accounts for fraud, and denied 139,000 developer registrations, arguing that the volume of blocked threats validates its strict control model.
The legal outcome remains uncertain, but the implications for platform trust are profound. For cryptocurrency users, the leakage of a seed phrase results in permanent loss of assets, making the credibility of the App Store’s endorsement critical. As fake wallets continue to bypass review mechanisms and exploit user trust, the incident underscores a growing disconnect between Apple’s security claims and the reality of decentralized finance risks, forcing a reevaluation of how much reliance can be placed on platform vetting for high-value digital assets.