Security Current Affairs

Apple's $1.8M Problem: How a Fake Sparrow Wallet App Slipped Through the Gates

2026-07-29

Three people have sued Apple for roughly $1.8 million in Bitcoin they lost to a fraudulent Sparrow Wallet app on the App Store. The suit, filed 24 July in federal court for northern California, accuses Apple of failing to properly vet apps while marketing the store as a trusted place to get software. Fair point, that one stings.

The victims—James Ramirez, Christopher Ellis, and Jalen Delgado—downloaded what they thought was the real Sparrow Wallet. The fake app asked them to enter their seed phrases. That's the master key to your Bitcoin. They gave it up. Scammers transferred the lot to wallets they controlled. Ramirez lost about $875,000. Ellis lost around $840,000. Delgado lost roughly $120,000. Thefts happened between May and August 2025.

Here's where it gets damning. The real Sparrow Wallet is desktop-only. Windows, macOS, Linux. No iOS version exists. Ever. So any iOS app claiming to be Sparrow is fake by definition. Apple ranked this malicious app in search results and placed it in curated crypto collections. Right there, next to legitimate wallets, as if it belonged.

Worse: Apple ignored warnings. Craig Raw, who actually built Sparrow, posted publicly on 6 January 2024 that a scam Sparrow app was still live despite him and others reporting it for weeks. Since 2023, more than a dozen fake Sparrow apps have appeared on the store. As recently as April 2026, new ones surfaced.

Raw tried protecting users by submitting a placeholder app with screenshots saying Sparrow is desktop-only. Apple flagged his developer account for "dishonest activity" and threatened to terminate it. They reversed course later. But the message was clear: Apple's review process doesn't reward actually protecting people.

When Ramirez reported the fraud and theft to Apple on 25 July 2025, Apple never contacted him. Not about his report. Not about the later ones either.

Apple's response: we block apps and we're great at security. The company reports removing impersonating apps and terminating developer accounts tied to them. During 2025, Apple claims it blocked more than $2.2 billion in potentially fraudulent transactions and rejected over two million problematic submissions. Those are big numbers. They don't fix the fact that this app got through.

The lawsuit highlights a real problem for Apple. As scams get smarter and losses grow bigger, the company's walled garden faces questions it can't answer with blocking stats. What matters isn't how many scams you stop. It's the ones that slip through—and whether you ignore warnings about them. Apple's ecosystem is closed. It's supposed to be safer. This case suggests the tightness doesn't equal rigour.

This isn't isolated. Earlier this year, a fake Ledger Live app stole over $9.5 million from more than 50 victims. A fraudulent Trezor app topped App Store search results in 2023 before removal. A fake Rabby Wallet linked to stolen funds showed up in 2024.

Cryptocurrency wallets are targets. High value, concentrated access, one mistake (or one malicious app) and everything is gone. The App Store should be a fortress. Instead, it's where people lose life-changing amounts of money to something claiming to be Sparrow.


Source & further reading:

Sources