Skip to main content
Emerging ThreatsMalware & Ransomware

Apple Faces Lawsuit Over $1.8M Bitcoin Heist via Fake App Store Wallet App

Smartphone on a plain surface with blurred laptop screen and scattered papers in the background.

Approximately $1.8 million in Bitcoin was taken from three people after they downloaded what they say was a fraudulent Sparrow Wallet application from Apple's App Store, according to a complaint filed in California.

Plaintiffs James Ramirez, Christopher Ellis, and Jalen Delgado

The complaint, filed on July 24 in California, names James Ramirez, Christopher Ellis, and Jalen Delgado as plaintiffs who say they lost cryptocurrency after using a spoofed mobile app that impersonated the Sparrow Bitcoin wallet. The filing alleges the malicious app instructed users to enter their seed phrases — the secret recovery credentials for their wallets — and that, after doing so, the plaintiffs' Bitcoin was transferred to wallets controlled by the scammers.

The complaint details the alleged losses and timelines: Delgado is said to have downloaded the fraudulent application on or around May 1, 2025, and to have lost 1.05033242 Bitcoin, worth approximately $120,000. Ramirez allegedly downloaded the app on July 25, 2025, losing 7.4 Bitcoin, valued at roughly $875,000; the filing says Ramirez reported the fraudulent app and the theft to Apple that same day but that Apple did not contact him. The complaint states that on or around August 3, Ellis installed the app and discovered approximately $840,000 in cryptocurrency had been transferred to a scammer, and immediately reported the app and theft to Apple.

How the fake Sparrow Wallet app is described in the complaint

The complaint alleges the App Store listing impersonated the legitimate Sparrow Bitcoin wallet and used that false identity to prompt users to surrender seed phrases. The plaintiffs say the app was ranked by Apple and included in curated cryptocurrency app collections, which the complaint asserts effectively recommended the fraudulent application alongside legitimate apps.

The filing seeks reimbursement of the stolen cryptocurrency, compensatory and punitive damages, restitution, attorneys' fees, and other damages. It also asks the court to require Apple to improve and publicly disclose procedures for detecting and removing fraudulent applications and to introduce warnings about the risks associated with cryptocurrency apps.

Sparrow Wallet developer Craig Raw's prior warnings

The complaint cites a January 6, 2024 post from Craig Raw, the developer of the legitimate Sparrow Wallet, noting that a scam Sparrow Wallet app remained available in the App Store even after he and others reported it weeks earlier. Raw warned users to obtain Sparrow Wallet only through its official website rather than trusting an app solely because it was available in an app store.

According to the complaint and additional reporting cited therein, Raw also submitted an unpublished placeholder app to the App Store that explained mobile apps using the "Sparrow Wallet" name were fake. Raw said Apple initially flagged his developer account for termination over alleged dishonest activity related to that submission, and later reversed the decision.

Apple's statements to BleepingComputer and App Store reporting mechanisms

Apple told BleepingComputer that it acted quickly to remove applications impersonating Sparrow Wallet and terminated the developer accounts associated with them. The company said developers who believe content distributed through its services infringes their intellectual property can submit a dispute to Apple's legal department. Customers can separately report suspected App Store scams and fraud through Apple's Report a Problem service, and Apple said it takes immediate action when applications are found to violate its guidelines.

What this means for end users, software developers, and Apple

  • End users: The complaint describes a direct risk to users who enter seed phrases into mobile applications, noting that the legitimate Sparrow Wallet has no iOS version and that purported iOS Sparrow apps are impersonations.
  • Software developers and open-source maintainers: Craig Raw's account of prior reports and a blocked placeholder submission underscores challenges developers face when policing impersonation on app marketplaces, including potential adverse actions against their developer accounts before resolutions are reached.
  • Apple and the courts: The plaintiffs have asked the court not only for damages but also for injunctive relief — public disclosure of App Store fraud-detection procedures and warnings about crypto-app risks — placing the company's app-review and monitoring processes at the center of the lawsuit's remedies.

The complaint frames the central dispute as both financial restitution for victims and a demand for procedural change: the plaintiffs allege Apple promoted or recommended a fraudulent app, that Apple had been warned about impersonations more than a year before the losses, and that the existing reporting and takedown processes did not prevent their thefts. How a California court evaluates those claims and the relief sought will determine whether this case changes how app stores police impersonation and crypto-related fraud.

Original story