Home / News / Breaking / DeFiLlama Had to Let Scammers Steal Its Crypto Before Apple Removed Fake App
Breaking 3 min read

DeFiLlama Had to Let Scammers Steal Its Crypto Before Apple Removed Fake App

DeFiLlama Had to Let Scammers Steal Its Crypto Before Apple Removed Fake App
DeFiLlama Had to Let Scammers Steal Its Crypto Before Apple Removed Fake App
Key Takeaways
  • DeFiLlama says it had to demonstrate a real crypto theft before Apple took action against an app impersonating the DeFi analytics platform.
  • An App Store listing using DeFiLlama branding had already attracted a public warning that it requested users’ wallet recovery phrases.
  • The episode follows several costly fake crypto apps that slipped through Apple’s review process in 2026, including impersonators of Ledger and Sparrow Wallet.

DeFiLlama has raised fresh questions about Apple’s App Store review process after saying it had to allow scammers to steal crypto from a test wallet to prove that an app impersonating the DeFi analytics platform was malicious.

The fake app allegedly asked users to enter their wallet seed phrase, giving its operators the credentials needed to take control of their assets. DeFiLlama’s team said earlier reports were insufficient to trigger removal, forcing it to demonstrate the drain with real crypto before action was taken.

Public App Store records reinforce the broader concern. A listing titled “DEFILLAMA App – TVL, Metrics” was published under developer OLAVI VITSUT rather than DeFiLlama.

One App Store review explicitly described the app as a scam and warned that it asked users to enter a seed or recovery phrase. The listing also carried an unrelated description for a product called “Dashkra Loan Manager,” another red flag.

Fake Crypto Apps Keep Passing App Store Checks

The incident is not isolated.

In April, a fraudulent Ledger Live app reached Apple’s store and was linked by blockchain investigator ZachXBT to roughly $9.5 million in losses across more than 50 victims. The stolen assets included Bitcoin, Ethereum, Solana, Tron, and XRP-linked funds. Apple subsequently removed the application and terminated the developer account.

The malicious Ledger app reportedly used a bait-and-switch technique, appearing legitimate during Apple’s review before changing behavior afterward. Victims were then prompted to enter wallet recovery phrases.

Apple Is Already Facing a Crypto App Lawsuit

Apple is also facing a federal lawsuit involving fake versions of Sparrow Wallet.

Three plaintiffs allege they collectively lost about $1.84 million in Bitcoin after downloading fraudulent Sparrow apps and entering their recovery phrases. One plaintiff allegedly reported losing $875,000 on July 25, 2025, yet another user allegedly lost around $840,000 more than a week later.

Sparrow’s legitimate wallet does not even have an iOS version.

The plaintiffs argue that Apple’s positioning of the App Store as a vetted marketplace gave the fraudulent software credibility it would not otherwise have had. Apple has said it removed apps impersonating Sparrow and terminated associated developer accounts.

Apple’s Fraud Numbers Show the Scale of the Problem

Apple says its defenses blocked more than $2.2 billion in potentially fraudulent transactions in 2025, rejected over two million problematic app submissions, and stopped more than 1.1 billion fraudulent account creations.

Those figures show the scale of Apple’s enforcement, but the DeFiLlama episode highlights the opposite side of the equation: in crypto, a malicious app that survives review can cause irreversible losses almost immediately.

That makes the central question less about whether Apple catches most fraudulent apps and more about how quickly it responds when a legitimate crypto company identifies one that slipped through.

Was this Article helpful? Yes No
Thank you for your feedback. 0% 0%