Apple Let a Fake Bitcoin App Steal $1.8 Million From iPhone Users. Now It's Being Sued

A new lawsuit accuses Apple of negligence and misleading App Store safety claims after three users allegedly lost $1.84 million to a fake wallet app.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Although Apple says it evaluates every app to ensure it meets “Apple’s high standards for privacy, security, and safety” before allowing it on the App Store,[1] a recent lawsuit suggests otherwise.

A new lawsuit filed in California accuses Apple of allowing a fraudulent Bitcoin wallet app to remain on its App Store for a week after a customer reported losing $875,000 to a scam.[2]

The fake wallet app impersonated Sparrow Wallet, a Bitcoin wallet available on Windows, Linux, and macOS, but not on the App Store. The three plaintiffs reportedly lost around $1.84 million to the fake wallet scam.

Here's what happened, how Apple was responsible, and, most importantly, how you can stay safe from such fraudulent applications.

In this article
Why Apple is being sued
Apple ignored warning signs
Not the first fake app case against Apple
Apple defends its App Store
Privacy risks of fraudulent wallet apps
What can you do to protect yourself
Bottom line

Why Apple is being sued

The federal lawsuit was filed on July 24 and has three plaintiffs.

  1. James Ramirez claims that he downloaded the fake Sparrow Wallet app on July 25, 2025, and lost 7.4 BTC (around $873,000). He reported the application to Apple the same day, but the company failed to take any action.
  2. Christopher Ellis, another plaintiff, lost $840,000 after installing the app one week later, on August 3, 2025.
  3. Jalen Delgado, the third plaintiff, downloaded the app on May 21, 2025, and lost around $120,000 worth of Bitcoin.

The plaintiffs allege that Apple didn’t devote the necessary oversight and attention to reviewing and monitoring the applications on its App Store, despite what the company claims.

For context, Apple retains exclusive control over which applications are allowed on the App Store. “Apple maintains the safety of the App Store by ensuring that every app is reviewed by a member of the App Review team,” says Apple.

Tthe lawsuit says that Apple failed to live up to its claims, allegedly allowing cybercriminals to plant fraudulent apps and steal funds from its own customers.

"These assurances, repeated across Apple's public-facing marketing and communications, fostered the widespread belief that all applications offered through the App Store were carefully reviewed, secure, and dependable," says the lawsuit.

Apple ignored warning signs

The lawsuit shouldn't come as a surprise to Apple. After all, the company has been ignoring warning signs about fake Sparrow Wallet apps since 2023. Craig Raw, the developer of the real Sparrow Wallet, has been warning users and Apple about these scams.

On January 6, 2024, he posted on X, saying there were still scam Sparrow Wallet apps on the Apple App Store despite him and others reporting them weeks earlier. The worst part about these apps, he said, was that users had to install them to report them.

Then again, in June 2026, Raw posted on X saying that his efforts to save innocent investors from such fake apps had been blocked by Apple.

Raw had launched an application that served as a placeholder, warning users that Sparrow is only a desktop application and that all other Sparrow apps are fake and unofficial. However, Apple flagged Raw's developer account for termination. The decision was reversed the next day.

Even in this case, Apple allegedly ignored James Ramirez's initial report and allowed the app to remain on its App Store for another week, resulting in Christopher Ellis losing another $840,000.

Not the first fake app case against Apple

A similar lawsuit was filed against Apple in May 2021, in which the plaintiff, Hadona Diep, accused Apple of hosting a fraudulent version of the Toast Wallet app, called Toast Plus, on its App Store.

Diep suffered losses of more than $5,000, while her co-plaintiff, Ryumei Nagao, lost $500,000 to the same fraudulent app.

However, a federal judge in San Francisco ruled that the company couldn’t be held liable for any damages under Section 230 of the Communications Decency Act. The court ruled that Apple is only an interactive computer service provider and publishes information provided by another content provider.

The court also highlighted that Apple's terms and conditions state that the company cannot be held liable for damages arising out of or related to the use of third-party applications.

Interestingly, the plaintiffs appealed to the Ninth Circuit, which partially reversed the order. The circuit said that while the plaintiffs couldn’t sue Apple for failing to detect or publish a scam application — since Apple is not the creator of the app — Apple's own terms of service cannot protect it from liability for fraud or false statements.

In other words, the circuit allowed the plaintiffs to sue Apple on the grounds that its own advertising about the App Store's safety was allegedly false and that people lost money because they relied on these claims.

Although the plaintiffs were given an opportunity to amend their complaint, the amendment was never filed, and the case was dismissed on procedural grounds. However, this could provide an important precedent for the current case.

While the courts may still decide that Apple is protected under Section 230, the plaintiffs are likely to draw on the fact that the Ninth Circuit allowed the lawsuit to proceed on false advertising grounds.

Apple defends its App Store

Apple responded to MacRumors by saying that it had taken swift action to remove applications impersonating Sparrow Wallet from its App Store and terminated the developer accounts associated with those applications.

Additionally, any developer who suspects that an application available on the App Store infringes on their intellectual property rights can submit a dispute form. Customers can also report App Store fraud.

Earlier in 2025, Apple said that it had reviewed more than 9.1 million App Store submissions, of which 2 million were rejected, preventing an estimated $2.2 billion in potential fraud.

Privacy risks of fraudulent wallet apps

Fake applications, such as this iOS version of Sparrow Wallet and Toast Plus, often ask users to enter their seed phrases or private keys to import or set up a wallet.

Unlike a stolen password, though, a compromised seed phrase cannot simply be reset and permanently exposes the assets in that wallet.

The same happened in this case as well. The plaintiffs trusted the application with their seed phrases, which ultimately led to the loss of their Bitcoin assets.

Worse still, such fraudulent apps can also impersonate other services, such as banking applications.

Entering your personal information such as your name, address, banking PINs, or passwords into such phishing apps can lead to financial fraud and identity theft. Malicious actors may use these credentials to open new lines of credit in your name or file tax returns to claim fraudulent refunds.

What can you do to protect yourself

While the Apple App Store is generally known for being safe, it’s understandable if the recent lawsuit has shaken your confidence in Apple's vetting process. As such, it’s advisable to reclaim your privacy and security.

Make sure that any application you download from the App Store is legitimate. A good way to do this is by visiting the application's official website and checking which platforms it supports.

If you don’t find the application listed as being available on the Apple App Store, the app you were about to download is most likely fraudulent.

Here are some more steps you can take to stay safe from fake apps:

  1. Check the developer name on the App Store page against the official developer name on the application's official website. Scammers often use similar names, but not identical ones.
  2. Look at the app's history, reviews, and release date. A financial application with very few reviews and a recent release date is a red flag you shouldn’t ignore.
  3. Search for the app name along with terms like "scam" or "fake" before installing it. If any such scams exist, you'll know about them right away.
  4. Never enter your seed phrase or private key into any newly installed application. If it’s a legitimate wallet, the provider will typically let you generate a new wallet instead of asking you to import an existing one.
  5. Always start with a small test transaction before moving large amounts of funds to a newly installed digital wallet application.
  6. If you have downloaded or interacted with such fake applications and are worried about your data, use an identity theft protection service. These services monitor the dark web and other online databases for your exposed information and alert you if they find any matches.

Bottom line

The new lawsuit against Apple accuses it of gross negligence and misusing customers' trust by hosting a scam crypto app, even after repeated reports from customers and developers. This ultimately led to losses of $1.84 million for the three plaintiffs in the case.

A similar lawsuit against Apple in the past, however, fell through on procedural grounds, even though the Ninth Circuit recognized the plaintiffs' right to pursue false advertising claims. Whether the current case follows a similar path or results in a different outcome, only time will tell.

Right now, if you rely on the App Store to only house verified applications, it’s time to reconsider that trust. Make sure that any applications you download are legitimate by cross-checking them with the provider's official website. Also, look at the app's release date and what people online, such as on X or Reddit, are saying about it.

4.8
Editorial Rating
Get Deal
On LifeLock's website
2026 Editors’ Choice
Best ID Theft Service for Comprehensive Monitoring
Identity Protection
LifeLock
  • ID theft protection with U.S.-based restoration specialists and data removal services included on every plan
  • ID theft insurance on all plans, with the Total plan covering up to $3M
  • Dark web, home title, and social media monitoring available, with coverage expanding by plan tier

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Maintaining a safe App Store experience

[2] Complaint for damages and demand for jury trial