DeFiLlama Sacrificed Real Crypto to Force Apple Into Action

  • DeFiLlama reported a fake app to Apple for months and got nowhere.
  • The team loaded a real wallet, downloaded the app, and lost the funds.
  • Apple removed the scam app days after receiving proof of the theft.
Promo

DeFiLlama’s team loaded a wallet with real crypto, handed it to a counterfeit version of their own app, and watched the money vanish. Apple removed the scam listing days later.

Months of trademark and impersonation complaints had achieved nothing. Only documented theft moved Apple’s reviewers, according to a post from DeFiLlama developer 0xngmi.

Sponsored
Sponsored

How the Fake DeFiLlama App Drained a Real Wallet

DeFiLlama tracks capital locked across decentralized finance (DeFi) protocols, and traders treat its dashboards as a reference point. That trust made the brand worth copying.

The clone was crude. It simply asked users to enter their seed phrase—the 12 or 24 words that control a wallet—and then emptied whatever it found.

No legitimate wallet or analytics app ever requests that phrase. However, an App Store badge lends the kind of credibility a phishing website cannot buy, which is why iPhone wallet exploits keep paying off for attackers.

The operators also walked through Apple’s identity checks. They registered the developer account using a small shoe shop incorporated 40 years ago and long since dissolved, 0xngmi said. The same crew has targeted other major crypto brands.

So the team stopped filing reports and instead built a case. They funded a throwaway wallet, installed the fake app, entered the phrase, lost the coins, and sent Apple the evidence. The listing disappeared within days.

Sponsored
Sponsored

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

Review Process Faces Growing Pressure

This case is not isolated. Kaspersky counted 26 fraudulent wallet apps on the App Store in April, with several impersonating Ledger, MetaMask, and Trust Wallet, according to its research.

Victims are rarely careless. In April, a fake Ledger app cost musician G. Love nearly 6 BTC after he trusted an App Store download. Copycat websites work the same way, and one Uniswap phishing clone took roughly $400,000 from traders in May.

Meanwhile, three Bitcoin holders sued Apple in late July over a counterfeit Sparrow Wallet listing they say cost them $1.8 million combined.

Therefore, the incentive gap looks stark. Brands absorb the reputational damage, users absorb the losses, and the store keeps collecting fees.

Security teams keep flagging the same weak point. Binance’s chief security officer recently argued that phishing and malware, not exotic cryptographic attacks, are what drain wallets today. Fake ads and spoofed sites, including a recent Trezor phishing campaign, reinforce that point.

DeFiLlama held back its own iOS release for months so no user would grab an imposter first. That caution cost the project time and momentum. Whether rival teams now copy the drain-yourself playbook says more about Apple’s process than about crypto.


To read the latest cryptocurrency market analysis from BeInCrypto, click here.

Disclaimer

BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.

Sponsored
Sponsored