Skip to main content
Sign in

Audit log

Every state-changing event for Apple App Store — Systematic Fake Crypto Wallet Cluster (26 Apps, April 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-10 23:32:37Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    9RzyygTB72pH…PQcTy2iEsha256 → base58
    verifying row…
    canonical bytes (35036 B) ▸
    {"actor":"system:backfill","investigation_id":"42b8c959-a16c-40cc-8834-3f1d3c054da1","kind":"publish","page_slug":"apple-app-store-systematic-fake-crypto-wallet-cluster-26-apps-april-2026","published_at":"2026-08-10T23:32:37.207Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Apple App Store — Systematic Fake Crypto Wallet Cluster (26 Apps, April 2026)","sections":[{"content":"Kaspersky researcher Sergey Puzan identified more than 26 malicious iOS applications in the Apple App Store masquerading as legitimate cryptocurrency wallets. The full research report was published on April 20, 2026 via Kaspersky's Securelist blog. The apps were first noticed appearing prominently in Chinese App Store search results in March 2026. The campaign was designated FakeWallet and had been active, based on malware metadata, since at least the fall of 2025. The 26 apps collectively impersonated seven major wallets: MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie. Kaspersky disclosed its findings to Apple, after which all 26 identified applications were removed. Apple did not publicly comment on how the apps had passed its review process.","heading":"Campaign Overview and Discovery","severity":"critical","sources":[{"credibility":2,"name":"FakeWallet cryptostealer propagating via iOS App Store applications — Securelist (Kaspersky)","type":"research","url":"https://securelist.com/fakewallet-cryptostealer-ios-app-store/119474/"},{"credibility":2,"name":"Kaspersky finds 26 fake crypto wallet apps on Apple's App Store — Kaspersky Press Release","type":"research","url":"https://www.kaspersky.com/about/press-releases/kaspersky-finds-26-fake-crypto-wallet-apps-on-apples-app-store-that-can-drain-digital-assets"},{"credibility":2,"name":"26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/04/26-fakewallet-apps-found-on-apple-app.html"},{"credibility":3,"name":"Kaspersky on X — Sergey Puzan video explanation of the attack","type":"social_media","url":"https://x.com/kaspersky/status/2047624170654052505"}]},{"content":"The FakeWallet campaign employed a multi-stage deception strategy to both bypass App Store review and compromise victims. To gain initial App Store approval, the malicious apps were submitted with superficially legitimate stub functionality — games, calculators, or task-planner interfaces — that concealed the malicious payload from automated and human review. Attackers used typosquatting (intentionally misspelled wallet names such as 'LeddgerNew') and cloned logos to appear credible in search results. Once installed, the apps redirected users to browser pages designed to mimic the official App Store UI, prompting the installation of a developer provisioning profile. This enterprise provisioning profile abuse — exploiting Apple's Developer Enterprise Program (available for $299/year) — allowed sideloading of a fully trojanized wallet application to the victim's device without going through the normal App Store channel. The injected malicious dynamic library (.dylib) hooked into legitimate wallet functions. For hot wallets, a compromised viewDidLoad method scanned the screen for mnemonic seed phrases, which were then encrypted using RSA/PKCS #1, Base64-encoded, and exfiltrated via HTTP POST to attacker command-and-control servers. For cold wallet targets, specifically Ledger-themed apps, attackers injected malicious React Native screens displaying fake seed phrase verification windows, with mnemonic autocomplete functionality included to project an appearance of quality. Some variants also incorporated optical character recognition (OCR) to extract seed phrases captured in screenshots on the device's photo roll — a technique previously documented in the related SparkKitty and SparkCat campaigns.","heading":"Attack Tactics and Technical Methods","severity":"critical","sources":[{"credibility":2,"name":"FakeWallet cryptostealer propagating via iOS App Store applications — Securelist (Kaspersky)","type":"research","url":"https://securelist.com/fakewallet-cryptostealer-ios-app-store/119474/"},{"credibility":2,"name":"Phishing crypto-wallet clones in the App Store and other attacks on iOS and macOS crypto owners — Kaspersky Blog","type":"research","url":"https://www.kaspersky.com/blog/ios-macos-fake-crypto-apps/55665/"},{"credibility":2,"name":"Apple's App Store found hosting 'FakeWallet' crypto-stealing apps — CyberInsider","type":"news_article","url":"https://cyberinsider.com/apples-app-store-found-hosting-fakewallet-crypto-stealing-apps/"}]},{"content":"The campaign primarily targeted Chinese iOS users, with nearly all 26 phishing applications made available exclusively to accounts with their Apple region set to China. This geographic focus was deliberate: Chinese App Store policies prohibit or restrict several prominent cryptocurrency wallet applications, creating a gap that fraudulent listings could fill. The absence of official wallet apps from the Chinese storefront meant users seeking MetaMask, Bitpie, imToken, and similar tools had fewer legitimate options to compare against. Despite this regional focus, the malware itself contained no built-in geographic restrictions, meaning victims from outside China could also have been affected if they accessed the apps. Android versions of some trojanized wallets were additionally distributed through phishing websites, extending the campaign beyond the iOS ecosystem.","heading":"Geographic Targeting and Opportunity Exploitation","severity":"high","sources":[{"credibility":2,"name":"26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/04/26-fakewallet-apps-found-on-apple-app.html"},{"credibility":2,"name":"Dozens of Malicious Crypto Apps Land in Apple App Store — Security Boulevard","type":"news_article","url":"https://securityboulevard.com/2026/04/dozens-of-malicious-crypto-apps-land-in-apple-app-store/"},{"credibility":3,"name":"China's Apple App Store infiltrated by crypto-stealing wallet apps — PRSOL","type":"news_article","url":"https://www.prsol.cc/2026/04/27/chinas-apple-app-store-infiltrated-by-crypto-stealing-wallet-apps/"}]},{"content":"Kaspersky attributed the FakeWallet campaign with moderate confidence to the SparkKitty threat actor group. SparkKitty was first documented by Kaspersky in June 2025 and had been active since at least February 2024. The group is assessed with moderate confidence to be operated by Chinese-speaking actors, based on Chinese-language logging messages embedded throughout the malware code, code structure overlaps, and shared infrastructure with the prior SparkCat campaign. Technical indicators linking FakeWallet to SparkKitty include overlapping infected app samples containing both FakeWallet and SparkKitty modules, shared phishing page distribution methodology, and OCR-based credential extraction techniques observed in both campaigns. SparkKitty itself is directly related to SparkCat: Android apps infected with SparkKitty were built using the same framework as SparkCat-infected apps, and debug symbols in SparkKitty's iOS frameworks matched file paths previously observed in SparkCat samples. SparkCat, first uncovered in January 2025, focused on gaining access to cryptocurrency wallets by scanning victims' photo galleries for seed phrase screenshots using OCR. The three campaigns — SparkCat, SparkKitty, and FakeWallet — are assessed by Kaspersky as likely sharing authorship or infrastructure, forming a continuous and evolving threat operation.","heading":"Threat Actor Attribution — SparkKitty","severity":"high","sources":[{"credibility":2,"name":"The new SparkKitty Trojan spy in the App Store and Google Play — Securelist","type":"research","url":"https://securelist.com/sparkkitty-ios-android-malware/116793/"},{"credibility":2,"name":"SparkKitty Malware Found in App Stores Targets Crypto Wallet Seed Phrases — Decrypt","type":"news_article","url":"https://decrypt.co/374450/sparkkitty-malware-mobile-apps-crypto-wallet"},{"credibility":2,"name":"New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/04/new-sparkcat-variant-in-ios-android.html"},{"credibility":2,"name":"FakeWallet cryptostealer propagating via iOS App Store applications — Securelist (Kaspersky)","type":"research","url":"https://securelist.com/fakewallet-cryptostealer-ios-app-store/119474/"}]},{"content":"Concurrent with the FakeWallet cluster disclosure, a separate but thematically related incident involved a fraudulent Ledger Live application distributed through Apple's Mac App Store under the developer account name 'Leva Heal Limited,' an entity with no affiliation to Ledger SAS. This app was active between approximately April 7 and April 13, 2026, a window of roughly one week before Apple removed it on or around April 14, 2026. The app deceived victims into entering their 24-word seed phrases, which the operators then used to drain connected wallets. Blockchain investigator ZachXBT traced the stolen funds across more than 50 suspected victims, with total losses confirmed at approximately $9.5 million. The three largest individual thefts were $3.23 million in USDT (April 9), $2.08 million in USDC (April 11), and $1.95 million in a mix of BTC, ETH, and stETH (April 8). One documented victim, publicly identified only as '@glove,' lost 5.9 BTC representing their entire savings accumulated over a decade. Stolen assets were routed through more than 150 KuCoin deposit addresses and connected to a centralized mixing service identified as 'AudiA6.' KuCoin subsequently froze the implicated accounts until April 20, 2026. Ledger CTO Charles Guillemet publicly stated after the incident that the legitimate Ledger Live application will never request a user's 24-word recovery phrase. It is not publicly known whether the Leva Heal developer account is linked to the SparkKitty operators responsible for the FakeWallet cluster, though both campaigns were active simultaneously.","heading":"Concurrent Incident: Fake Ledger Live on Mac App Store ($9.5M Stolen)","severity":"critical","sources":[{"credibility":2,"name":"Bogus crypto wallet on App Store steals $9.5M — AppleInsider","type":"news_article","url":"https://appleinsider.com/articles/26/04/14/bogus-crypto-wallet-on-app-store-steals-95m"},{"credibility":1,"name":"A fake Ledger app on the Apple App Store just drained $9.5 million in crypto — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/04/14/a-fake-ledger-app-on-the-apple-app-store-just-drained-usd9-5-million-in-crypto"},{"credibility":2,"name":"Apple Removes Fake Crypto Wallet App That Stole $9.5 Million From Mac Users — MacRumors","type":"news_article","url":"https://www.macrumors.com/2026/04/14/apple-mac-app-store-fake-crypto-wallet/"},{"credibility":2,"name":"Fake Ledger app on Mac App Store scams users out of $9.5 million — SC Media","type":"news_article","url":"https://www.scworld.com/brief/fake-ledger-app-on-mac-app-store-scams-users-out-of-9-5-million"},{"credibility":2,"name":"Fake Ledger app on the Apple App Store steals $9.5 million from 50 users — CyberInsider","type":"news_article","url":"https://cyberinsider.com/fake-ledger-app-on-the-apple-app-store-steals-9-5-million-from-50-users/"}]},{"content":"A separate but related incident involves a fraudulent iOS application impersonating Sparrow Wallet, a desktop-only Bitcoin wallet application that has never offered an iOS version. Three plaintiffs — James Ramirez, Christopher Ellis, and Jalen Delgado — filed suit against Apple in the Northern District of California in late July 2026, alleging collective losses of approximately $1.84 million. Ramirez downloaded the fraudulent app on July 25, 2025, losing 7.4 BTC; Ellis installed it on August 3, 2025, losing approximately $840,000; and Delgado downloaded it around May 1, 2025, losing 1.05 BTC. The lawsuit alleges that after Ramirez reported the theft to Apple, the company failed to remove the app, allowing Ellis to be victimized more than a week later. Ramirez and Ellis alleged Apple never responded to their reports. The complaint further notes that legitimate Sparrow Wallet developer Craig Raw had first warned Apple about unauthorized mobile impersonators as early as January 2024, and that when Raw attempted to submit a placeholder iOS listing to warn users, Apple threatened to terminate his developer account for alleged 'dishonest activity' — before reversing that decision in June 2026. Legal claims include fraudulent misrepresentation, fraudulent concealment, failure to warn, and violations of consumer protection laws in California, Louisiana, and Massachusetts. The case highlights a documented multi-year failure by Apple to act on developer-reported impersonation.","heading":"Concurrent Incident: Fake Sparrow Wallet (Lawsuit Filed July 2026)","severity":"high","sources":[{"credibility":1,"name":"Apple kept fake bitcoin wallet on App Store after $875,000 theft report, lawsuit alleges — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/28/apple-kept-fake-bitcoin-wallet-on-app-store-after-usd875-000-theft-report-lawsuit-alleges"},{"credibility":2,"name":"Three customers sue Apple after fake wallet app wipes out their Bitcoin — 9to5Mac","type":"news_article","url":"https://9to5mac.com/2026/07/27/three-customers-sue-apple-after-fake-wallet-app-wipes-out-their-bitcoin/"},{"credibility":2,"name":"Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin — Bleeping Computer","type":"news_article","url":"https://www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-crypto-wallet-app-stealing-18m-in-bitcoin/"},{"credibility":2,"name":"Apple's App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/apples-app-store-security-promise-faces-test-as-fake-crypto-wallets-keep-getting-through/"},{"credibility":2,"name":"Apple sued after users lose $1.8M to fraudulent crypto wallet app on iOS — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/apple-sued-fraudulent-crypto-wallet-app/"}]},{"content":"A fraudulent Wasabi Wallet application also appeared on the Apple App Store in 2026, with at least one confirmed victim reporting a loss of approximately 6 BTC. The app was identified as part of an expanding count of fake wallet listings on Apple's platform — collectively, at least 27 distinct wallet clone listings were identified on the App Store during 2026. Specific developer account details and a precise timeline for the Wasabi Wallet case have not been publicly disclosed.","heading":"Concurrent Incident: Fake Wasabi Wallet","severity":"high","sources":[{"credibility":2,"name":"Fake Wasabi Wallet app steals 6 BTC after landing on Apple Store — Crypto.news","type":"news_article","url":"https://crypto.news/fake-wasabi-wallet-app-steals-6-btc-after-landing-on-apple-store/"}]},{"content":"Apple removed all 26 FakeWallet cluster apps following Kaspersky's disclosure to the company in April 2026. The fake Ledger Live app on the Mac App Store was removed on or around April 14, 2026, approximately two weeks after it became active. Apple has not publicly explained how any of these apps passed its review process, and did not respond to press requests for comment on the FakeWallet cluster or the Ledger Live incident. In the Sparrow Wallet lawsuit, Apple's alleged failure to act on user-reported theft for more than a week is a central claim. Apple's public defense of its marketplace states that its review process prevented more than $9 billion in fraudulent transactions between 2020 and 2024, and that nearly 2 million app submissions are rejected annually. Critics and plaintiffs argue that the curated, closed marketplace model creates an implicit safety guarantee that Apple does not adequately fulfill, particularly for irreversible financial loss scenarios such as seed phrase theft. The repeated pattern of fraudulent wallet apps bypassing review — spanning at least Sparrow Wallet (2024-2025), Trezor wallet (2023), Rabby Wallet (2024), MyEtherWallet (2017), the FakeWallet cluster (2025-2026), and the Ledger Live and Wasabi Wallet incidents (2026) — has prompted legal scrutiny of Apple's review processes.","heading":"Apple's Response and App Store Review Process Failures","severity":"high","sources":[{"credibility":2,"name":"Apple Removes Fake Crypto Wallet App That Stole $9.5 Million From Mac Users — MacRumors","type":"news_article","url":"https://www.macrumors.com/2026/04/14/apple-mac-app-store-fake-crypto-wallet/"},{"credibility":2,"name":"Apple accused of letting fake crypto app steal $1.8 million — Malwarebytes Blog","type":"news_article","url":"https://www.malwarebytes.com/blog/news/2026/07/apple-accused-of-letting-fake-crypto-app-steal-1-8-million"},{"credibility":3,"name":"Apple Faces Lawsuit From Customers Who Fell Victim to a Fake Wallet That Wiped Out Their Bitcoin — iMore / iTechPost","type":"news_article","url":"https://www.itechpost.com/articles/236842/20260728/apple-faces-lawsuit-customers-who-fell-victim-fake-wallet-that-wiped-out-their-bitcoin.htm"},{"credibility":1,"name":"Apple Accused Of Not Stopping Fake Wallet Apps' Crypto Theft — Law360","type":"news_article","url":"https://www.law360.com/articles/2507269/apple-accused-of-not-stopping-fake-wallet-apps-crypto-theft"}]},{"content":"Documented losses across the interconnected 2026 Apple App Store fake wallet incidents are substantial. The fake Ledger Live Mac App Store app (Leva Heal Limited) alone caused confirmed losses of approximately $9.5 million from more than 50 victims in a one-week active window. The fake Sparrow Wallet iOS apps caused documented losses of approximately $1.84 million across three named plaintiffs. The fake Wasabi Wallet caused at least one confirmed loss of approximately 6 BTC. The 26-app FakeWallet iOS cluster reported by Kaspersky does not have a confirmed total loss figure in publicly available sources; victims from the Chinese App Store are the primary targets. Combined confirmed losses from the discrete, verifiable incidents on Apple's platforms in 2026 therefore exceed $11 million, excluding the FakeWallet cluster for which victim financials have not been independently quantified. The mechanism of harm in all cases was seed phrase or recovery phrase theft, enabling attackers to achieve complete and irreversible control of victim wallets across multiple blockchains including Bitcoin, Ethereum, Tron, Solana, and XRP.","heading":"Victim Impact and Documented Losses","severity":"critical","sources":[{"credibility":1,"name":"A fake Ledger app on the Apple App Store just drained $9.5 million in crypto — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/04/14/a-fake-ledger-app-on-the-apple-app-store-just-drained-usd9-5-million-in-crypto"},{"credibility":1,"name":"Apple kept fake bitcoin wallet on App Store after $875,000 theft report, lawsuit alleges — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/28/apple-kept-fake-bitcoin-wallet-on-app-store-after-usd875-000-theft-report-lawsuit-alleges"},{"credibility":2,"name":"Fake Wasabi Wallet app steals 6 BTC after landing on Apple Store — Crypto.news","type":"news_article","url":"https://crypto.news/fake-wasabi-wallet-app-steals-6-btc-after-landing-on-apple-store/"}]},{"content":"The FakeWallet campaign is assessed by Kaspersky as part of a continuing lineage of mobile crypto theft operations. SparkCat, documented in January 2025, pioneered OCR-based photo gallery scanning to extract seed phrase screenshots from victim devices; it was active on both the Apple App Store and Google Play and was linked to Chinese-speaking operators. SparkKitty, documented by Kaspersky in June 2025, evolved the approach with cross-platform (iOS and Android) credential exfiltration using AES-256 encrypted C2 communication and enterprise provisioning profile abuse. FakeWallet, disclosed April 2026, represents a further refinement that directly embeds malicious libraries into App Store-distributed apps rather than relying solely on post-install sideloading. All three campaigns share overlapping infected app samples, code artifacts, and infrastructure, suggesting a single persistent threat actor or tight cluster of affiliated actors. The laundering infrastructure identified in the fake Ledger Live incident — 150+ KuCoin deposit addresses and the AudiA6 mixing service — has not been publicly linked by investigators to the SparkKitty network, and attribution of that specific incident to SparkKitty has not been established. Android distribution vectors for the FakeWallet campaign also used phishing websites to distribute trojanized wallet APKs, indicating infrastructure beyond Apple's ecosystem.","heading":"Connections to Broader Fraud Network","severity":"high","sources":[{"credibility":2,"name":"The new SparkKitty Trojan spy in the App Store and Google Play — Securelist","type":"research","url":"https://securelist.com/sparkkitty-ios-android-malware/116793/"},{"credibility":2,"name":"New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/04/new-sparkcat-variant-in-ios-android.html"},{"credibility":2,"name":"SparkKitty Malware: An Emerging Threat to Mobile Users — Cyberint","type":"research","url":"https://cyberint.com/blog/dark-web/sparkkitty-malware-an-emerging-threat-to-mobile-users/"}]}],"sources_used":[{"credibility":2,"name":"FakeWallet cryptostealer propagating via iOS App Store applications — Securelist (Kaspersky)","type":"research","url":"https://securelist.com/fakewallet-cryptostealer-ios-app-store/119474/"},{"credibility":2,"name":"Kaspersky finds 26 fake crypto wallet apps on Apple's App Store — Kaspersky Press Release","type":"research","url":"https://www.kaspersky.com/about/press-releases/kaspersky-finds-26-fake-crypto-wallet-apps-on-apples-app-store-that-can-drain-digital-assets"},{"credibility":2,"name":"Phishing crypto-wallet clones in the App Store — Kaspersky Blog","type":"research","url":"https://www.kaspersky.com/blog/ios-macos-fake-crypto-apps/55665/"},{"credibility":2,"name":"26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/04/26-fakewallet-apps-found-on-apple-app.html"},{"credibility":1,"name":"A fake Ledger app on the Apple App Store just drained $9.5 million in crypto — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/04/14/a-fake-ledger-app-on-the-apple-app-store-just-drained-usd9-5-million-in-crypto"},{"credibility":1,"name":"Apple kept fake bitcoin wallet on App Store after $875,000 theft report, lawsuit alleges — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/28/apple-kept-fake-bitcoin-wallet-on-app-store-after-usd875-000-theft-report-lawsuit-alleges"},{"credibility":2,"name":"Bogus crypto wallet on App Store steals $9.5M — AppleInsider","type":"news_article","url":"https://appleinsider.com/articles/26/04/14/bogus-crypto-wallet-on-app-store-steals-95m"},{"credibility":2,"name":"Apple Removes Fake Crypto Wallet App That Stole $9.5 Million From Mac Users — MacRumors","type":"news_article","url":"https://www.macrumors.com/2026/04/14/apple-mac-app-store-fake-crypto-wallet/"},{"credibility":2,"name":"Three customers sue Apple after fake wallet app wipes out their Bitcoin — 9to5Mac","type":"news_article","url":"https://9to5mac.com/2026/07/27/three-customers-sue-apple-after-fake-wallet-app-wipes-out-their-bitcoin/"},{"credibility":2,"name":"Apple's App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/apples-app-store-security-promise-faces-test-as-fake-crypto-wallets-keep-getting-through/"},{"credibility":2,"name":"Apple accused of letting fake crypto app steal $1.8 million — Malwarebytes Blog","type":"news_article","url":"https://www.malwarebytes.com/blog/news/2026/07/apple-accused-of-letting-fake-crypto-app-steal-1-8-million"},{"credibility":2,"name":"Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin — Bleeping Computer","type":"news_article","url":"https://www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-crypto-wallet-app-stealing-18m-in-bitcoin/"},{"credibility":1,"name":"Apple Accused Of Not Stopping Fake Wallet Apps' Crypto Theft — Law360","type":"news_article","url":"https://www.law360.com/articles/2507269/apple-accused-of-not-stopping-fake-wallet-apps-crypto-theft"},{"credibility":2,"name":"The new SparkKitty Trojan spy in the App Store and Google Play — Securelist","type":"research","url":"https://securelist.com/sparkkitty-ios-android-malware/116793/"},{"credibility":2,"name":"New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/04/new-sparkcat-variant-in-ios-android.html"},{"credibility":2,"name":"SparkKitty Malware Found in App Stores Targets Crypto Wallet Seed Phrases — Decrypt","type":"news_article","url":"https://decrypt.co/374450/sparkkitty-malware-mobile-apps-crypto-wallet"},{"credibility":2,"name":"SparkKitty Malware: An Emerging Threat to Mobile Users — Cyberint","type":"research","url":"https://cyberint.com/blog/dark-web/sparkkitty-malware-an-emerging-threat-to-mobile-users/"},{"credibility":2,"name":"Apple's App Store found hosting 'FakeWallet' crypto-stealing apps — CyberInsider","type":"news_article","url":"https://cyberinsider.com/apples-app-store-found-hosting-fakewallet-crypto-stealing-apps/"},{"credibility":2,"name":"Fake Ledger app on the Apple App Store steals $9.5 million from 50 users — CyberInsider","type":"news_article","url":"https://cyberinsider.com/fake-ledger-app-on-the-apple-app-store-steals-9-5-million-from-50-users/"},{"credibility":2,"name":"Fake Ledger app on Mac App Store scams users out of $9.5 million — SC Media","type":"news_article","url":"https://www.scworld.com/brief/fake-ledger-app-on-mac-app-store-scams-users-out-of-9-5-million"},{"credibility":2,"name":"Fake Wasabi Wallet app steals 6 BTC after landing on Apple Store — Crypto.news","type":"news_article","url":"https://crypto.news/fake-wasabi-wallet-app-steals-6-btc-after-landing-on-apple-store/"},{"credibility":2,"name":"Dozens of Malicious Crypto Apps Land in Apple App Store — Security Boulevard","type":"news_article","url":"https://securityboulevard.com/2026/04/dozens-of-malicious-crypto-apps-land-in-apple-app-store/"},{"credibility":2,"name":"Apple sued after users lose $1.8M to fraudulent crypto wallet app on iOS — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/apple-sued-fraudulent-crypto-wallet-app/"},{"credibility":2,"name":"Fake Crypto Wallet Apps On Apple's App Store Capable Of Draining Digital Assets — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/04/274865-fake-crypto-wallet-apps-on-apples-app-store-capable-of-draining-digital-assets-report-reveals/"},{"credibility":3,"name":"Apple Sued Over Fake Sparrow Wallet App That Drained $1.8M in Bitcoin — TFTC","type":"news_article","url":"https://www.tftc.io/apple-sued-fake-sparrow-wallet-app-18-million-bitcoin"}],"summary":"Beginning in at least fall 2025 and publicly disclosed in April 2026, a coordinated cluster of 26 fraudulent iOS applications impersonating major cryptocurrency wallets was discovered on Apple's App Store by Kaspersky researchers. The campaign, dubbed FakeWallet and attributed with moderate confidence to the SparkKitty threat actor group, targeted seed phrase theft primarily from Chinese iOS users. The broader pattern of fake wallet apps on Apple's platforms in 2026 resulted in documented losses exceeding $11 million across multiple distinct incidents and triggered civil litigation against Apple.","timeline":[{"date":"2017-01-01","event":"Fake MyEtherWallet app appeared on Apple App Store — among the earliest documented fake crypto wallet incidents on the platform.","source":"9to5Mac / Crypto Briefing (historical reference)","source_url":"https://cryptobriefing.com/apple-sued-fraudulent-crypto-wallet-app/"},{"date":"2023-01-01","event":"Fake Trezor wallet app appeared on Apple App Store, establishing a recurring pattern of impersonation campaigns.","source":"9to5Mac / Crypto Briefing (historical reference)","source_url":"https://cryptobriefing.com/apple-sued-fraudulent-crypto-wallet-app/"},{"date":"2024-01-01","event":"Craig Raw, developer of Sparrow Wallet, first warned Apple about fake iOS Sparrow Wallet apps. Apple failed to remove them promptly. Fake Rabby Wallet also appeared during this period.","source":"CryptoSlate","source_url":"https://cryptoslate.com/apples-app-store-security-promise-faces-test-as-fake-crypto-wallets-keep-getting-through/"},{"date":"2024-06-01","event":"SparkKitty malware first documented by Kaspersky, linked to Chinese-speaking operators. Campaign assessed to have begun as early as February 2024.","source":"Securelist — The new SparkKitty Trojan spy in the App Store and Google Play","source_url":"https://securelist.com/sparkkitty-ios-android-malware/116793/"},{"date":"2025-01-01","event":"SparkCat spyware campaign publicly uncovered; used OCR to scan iOS and Android photo galleries for crypto wallet seed phrase screenshots.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/04/new-sparkcat-variant-in-ios-android.html"},{"date":"2025-05-01","event":"Jalen Delgado downloaded fake Sparrow Wallet iOS app, losing 1.05 BTC (approximately $120,000).","source":"9to5Mac","source_url":"https://9to5mac.com/2026/07/27/three-customers-sue-apple-after-fake-wallet-app-wipes-out-their-bitcoin/"},{"date":"2025-07-25","event":"James Ramirez downloaded fake Sparrow Wallet iOS app, losing 7.4 BTC worth approximately $875,000. Ramirez reported the theft to Apple.","source":"9to5Mac / CoinDesk","source_url":"https://www.coindesk.com/business/2026/07/28/apple-kept-fake-bitcoin-wallet-on-app-store-after-usd875-000-theft-report-lawsuit-alleges"},{"date":"2025-08-03","event":"Christopher Ellis downloaded fake Sparrow Wallet iOS app more than a week after Ramirez's theft report, losing approximately $840,000. Apple had not removed the app or responded to Ramirez.","source":"9to5Mac / CoinDesk","source_url":"https://www.coindesk.com/business/2026/07/28/apple-kept-fake-bitcoin-wallet-on-app-store-after-usd875-000-theft-report-lawsuit-alleges"},{"date":"2025-09-01","event":"FakeWallet campaign assessed to have begun operating on the Apple App Store, based on malware metadata reviewed by Kaspersky.","source":"Kaspersky Press Release","source_url":"https://www.kaspersky.com/about/press-releases/kaspersky-finds-26-fake-crypto-wallet-apps-on-apples-app-store-that-can-drain-digital-assets"},{"date":"2026-03-01","event":"26 FakeWallet cluster apps first noticed appearing prominently in Chinese App Store search results by Kaspersky researchers.","source":"Securelist / The Hacker News","source_url":"https://securelist.com/fakewallet-cryptostealer-ios-app-store/119474/"},{"date":"2026-04-07","event":"Fake Ledger Live app (developer: Leva Heal Limited) on Mac App Store begins active theft campaign. First major victim losses recorded.","source":"CoinDesk / AppleInsider","source_url":"https://www.coindesk.com/business/2026/04/14/a-fake-ledger-app-on-the-apple-app-store-just-drained-usd9-5-million-in-crypto"},{"date":"2026-04-08","event":"Largest single-day losses in Ledger Live incident: one victim loses $1.95 million in BTC, ETH, and stETH.","source":"CoinDesk / AppleInsider","source_url":"https://appleinsider.com/articles/26/04/14/bogus-crypto-wallet-on-app-store-steals-95m"},{"date":"2026-04-09","event":"Second-largest theft in Ledger Live incident: one victim loses $3.23 million in USDT.","source":"CoinDesk / AppleInsider","source_url":"https://appleinsider.com/articles/26/04/14/bogus-crypto-wallet-on-app-store-steals-95m"},{"date":"2026-04-11","event":"Third-largest theft in Ledger Live incident: one victim loses $2.08 million in USDC.","source":"CoinDesk / AppleInsider","source_url":"https://appleinsider.com/articles/26/04/14/bogus-crypto-wallet-on-app-store-steals-95m"},{"date":"2026-04-13","event":"Fake Ledger Live theft campaign ends. ZachXBT begins tracing stolen funds through 150+ KuCoin deposit addresses and AudiA6 mixing service.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/04/14/a-fake-ledger-app-on-the-apple-app-store-just-drained-usd9-5-million-in-crypto"},{"date":"2026-04-14","event":"Apple removes fake Ledger Live app from the Mac App Store. Total losses confirmed at approximately $9.5 million from 50+ victims.","source":"MacRumors / AppleInsider","source_url":"https://www.macrumors.com/2026/04/14/apple-mac-app-store-fake-crypto-wallet/"},{"date":"2026-04-20","event":"Kaspersky publishes full FakeWallet research report by Sergey Puzan on Securelist. All 26 iOS FakeWallet apps reported to Apple. Attribution to SparkKitty stated with moderate confidence.","source":"Securelist / Kaspersky Press Release","source_url":"https://securelist.com/fakewallet-cryptostealer-ios-app-store/119474/"},{"date":"2026-04-20","event":"KuCoin freezes deposit accounts implicated in laundering of stolen Ledger Live funds.","source":"AppleInsider / CyberInsider","source_url":"https://cyberinsider.com/fake-ledger-app-on-the-apple-app-store-steals-9-5-million-from-50-users/"},{"date":"2026-06-01","event":"Apple reverses threatened termination of Sparrow Wallet developer Craig Raw's account, restoring his ability to submit an iOS warning placeholder.","source":"CryptoSlate","source_url":"https://cryptoslate.com/apples-app-store-security-promise-faces-test-as-fake-crypto-wallets-keep-getting-through/"},{"date":"2026-07-24","event":"Three Sparrow Wallet victims file lawsuit against Apple in the Northern District of California, seeking restitution for $1.84 million in combined Bitcoin losses.","source":"MacRumors / CoinDesk / 9to5Mac","source_url":"https://www.macrumors.com/2026/07/25/apple-app-store-fake-bitcoin-wallet-lawsuit/"},{"date":"2026-07-28","event":"CoinDesk reports details of the Sparrow Wallet lawsuit, including allegation that Apple failed to act for over a week after the first $875,000 theft was reported.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/07/28/apple-kept-fake-bitcoin-wallet-on-app-store-after-usd875-000-theft-report-lawsuit-alleges"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 242a468f-8f67-47af-b347-f04a7e6fa773
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.