Three cryptocurrency users have sued Apple, alleging that a fraudulent app distributed through its App Store impersonated Sparrow Wallet and enabled the theft of more than $1.8 million in bitcoin.
The complaint, filed in the U.S. District Court for the Northern District of California, accuses Apple of negligence in operating the App Store and challenges the security assurances attached to its tightly controlled distribution model. The allegations have not been proven, and Apple has not been found liable.
TechCrunch reported that plaintiffs James Ramirez, Christopher Ellis and Jalen Delgado say they downloaded the fraudulent app and collectively lost more than $1.8 million. According to the report’s account of the complaint, Ramirez alleges a loss of about $875,000, Ellis about $840,000 and Delgado roughly $120,000.
An impostor inside a trusted distribution channel
The app used the name Sparrow Wallet, but the legitimate Sparrow Bitcoin wallet was not available for iPhone. Sparrow’s official download page identifies its software as a desktop application and offers builds for macOS, Windows and Linux, not iOS.
That distinction is central to the case. Users did not obtain an unknown wallet from an unofficial download site; according to the complaint, they encountered an impostor in Apple’s own marketplace. PaymentsJournal reported that the downloads occurred between May and August 2025 and that users were prompted to enter wallet recovery phrases. The plaintiffs allege that the exposed recovery credentials allowed criminals to access their wallets and remove the funds.
Recovery phrases function as control credentials for self-custodied cryptocurrency. Anyone who obtains one can generally recreate the wallet and authorize transfers without help from a bank, card network or conventional account-recovery desk. That makes impersonation at the software-distribution layer particularly dangerous: once the credential is surrendered and funds move on-chain, a platform’s later removal of the app may not restore the victim’s assets.
Apple’s review claims face a concrete test
Apple publicly describes the App Store as a safe and trusted marketplace and says it reviews submissions and removes malicious developer accounts. In a May 2025 fraud analysis, the company said it rejected more than 320,000 app submissions in 2024 because they copied other apps, were spam or otherwise misled users. Apple also said it rejected more than 43,000 submissions containing hidden or undocumented features.
The lawsuit does not show that Apple lacks review controls. It instead raises a narrower accountability question: whether those controls were reasonably designed and operated for an impersonation risk that was foreseeable, and whether Apple acted adequately after warnings or reports. PaymentsJournal said the complaint alleges fake Sparrow Wallet apps remained available after reports and that Sparrow developer Craig Raw had warned Apple about impostors as early as January 2024. Those remain plaintiffs’ allegations rather than judicial findings.
Apple declined to comment to TechCrunch on the litigation itself. The company told the publication that apps impersonating others violate its guidelines, that it acts swiftly to remove them and that no Sparrow Wallet copycats were then available in the App Store.
Why the case matters to payment and wallet operators
For payment providers, the dispute illustrates that fraud controls cannot stop at transaction authorization. In self-custodied products, software authenticity, developer verification, brand monitoring and recovery-credential education can determine whether the person authorizing a transfer is the legitimate holder or a criminal operating with stolen credentials.
App marketplaces occupy a critical control point because they approve the software through which users create, restore and operate wallets. Relevant safeguards include verifying the legal and technical identity of wallet publishers, detecting cloned names and branding, responding consistently to developer and user reports, preserving evidence after removal, and warning users when a popular financial product has no official mobile version.
Wallet developers also have a role. Official download pages should state supported platforms prominently, publish verifiable release signatures, monitor marketplaces for impersonators and maintain clear channels for reporting fakes. Exchanges and other services that receive assets linked to reported thefts need escalation procedures that can preserve records and, where legally permitted, restrict onward movement.
The litigation is at an early stage. The plaintiffs are seeking a jury trial, recovery of their alleged losses, other damages and warnings about App Store risks, TechCrunch reported. Whether Apple had a legal duty to prevent the particular losses, whether its response was reasonable and how the alleged thefts are causally connected to its review process will be questions for the court, not conclusions established by the filing.
Whatever the outcome, the case puts a measurable incident behind a broader industry concern. A curated marketplace can reduce software-distribution risk, but the presence of a review gate can also increase user reliance on the marketplace’s trust signals. For financial apps, controls should therefore be evaluated not only by how many bad submissions are rejected, but by how quickly convincing impersonators are detected, removed and prevented from returning.