Overview
- DeFiLlama said on Aug. 15 that after months of trademark and impersonation reports it loaded a small test wallet, connected it to a fake iOS app, and let the app drain the funds to collect evidence; Apple removed the listing within days.
- The project delayed its official mobile launch while impersonating apps remained live and now lists a verified iOS app after the fraudulent listing was taken down.
- Reporting and blockchain analysis link the same pattern of cloned apps to other attacks, and earlier coverage tied a fake Rabby Wallet listing to roughly $1.6 million traced in stolen funds.
- Kaspersky threat researchers and multiple teams say attackers use cloned wallet apps to phish seed phrases, reconstruct victims’ wallets, and launder assets across blockchains.
- The case shows that App Store approval is no longer a reliable sign of legitimacy and that users should install apps only from a project’s official site while platforms tighten review, trademark response, and takedown processes.