A fake DeFiLlama app capable of draining cryptocurrency wallets was removed from Apple’s App Store only after the real DeFiLlama team deliberately installed the malicious application, loaded a small test wallet and allowed it to steal the funds as proof of the security threat. DeFiLlama founder 0xngmi said the team had spent months reporting the impersonating application to Apple over trademark violations and impersonation concerns before conducting the test that finally led to its removal.
The incident is particularly concerning because the malicious application wasn’t being distributed through an obscure website or unofficial download. It had made its way onto Apple’s official App Store, where users generally expect applications to have undergone security review. The episode highlights how crypto scammers are increasingly exploiting trusted distribution platforms to make malicious applications appear legitimate.
DeFiLlama Team Deliberately Tested the Fake App
According to 0xngmi, DeFiLlama had been attempting to get the impersonating application removed for months.
The team reported the app to Apple citing trademark violations and concerns that it was falsely presenting itself as an official DeFiLlama product. However, those reports apparently weren’t enough to get the application immediately removed.
DeFiLlama eventually decided to demonstrate that the threat extended beyond simple brand impersonation.
The team created or loaded a small cryptocurrency wallet specifically for testing, downloaded the fake application and interacted with it.
The result was exactly what they expected.
The wallet was drained.
Apple Removed the App Within Days After Funds Were Stolen
After demonstrating that the application could actually steal cryptocurrency, DeFiLlama reported the incident to Apple.
According to 0xngmi, Apple removed the application within days of receiving evidence from the wallet-draining test.
That sequence raises an important question about how malicious crypto applications are handled by major app stores.
The DeFiLlama team says it had already reported the application for months based on impersonation and trademark concerns. Yet demonstrating an actual theft appears to have produced a much faster response.
The Crypto Times said it contacted Apple for comment but had not received a response at the time its report was published.
The Amount Stolen Was Not Disclosed
DeFiLlama did not reveal exactly how much cryptocurrency was stolen during the security test.
The team intentionally used a small test wallet, limiting the amount that could be lost while proving that the application was malicious.
The report also doesn’t provide technical details explaining precisely how the fake application drained the wallet.
That means it isn’t clear from the available information whether the application attempted to steal a recovery phrase, tricked the user into approving a malicious transaction, captured credentials or used another method.
What DeFiLlama demonstrated was the end result — installing and interacting with the impersonating application could result in cryptocurrency being stolen.
DeFiLlama Doesn’t Have an Official Mobile App
The incident is particularly important because users searching for a DeFiLlama application shouldn’t have been looking for one in the first place.
DeFiLlama does not currently offer an official mobile application.
The platform operates primarily through its website, providing analytics covering decentralized finance, total value locked, stablecoins, decentralized exchanges, fees, yields and other onchain activity.
That means an application presenting itself as an official DeFiLlama mobile app should immediately raise suspicion.
This is a common tactic among crypto scammers. Attackers impersonate recognizable companies that don’t necessarily offer official applications, hoping users will assume a professional-looking App Store listing is legitimate.
App Store Approval Doesn’t Guarantee a Crypto App Is Safe
The incident exposes an uncomfortable problem surrounding mobile application security.
Apple maintains an application review process designed to prevent malicious software from reaching iPhone and iPad users.
But no review system is perfect.
Attackers can potentially design applications that appear legitimate during the approval process and activate malicious functionality later, hide dangerous behavior behind specific user interactions or simply exploit gaps in automated and human review.
For cryptocurrency users, the consequences can be particularly severe because blockchain transactions generally cannot be reversed after assets are transferred to an attacker.
A fraudulent banking application might result in suspicious transactions that a financial institution can investigate or potentially reverse.
A malicious crypto wallet can drain assets directly to an attacker-controlled blockchain address.
Crypto Scammers Are Exploiting Trusted Platforms
The fake DeFiLlama incident is part of a broader shift in crypto phishing.
Attackers increasingly aren’t relying solely on obviously suspicious emails or websites.
They are finding ways to place malicious content inside platforms users already trust.
Recent incidents have involved fake applications, sponsored search advertisements, impersonated social-media accounts and fraudulent websites appearing through legitimate online services.
Crypto Times noted that the incident comes amid a broader wave of crypto impersonation attacks targeting users through trusted platforms, including app stores and sponsored search results.
That makes the scam considerably more convincing.
A user may correctly avoid clicking a random link sent through Telegram but feel comfortable downloading an application directly from Apple’s App Store.
Attackers understand that difference in trust.
Crypto Wallet Drainers Remain a Major Threat
Wallet drainers have become one of the most effective tools used by cryptocurrency scammers.
Instead of hacking a blockchain or breaking wallet encryption, attackers frequently attempt to convince users to voluntarily provide the permissions needed to steal their assets.
A malicious application or website might ask someone to connect their wallet and sign what appears to be a normal authentication request.
The transaction can instead grant the attacker permission to transfer tokens.
Other scams attempt to capture recovery phrases or private keys directly.
Once those credentials or permissions are obtained, attackers can move cryptocurrency almost instantly.
Fake Apps Can Be More Dangerous Than Fake Websites
Malicious mobile applications create an additional layer of credibility.
A fake website can often be identified through an unusual domain name.
A fraudulent application downloaded through an official app store may appear considerably more legitimate because users assume the platform has already verified it.
Scammers can strengthen that illusion with copied logos, screenshots, branding, descriptions and interface elementsfrom the legitimate company.
Someone searching for “DeFiLlama” in the App Store could therefore reasonably assume that an application using the company’s name and branding was authentic.
That is precisely why impersonation complaints can become security issues rather than merely trademark disputes.
The Incident Raises Questions About App Store Enforcement
The most significant part of the story may not be that another malicious crypto application existed.
It’s how long DeFiLlama says it took to get it removed.
According to 0xngmi, the team spent months reporting the fake application before eventually proving that it could steal cryptocurrency. Only after the test wallet was drained did the application disappear within days.
That suggests platforms may need faster escalation procedures when financial companies report applications impersonating their brands.
In crypto, waiting until confirmed financial losses occur can be particularly dangerous because the transactions are usually irreversible.
- Sui Gears Up to Launch Web3 Gaming Device, Slated For 2025 Release
- SecondFi Shuts Down After $2.4 Million Cardano Wallet Exploit
- Bybit Uncovers macOS Malware Campaign Targeting Claude Code Developers and Crypto Wallets
- MetaMask Launches Social Login Feature Using Google and Apple Accounts For Wallet Access
- Google Unveils Pixel 10 Lineup With AI Features, New Watch and Earbuds
- TCL’s RayNeo Air 3s Pro AR Glasses Go Global with a $249 Price Tag



















































































































































