A fake DeFiLlama app capable of draining cryptocy wallets was removed from Apple’s App Store only after the real DeFiLlama team deliberately installed the malicious application, loaded a small test wallet and allowed it to steal the funds as proof of the security threat. DeFiLlama founder 0xngmi said the team had spent months reporting the impersonating application to Apple over trademark violations and impersonation concerns before conducting the test that finally led to its removal.
The incident is particularly concerning because the malicious application wasn’t being distributed through an obscure website or unofficial download. It had made its way onto Apple’s official App Store, where users generally expect applications to have undergone security review. The episode highlights how crypto scammers are increasingly exploiting trusted distribution platforms to make malicious applications appear legitimate.
According to 0xngmi, DeFiLlama had been attempting to get the impersonating application removed for months.
The team reported the app to Apple citing trademark violations and concerns that it was falsely presenting itself as an official DeFiLlama product. However, those reports apparently weren’t enough to get the application immediately removed.
DeFiLlama eventually decided to demonstrate that the threat extended beyond simple brand impersonation.
The team created or loaded a small cryptocy wallet specifically for testing, downloaded the fake application and interacted with it.
The result was exactly what they expected.
The wallet was drained.
After demonstrating that the application could actually steal cryptocy, DeFiLlama reported the incident to Apple.
According to 0xngmi, Apple removed the application within days of receiving evidence from the wallet-draining test.
That sequence raises an important question about how malicious crypto applications are handled by major app stores.
The DeFiLlama team says it had already reported the application for months based on impersonation and trademark concerns. Yet demonstrating an actual theft appears to have produced a much faster response.
The Crypto Times said it contacted Apple for comment but had not received a response at the time its report was published.
DeFiLlama did not reveal exactly how much cryptocy was stolen during the security test.
The team intentionally used a small test wallet, limiting the amount that could be lost while proving that the application was malicious.
The report also doesn’t provide technical details explaining precisely how the fake application drained the wallet.
That means it isn’t clear from the available information whether the application attempted to steal a recovery phrase, tricked the user into approving a malicious transaction, captured credentials or used another method.
What DeFiLlama demonstrated was the end result — installing and interacting with the impersonating application could result in cryptocy being stolen.
The incident is particularly important because users searching for a DeFiLlama application shouldn’t have been looking for one in the first place.
DeFiLlama does not currently offer an official mobile application.
The platform operates primarily through its website, providing analytics covering decentralized finance, total value locked, stablecoins, decentralized exchanges, fees, yields and other onchain activity.
That means an application presenting itself as an official DeFiLlama mobile app should immediately raise suspicion.
This is a common tactic among crypto scammers. Attackers impersonate recognizable companies that don’t necessarily offer official applications, hoping users will assume a professional-looking App Store listing is legitimate.
The incident exposes an uncomfortable problem surrounding mobile application security.
Apple maintains an application review process designed to prevent malicious software from reaching iPhone and iPad users.
But no review system is perfect.
Attackers can potentially design applications that appear legitimate during the approval process and activate malicious functionality later, hide dangerous behavior behind specific user interactions or simply exploit gaps in automated and human review.
For cryptocy users, the consequences can be particularly severe because blockchain transactions generally cannot be reversed after assets are transferred to an attacker.
A fraudulent banking application might result in suspicious transactions that a financial institution can investigate or potentially reverse.
A malicious crypto wallet can drain assets directly to an attacker-controlled blockchain address.
The fake DeFiLlama incident is part of a broader shift in crypto phishing.
Attackers increasingly aren’t relying solely on obviously suspicious emails or websites.
They are finding ways to place malicious content inside platforms users already trust.
Recent incidents have involved fake applications, sponsored search advertisements, impersonated social-media accounts and fraudulent websites appearing through legitimate online services.
Crypto Times noted that the incident comes amid a broader wave of crypto impersonation attacks targeting users through trusted platforms, including app stores and sponsored search results.
That makes the scam considerably more convincing.
A user may correctly avoid clicking a random link sent through Telegram but feel comfortable downloading an application directly from Apple’s App Store.
Attackers understand that difference in trust.
Wallet drainers have become one of the most effective tools used by cryptocy scammers.
Instead of hacking a blockchain or breaking wallet encryption, attackers frequently attempt to convince users to voluntarily provide the permissions needed to steal their assets.
A malicious application or website might ask someone to connect their wallet and sign what appears to be a normal authentication request.
The transaction can instead grant the attacker permission to transfer tokens.
Other scams attempt to capture recovery phrases or private keys directly.
Once those credentials or permissions are obtained, attackers can move cryptocy almost instantly.
Malicious mobile applications create an additional layer of credibility.
A fake website can often be identified through an unusual domain name.
A fraudulent application downloaded through an official app store may appear considerably more legitimate because users assume the platform has already verified it.
Scammers can strengthen that illusion with copied logos, screenshots, branding, descriptions and interface elementsfrom the legitimate company.
Someone searching for “DeFiLlama” in the App Store could therefore reasonably assume that an application using the company’s name and branding was authentic.
That is precisely why impersonation complaints can become security issues rather than merely trademark disputes.
The most significant part of the story may not be that another malicious crypto application existed.
It’s how long DeFiLlama says it took to get it removed.
According to 0xngmi, the team spent months reporting the fake application before eventually proving that it could steal cryptocy. Only after the test wallet was drained did the application disappear within days.
That suggests platforms may need faster escalation procedures when financial companies report applications impersonating their brands.
In crypto, waiting until confirmed financial losses occur can be particularly dangerous because the transactions are usually irreversible.
MapleStory Universe is putting artificial intelligence in the hands of game creators with the launch…
Kalshi is making another major move beyond prediction markets, filing with the Commodity Futures Trading…
Coinbase is bringing high-leverage decentralized derivatives directly into its Base App through an integration with…
Hong Kong's first regulated Hong Kong dollar stablecoin is moving beyond testing and into real-world…
Cybersecurity researchers at Rapid7 have uncovered a sophisticated crypto fraud operation that used nearly 885,000…
The highly anticipated launch of $CLOCKIN on StonkBroker’s Stonk Launcher has come under scrutiny after…