Founder of DefiLlama Accuses Apple of Taking Months to Remove Fake App
On August 15, pseudonymous founder 0xngmi announced that DefiLlama has postponed the public release of its mobile app while working to eliminate apps impersonating the DeFi analytics platform from Apple’s App Store.
Summary
- DefiLlama opted to delay its mobile launch until fraudulent App Store listings were taken down, as confirmed by founder 0xngmi.
- Apple removed one impersonating app within days after DefiLlama showcased that it could drain crypto funds.
- The official iPhone app for DefiLlama is now live, with DEFILLAMA LIMITED listed as the provider by Apple.
- Apple’s guidelines strictly forbid app impersonation and unauthorized use of another developer’s brand or product names.
- There have been repeated instances of fake crypto apps appearing on Apple’s store, including recent cases involving Ledger and Sparrow wallets.
The team eventually proved that one fake app could drain a funded crypto wallet before Apple took it down, according to 0xngmi’s post.
According to 0xngmi, DefiLlama had reported the offending application for several months over issues related to trademark infringement and impersonation but had not succeeded in getting it removed. The team then funded a small test wallet, downloaded the fraudulent app, and observed the funds vanish. “App was taken down in days after that,” he mentioned. The specifics of the amount drained from the test wallet were not disclosed.
DefiLlama waited until fake apps were removed
The security issue directly impacted DefiLlama’s product launch. 0xngmi stated that the company “waited ’till all the fake apps were taken down before we launched ours to avoid any user getting scammed.” This timeline reflects DefiLlama’s perspective and has not been independently verified by Apple.
The authentic DefiLlama application is now publicly accessible. The official page indicates that its mobile product is available on both iOS and Android platforms. Apple’s listing refers to the iPhone app as “DefiLlama: DeFi Tracker,” identifies DefiLlama as the developer, and shows DEFILLAMA LIMITED as the provider.
In the meantime, Apple’s App Review guidelines prohibit the creation of applications that impersonate other apps or services. The rules also prevent developers from using another developer’s icon, brand, or product name without permission. Continuous impersonation can result in removal from the Apple Developer Program.
Apple has not publicly responded to 0xngmi’s specific claims in the official documentation reviewed for this report. The company has previously stated that its App Review process evaluates applications for security and safety, reporting that over 320,000 submissions were rejected in 2024 for reasons including copycat applications, spam, or user misrepresentation.
Fake crypto apps have caused documented losses
The DefiLlama issue is not isolated, as there have been other documented instances where counterfeit cryptocurrency apps infiltrated Apple’s marketplace. For example, a fraudulent Ledger Live application drained 5.9 BTC, valued at approximately $420,000, from musician Garrett Dutton back in April. On-chain researcher ZachXBT tracked the stolen Bitcoin to addresses linked with KuCoin.
Apple is also dealing with a U.S. lawsuit involving three users who allege that fake Sparrow Wallet apps led to $1.835 million in Bitcoin losses. These allegations are yet to be proven in court. In that instance, Apple asserted that it removed impersonating applications and banned the associated developer accounts.
In addition, a counterfeit Phantom Wallet application made its way to Apple’s App Store before it was eventually removed following user reports of lost funds.
What happens next
DefiLlama’s official app is now live, and its website offers direct access to the legitimate mobile product. The iOS listing currently shows version 1.0.5, indicating defillama.com as the developer’s website, which provides users with multiple avenues to confirm legitimacy prior to installation.
The founder has not shared details regarding the addresses of the attackers, the amount drained during DefiLlama’s testing phase, or any technical analysis of the malicious application. Such information would be crucial for an independent reconstruction of the wallet drain incident. For users, the most straightforward verified precaution is to access the mobile application through DefiLlama’s official website and to verify the developer and provider listed rather than depending solely on App Store search results.
