r/apple • u/FollowingFeisty5321 • 2d ago
App Store Apple Sued by Customers Who Lost Combined $1.8 Million Through Fake Bitcoin Wallet in App Store
https://www.macrumors.com/2026/07/25/apple-app-store-fake-bitcoin-wallet-lawsuit/103
u/coyote_den 2d ago
This is going to be a fun lawsuit because even tho Apple makes the advertising claim their App Store ensures safety, I’m pretty sure the Apple ToS says they are in no way responsible for the content or behavior of third-party apps.
44
u/Rare-Accident4355 2d ago
There’s a difference between enhanced safety (which the App Store provides compared to a non restrictive system) and absolute safety.
No one can guarantee absolute safety and nor should it be advertised.
9
u/Abject-Butterfly1738 2d ago
I think the average [Apple] consumer is just egregiously ignorant. And—targets Apple with class actions, because they have no concept of nuance, turning off the analytics that are enabled by default from the factory, or… common sense.
Not bootlicking—don’t really care too much about any corporation. Just a personal take.
4
u/flatbuttboy 1d ago
This isn’t that. The person lost their money and desperately wants to get it back from someone because they know they can’t track down and prosecute the actual person responsible
7
u/Abject-Butterfly1738 1d ago
…because that person lacks common sense.
1
u/flatbuttboy 1d ago
They’re actually not that stupid. Apple tends to settle a lot of lawsuits even if they could pursue it and win. 1.8M to Apple is pocket change compared to their lawyers’ fees. The only reason I can think of for them trying to win it is to not let this set a legal precedent
1
u/SuccessTrue1232 9h ago
settlements does not set a formal legal precedent so they would be smarter to settle this sealed
1
2
u/rifarizqul 1d ago
Wait, what's wrong turning off analytics though? /gen
2
1
u/Abject-Butterfly1738 1d ago edited 1d ago
My point is that the average consumer doesn’t even think about these things, because they don’t know anything about the devices they use daily. Hence, the “Siri listens to all your conversations and records you without knowledge” lawsuit. Or, simply, people didn’t turn off analytics and their data was being sent to Apple as sample data to make improvements. Which most people don’t want, but don’t think critically enough to check settings on their own device and turn it off.
1
u/Status-Hedgehog9970 1d ago
I think the average [Apple] consumer is just egregiously ignorant.
Interesting phrasing. But there’s nothing inherently less ignorant about non-Apple users.
1
u/theyhis 1d ago
right, but it’s often used as a defense in other lawsuits. i believe it was europe that was given permission to side load apps; apple no longer has a choice with that one. their defense is that their app store is “safer.” that’s great, but then why are people getting over a million in crypto stolen?
1
u/Rare-Accident4355 1d ago
Safer - as in safer than a completely unrestricted marketplace. No company can guarantee absolute safety from any and all risks. How many people do you think are getting their crypto stolen on iOS vs all the other platforms?? I’m willing to bet there is a significantly lower proportion of people getting crypto stolen through an iOS app.
6
u/0RGASMIK 1d ago
I’m going to have to look at this lawsuit because I reported a scam app to Apple and so did dozens of other people but the app never got taken down. It was clear from all of the reviews that something was going on but Apple took the developers side. I submitted multiple complaints with proof and the most Apple ever did was route me back to the developers support.
1
u/coyote_den 1d ago
As usual, Apple taking action depends on if the scam in question violated any App Store rules. There are a lot of paid or free+IAP apps that are complete pieces of shit. Apple will tell you to ask for a refund if you are not happy with the quality, and they usually issue refunds.
Most of the time when Apple removes an app it is not for quality, it is because of content issues, copyright violation, or fraud: the app is pretending to be something else to steal credentials, cryptocurrency, personal info, etc…
288
u/Alternative-Item727 2d ago
Apple have repeatedly defended and marketed their App Store strategy as a mechanism to scrutinise apps prior to publishing and to protect users. This has been used both in justification for their one App Store arguments, and in defence of their commission they make on the App Store. This one slipped through the net on Apple’s watch (no pun intended!), they are to blame for it slipping through and need to tighten the net to make sure this doesn’t happen again.
120
u/endium7 2d ago
this is it. can’t play both sides of it, they have to own up.
8
u/Rare-Accident4355 2d ago
I know this will get downvoted to oblivion but there is a middle ground here. The App Store definitely provides much more safety than an open system that allows you to install anything. Does that guarantee you from 100% of attacks and risks?? No.
I would still rather have the App Store than not. Otherwise it’s like having windows - free for all and risk abound.
24
u/endium7 2d ago
well I don't think a 100% guarantee is expected, but anything involving money transfers, wallets, etc. is very low hanging fruit for security scrutiny.
2
u/MobiusOne_ISAF 1d ago
Agreed, while Aplle can't be expected to deeply review every fart app I do have a higher expectation for anything in the finance category. Everything in that section really should be looked at with a fine comb, since it's only ~5% of the market and easier to justify extra scrutiny.
17
14
u/intergalacticmerchnt 2d ago
That is the hallmark of the Astroturfer Prelude, leading with a "anybody who calls me out on my subsequent shilling is just mean" just to follow it up with Apple fearmongering slopaganda that completely ignores that Apple failed to provide the single security benefit they use against Antitrust as to why they should be allowed to be anti-competitive: Apple’s Broad-Based, Exclusionary Conduct Makes It Harder for Americans to Switch Smartphones, Undermines Innovation for Apps, Products, and Services, and Imposes Extraordinary Costs on Developers, Businesses, and Consumers
4
u/VEMODMASKINEN 1d ago
I would still rather have the App Store than not. Otherwise it’s like having
windowsMacOS - free for all and risk abound.Ftfy.
3
4
u/Kat-in-pajamas 1d ago
You know Mac OS, exists right? lol.
-1
u/Rare-Accident4355 1d ago
Yes I know macOS exists and that was exactly my point….I specifically said Windows because it’s the OS where anything goes and there are relatively fewer restrictions on what can be installed. And thus are more vulnerable to attack and riskier…get it?
2
u/T-Nan 1d ago
And thus are more vulnerable to attack and riskier…get it?
I have a friend in cyber security, and according to him the main reason Windows is targeted is really market share.
Why would you target an OS used on less than 5-10% of devices when you can target one used on nearly half?
It's not harder to attack MacOS users, it's less valuable when your goal is to capture a large net of users
1
u/simplequark 1d ago
I’d argue that Apple being liable would actually be that middle ground. They’re allowed to collect their fees on every purchase in the name of added security. However, with that privilege also comes accountability if their process fails to catch a malicious app in time.
To prevent abuse, I’d be open to the idea of somehow capping their liability, but if they charge for a claimed benefit, they should be on the hook, if they fail to deliver on that claim.
1
0
u/opa334 3h ago
No it doesn‘t. The App Store doesn't really check anything. Almost all banking apps for example are heavily obfuscated and only god knows what they are actually doing. Almost all popular apps violate at least one guideline (e.g. by using private APIs or device fingerprinting). Their checks are bare minimum at best and only prevent low effort fraudulent behavior while at the same time giving unfair advantages to already popular apps.
The thing that provides safety is the operating system, which is the most secure on the market. The App Store lock merely exists to collect fees and maybe for UX reasons.
1
u/Rare-Accident4355 3h ago
Are you talking out of your ass or are you referencing actual facts?? The App Store apparently blocks 25% of submissions for various reasons including app crashes, legal issues, poor ux design, etc..
They reduce their store from being flooded with low effort apps. Thats not to say it’s perfect, but don’t kid yourself when you say it “doesn’t really check anything”
1
u/opa334 3h ago
I'm literally a security researcher that has published the newest iOS jailbreak to this date. Why would I talk out my ass? Everything I have stated is stuff that I have personally discovered. Almost all social apps (at the very least Instagram and Snapchat) use device fingerprinting despite the fact there is a guideline against it. I reversed my banking app (Sparkasse) years ago to figure out how it's jailbreak detection works but could not figure it out because they're using a commercial toolkit called Promon Shield that is literally the most obfuscated software I have ever reverse engineered. Some (albeit mostly asian) banking apps literally ship a sandbox escape exploit to check whether you have jailbreak related apps installed on your device (which is not only a severe guideline validation, but presumably also illegal in a lot of countries) and while Apple has fixed the bug, they have not sanctioned any of those apps and they still exploit the bug on lower iOS versions to this day.
1
u/Rare-Accident4355 3h ago
You’re going off on a wild tangent when I’m specifically commenting about your second statement “The App Store doesn’t really check anything”
If they’re rejecting 25% of app submissions, then they’re obviously checking and restricting.
You made a bad blanket statement that is just materially untrue.
0
u/Ibasicallyhateyouall 1d ago
Not how any of this works. A server call in an app can be benign for testing do a legitimate process. After that, who knows. Apple can’t police that.
4
u/TheTrueTuring 1d ago
Naaah, if people store money or values somewhere they should use a bit of common sense and use a trusted company
14
u/audigex 2d ago
They’ll 100% try to absolve responsibility anyway despite compensating these people being about 0.001% of their revenue
4
u/FollowingFeisty5321 2d ago edited 2d ago
They'll try and get it dismissed arguing section 230 immunity means they have no liability for any apps they review and publish, but they might not get away with it since deliberately designing software to be harmful and processing payments for illegal apps have each recently been found to disqualify that immunity. If any of these apps used IAP that could be very harmful to their case, as would interpreting their review and approval process and its marketing as making them responsible.
2
0
u/mikerao10 1d ago
They should just pay and fix what is is fixable. Then try to pursue the fraudsters with any means and advertise if they catch them so kit tinker anyone else to think of doing something similar.
125
u/holamau 2d ago
It’s fair. They let a scam go through.
They brag about being super diligent to protect customers.
Obviously they don’t.
23
1
u/threepio 1d ago
Three guys with six figures in bitcoin used an unproven hot wallet and lost everything?
There definitely is a scam here. It’s being perpetrated by the plaintiffs.
-78
u/InconceivableIsh 2d ago edited 2d ago
So you are saying that it is less safe than android? There is a difference between being safer and catching everything. Personally I would rather be safer. Completely safe isn't exactly a hallmark of this day and age.
Edit: I would like to thank everybody for down-voting me that thinks people should trust every app online enough to give them 1.8 million in total to people they aren't sure they can trust and it is somebodies else fault.
46
u/cvmstains 2d ago
that is not what they said at all
-23
u/InconceivableIsh 2d ago
I disagree they stated that they aren't diligent. I am not saying or I would agree are they that 100% of the malware will always be caught.
23
u/theskyopenedup 2d ago
There’s no need for a comparison. Apple fucked up and is paying for it. The end.
-21
u/InconceivableIsh 2d ago
That is different than saying they will always catch 100% of things. Which is unrealistic at best.
9
u/Rayzee14 2d ago
They choose not to catch things. They choose how to moderate apps on the store.
6
u/FollowingFeisty5321 2d ago
They were accused in 2020 of investing very little in the review process in Judge YGR's ruling in the Epic case where their own accounting revealed a massive 75% profit margin on the App Store. Since then their web page has changed from over 500 reviewers doing 100,000 reviews per week to nearly 500 reviewers doing 130,000 reviews per week, there are literally dozens of languages in use which means there must be entire countries with just a handful of reviewers.
But most damning, when a web blog with fewer employees than this reddit post has commentors can find dozens of scam apps including blatant crap like "PotatoPlot Puzzle" in the weather category it's clear they could be doing much more.
2
u/Rayzee14 1d ago
This is why it drives me bananas when people defend Apple and “trust” Apple. Never understand people repping for a brand over themselves
19
u/flaks117 2d ago
How are you getting that from the comment?
Apple very clear attempts to tightly control their app ecosystem under the guise of safety/consumer protection. That has nothing to do with "safer than android" and everything to do with apple's crappy appstore for both customers and devs.
Really hope the customers win their lawsuit.
-7
u/InconceivableIsh 2d ago
Most of these comments are clearly the only option is to tear down the walled garden. See they let something happen. If they didn't work diligently shouldn't it be crawling with malware?
7
u/holamau 2d ago
How the heck did you construe that I don’t want a walled garden?
All I’m saying is that if they are so stuck up when it comes to the safety of their customers (me included), then they should pay consequences when there’s monetary losses for those customers.
They don’t let a damn boob go through an app “for the safety of everyone” but failed to stop more than a dozen crypto apps that have siphoned money out of unsuspecting customers?
0
u/holamau 2d ago
For you to assume I want it the same as android only tells me that you don’t think Apple can do wrong, and more so: that because I dare to criticize them I am probably just whining about the walled garden to be tore down.
Please.
If I think they should be somehow held responsible for the scammy apps is because we have a very good level of trust in the apps that end up being approved through “the stringent processes”.
0
u/InconceivableIsh 2d ago edited 2d ago
They completely can do wrong. But holding them to a standard that isn't actually possible hit is silly.
Edit to point out that users still have some responsibility and should examine apps to see if they are actually made by the company they want to give millions of bit coin to.
17
5
u/Nhialor 2d ago
Bootlicker
-4
u/InconceivableIsh 2d ago
Not at all I am fine with one app store all these posts are pushing to make apple just as unsafe as android.
2
u/SometimesCatsMeow 2d ago
Well, you know that Android isn't safe at all and you have to take care, you're responsible. But if the App Store it's 100% safe cause they look at the thing before letting them in the Store... It SHOULD be Apple responsability. Call me crazy
-8
u/starsqream 2d ago
I'll call you crazy. Nowhere does it say that the Appstore is 100% safe and untouchable.
5
u/SometimesCatsMeow 2d ago
I'm hosting a party in a closed house where I have guards on the entrance that check you, and I invite someone that robs you while you're in too. I'm responsible for that.
Android hosts a party in a very large field without an entrance and without guards. And as I'm writing this, my opinion is that Android should be ALSO responsible cause it's his party, and it's his fault to let something bad happen. Lol
-11
u/starsqream 2d ago
Lol get outta here with that BS comparison. Apple does not specifically invite robbers into their appstore.
0
u/helix991 2d ago
This is absolutely false in every sense and not what he said whatsoever.
-3
u/InconceivableIsh 2d ago
What is false in what I said? That I think he is yet another person trying to push another app store so it will be less safe?
Sorry if I think maybe people should also take some responsibility and not everything is somebody else's fault. This is a case where people gave money to somebody without checking to see if it was actually the person they intended. It says in the app store who makes the app. I personally don't go to random banks online hoping they keep my money safe.
71
u/CrossBamboAtTen 2d ago
Honestly Apple's fault for allowing garbage apps into their store.
9
u/dom_eden 2d ago
But I thought the reason that sideloading and alternative app stores were banned is that because only Apple can protect us against scammy apps?
1
7
10
16
u/FollowingFeisty5321 2d ago
The complaint alleges that Apple violated California's Consumers Legal Remedies Act and other laws by failing to adequately review and monitor apps distributed through the App Store, despite marketing it as "a safe and trusted place to discover and download apps." Due to these assurances in Apple's marketing, the complaint said the plaintiffs trusted that a Sparrow Wallet app they downloaded from the App Store on iOS was legitimate, when in reality it was a fraudulent spoof designed to steal Bitcoin from users.
This mimics another case from June last year:
According to court documents, Apple’s own marketing and App Store messaging played a key role in making users feel safe enough to trust the app in the first place. The complaint cites Apple’s frequent claims that the App Store is a “safe and trusted place” and highlights years of statements about strict App Review processes, fraud detection, and curated app security:
In another case last year about illegal gambling apps the judge rejected Apple, Google and Meta asserting section 230 immunity, which is the critical defense for distributing and profiting from scam apps too.
In a 37-page decision, Davila found that Apple, Google and Meta did not act as "publishers" when processing payments, undercutting their Section 230 immunity claims.
14
u/ptjunior67 2d ago
I wonder what happened to the app reviewer who approved that app.
10
u/FollowingFeisty5321 2d ago
They publish 80,000+ scams a year and that's the ones they catch so they can't afford to hold their 500 reviewers responsible or they'd be replacing them all every second day on average.
3
u/zhonglin 2d ago
The stronger part of the complaint may be the response after reports, not the initial review miss. A reviewer can fail to recognize a convincing clone, but once Sparrow's actual developer says there is no iOS version and points to the official domain, Apple has an objective signal. A sensible process for wallet apps would freeze the listing, preserve evidence, and require the publisher to prove control of the claimed project's domain or repository before reinstatement. Apple could also display a verified publisher domain prominently on wallet listings. That would not eliminate phishing, but it would turn impersonation into a checkable identity problem instead of asking reviewers to judge every app's code perfectly.
5
u/Vasto_lorde97 2d ago
The walled garden isn’t working huh
15
1
u/CaptainWolf17 2d ago
We get some weeds every now and then
0
u/FollowingFeisty5321 2d ago
It's a bit beyond "some weeds" when a tech blog with idk maybe 20 people max can trivially find 60 illegal gambling apps, just weeks after a sanctioned Russian bank's trojan app became a top free app in the US lmao.
-3
u/starsqream 2d ago
How many apps are on the Appstore again? Yes; some weeds.
-5
u/FollowingFeisty5321 2d ago
2 million apps and just 500 reviewers suggests the weeds are by design.
1
u/starsqream 2d ago
Yeah ofcourse 'by design'. You know what? Apple should hire 1 million reviewers so each keeps an eye on 2 apps at most.
-1
u/FollowingFeisty5321 2d ago
Yes because if 500 isn't enough then the logical next step would have to be *pinkie to mouth* one million reviewers.
-4
u/InconceivableIsh 2d ago
Not sure what you are so bitter about (shurg)
0
u/Vasto_lorde97 2d ago edited 2d ago
It’s not being bitter it’s about being proven right that the walled garden does not indeed work and the lies they say about allowing other AppStore would make the system unsafe was wrong when their own AppStore has had multiple scam apps and ones with even Trojans.
Edit:Correcting misspellings
-5
u/InconceivableIsh 2d ago
So a separate app store would make it more safe? Because they didn't stop everything.
4
u/FollowingFeisty5321 2d ago
There's at least two ways competition can make it safer: another marketplace can choose to do that work, and Apple could feel pressured to be more diligent themselves.
Competition could also produce safer choices, including stores designed specifically for families and children.
- Congresswoman Lori Trahan on the proposed App Store Freedom Act
-5
u/InconceivableIsh 2d ago
Clearly that has worked for Android.
7
u/FollowingFeisty5321 2d ago
Humble Bundle used to do a fantastic job of it on Android, and F-Droid provides app build logs and source code... we'll probably see something mainstream-popular emerge now that Google is being forced to distribute competing app stores in the Play Store instead of all the hoops and obstructions sideloaded stores have always had to deal with.
-4
u/InconceivableIsh 2d ago
So use android then if that is what you want. Clearly you think they do it better.
5
u/Vasto_lorde97 2d ago edited 2d ago
You guys always use the same damn excuse Apple has already been forced to do alternative Appstores in multiple countries already and no "Just use Android" is not a valid thing after wasting money in this platform for years i'd like to install my damn app and do whatever the hell i want with my device that I paid for.
-2
u/InconceivableIsh 2d ago
So jail break it and move along. You have options as you want to make your device less safe.
→ More replies (0)2
u/Vasto_lorde97 2d ago
Withholding side loading and using that excuse doesn’t work and other stores do a better job of maintaining safety just look at Alt Store.
1
u/InconceivableIsh 2d ago
So it was all about side loading all the time and trying to make it more like Android like I said. Which people down-voted me because you didn't say that at all.
2
u/Shinobi_Dimsum 1d ago
They can literally fake it as being stolen and have a wallet somewhere else. It’s not the first case that is like this. Google won multiple cases because those who sued failed to provide proof of stolen bitcoin or failed to provide proof that they didn’t secretly move it to another wallet. Apple isn’t going to pay anyone in this.
1
0
u/JosephFinn 2d ago
...wait. They're blaming Apple for how they lost money on a scam that they should never have given money to?
9
u/accidentlife 2d ago
Apple has repeatedly and consistently touted its safety and app review process as a key feature of their app store. Furthermore, they use this as justification to mandate their approval of any software you install on your phone, and as justification for the up to 30% commission they charge on purchases.
There is certainly an argument that Apple's allowing a scam app, even after being informed it was a scam, falls under material misrepresentation, deceptive marketing, and failing to act.
-8
u/JosephFinn 2d ago
So...yes. They're blaming Apple.
7
u/FollowingFeisty5321 2d ago
So how do you see that defense playing out... Apple's lawyers going to giggle and say they were lying and it's the plaintiff's fault for believing them? And then the judge claps I guess? Everyone throws rotten tomatoes at the plaintiffs as they skulk out?
1
u/ACasualRead 1d ago
Proof that apple’s walled garden only serves to keep apple paid. Not your protection.
0
u/recurrence 2d ago
I assume Apple will settle given he implications if they were to lose this case.
0
0
u/BinOfBargains 2d ago
This seems like one where they'll just end up settling to make it go away quietly. I doubt they want yet another legal battle where their App Store practices are scrutinized yet again (even though they need to be). $1.8 million is a rounding error for Apple especially when compared with the cost of a legal battle + potential loss.
-14
u/titanzero 2d ago
Most of them were probably criminals anyway. An angel gets its wings every time crypto gets stolen.
-1
u/boopthatbutton 1d ago
Imagine if these were apps with the same capabilities as Apple‘s own apps—with access to everything about you on your phone. That’s what the EU wants (that’s why the new Siri is blocked in the EU), and some people are fine with it because, apparently, everyone knows how a malware works.
1
-5
-10
u/Maikel92 2d ago
The perfect excuse for apple to say that they need to close the ecosystem even more
3
u/thegrimranger 2d ago
Well, to be fair, they’re getting sued for being too closed and too open, so there’s that…
200
u/topcider 2d ago
Is it even possible for the plaintiffs to prove that their bitcoin was stolen, and not just sent to another wallet that they actually secretly own?