DefiLlama, one of the most widely used DeFi analytics platforms, pushed back the launch of its own mobile app to first clear out a crop of fake apps impersonating it on Apple’s App Store. The pseudonymous founder, known as 0xngmi, said the team waited deliberately rather than compete for attention against copycats that could put users’ funds at risk.

“We waited ’till all the fake apps were taken down before we launched ours,” the founder said, explaining that shipping DefiLlama’s legitimate app while lookalikes were still live risked users downloading the wrong one and connecting a wallet to it.

A close up of a cell phone with icons on it
Photo by Saradasish Pradhan on Unsplash

Months of Pressure, Then a Fast Takedown

Getting Apple to act wasn’t quick. The DefiLlama team says it pursued the company for months over one particularly malicious clone before Apple removed it — but once the team supplied documented evidence that the fake app had actually drained a user’s crypto wallet, the takedown happened within days. The episode illustrates a recurring complaint from crypto teams: app-store moderation tends to move fastest only after there’s already a victim.

Part of a Bigger Pattern

DefiLlama’s experience fits a broader trend security researchers have been tracking all year. Kaspersky reported in April 2026 that it had found 26 separate “FakeWallet” apps on the App Store impersonating well-known wallets including MetaMask, Ledger, Trust Wallet and imToken, designed to harvest seed phrases and recovery keys and attributed with moderate confidence to a threat group tracked as SparkKitty. Separately, three users sued Apple in July 2026 after losing a combined $1.8 million to a fake Sparrow Wallet app the company had left live on the App Store for months despite earlier warnings — Sparrow Wallet has no legitimate iOS version at all, a detail that should have made the fake easy to catch.

Related: ENS Tokenholders Hand $65M Endowment to New Formal Foundation

Why Crypto Apps Keep Getting Copied

Fake wallet and DeFi apps remain an attractive target because the payout for a successful phishing app is direct access to a victim’s funds, with no bank or card network in between to reverse the transaction. Earlier incidents follow the same script — a fraudulent Curve Finance app in 2024, and a fake Ledger Live app on the Microsoft Store in November 2023 that stole roughly $588,000 across 38 transactions — suggesting the App Store’s review process still struggles to distinguish a convincing clone from the real thing until someone has already lost money and can prove it.