A hand reaching for a smartphone on a table, with
Crypto

DefiLlama delayed iOS app launch until Apple removed App Store phishing clones

Founder 0xngmi said one impersonator app came down “in days” after a documented wallet drain.

By Marcus Hale3 min read

DefiLlama held back its mobile app launch while phishing apps impersonating the brand were live on Apple’s App Store, according to founder 0xngmi. The team says Apple moved faster only after DefiLlama documented an active wallet drain tied to one of the fake apps.

DefiLlama delayed the launch of its mobile app until phishing apps impersonating the analytics provider were removed from Apple’s App Store, according to the project’s pseudonymous founder, 0xngmi.

“We waited ‘till all the fake apps were taken down before we launched ours to avoid any user getting scammed,” 0xngmi said in a Saturday post on X.

The practical issue is distribution, not code. A phishing app that ranks for a known brand can sit between a user and the real product, and the first mistake happens before a wallet even opens. Apple was approached for comment on the takedowns and the impersonator apps, but no response was included in the source material.

The Takedown Timeline: ‘Months’ of Attempts, Then a Removal ‘in Days’ After a Wallet Drain

0xngmi described a two-speed enforcement process. DefiLlama spent “months” trying to get at least one malicious impersonator app removed from the App Store before proceeding with its own launch.

That changed after the team downloaded one of the fake apps and documented a small crypto wallet being drained. 0xngmi said Apple removed that malicious app “in days” after the documentation.

The missing details matter for sizing the risk. The exact dates of the takedown requests and removals were not specified beyond “months” and “in days.” The number of DefiLlama-branded impersonator apps was not provided, and the amount drained from the “small wallet” was not disclosed. It is also unclear whether the takedowns were uniform across App Store regions and locales, which is often where clones persist.

This is not a one-off pattern confined to a single brand. Fake apps impersonating major crypto names have previously appeared on Apple’s App Store, including apps impersonating Rabby wallet and Curve Finance in 2024. The broader app-marketplace problem is cross-platform: a fake Ledger Live app on the Microsoft Store in November 2023 resulted in $588,000 stolen across 38 transactions.

What to Monitor Next: Clone Reappearance Risk and App-Store Enforcement Signals

The first signal is whether Apple comments or clarifies how it handles takedowns for crypto impersonator and phishing apps, including what evidence accelerates action and whether repeat offenders are blocked at the developer-account level.

The second is whether DefiLlama-branded clones reappear after the official app is live, particularly through near-match naming, logo reuse, or keyword stuffing that captures search traffic. Copycats tend to iterate faster than enforcement.

The third is whether DefiLlama or 0xngmi publishes more specifics on scope, including how many impersonator apps were involved and whether removals were confirmed across regions. Without that, traders are left guessing whether the risk was a single listing or a broader campaign.

The last is user-reported wallet drains tied to mobile impersonator apps. Fresh incidents would imply the operation is ongoing despite removals, and that the distribution layer remains the easiest on-ramp for theft.

My Read: App Stores Are Still a Live Attack Surface for On-Chain Users

The threshold that matters is not whether an official app exists. It is whether the platform can keep search results clean when a brand becomes a keyword worth stealing. DefiLlama delaying its own launch until “all the fake apps were taken down” reads like a team treating App Store impersonation as near-term user-loss risk, not a theoretical edge case.

The months-versus-“in days” contrast is the tell. If enforcement only accelerates after a documented wallet drain, the incentive is backwards and the counterparty is the user. This matters in practical terms if clone reappearance becomes routine and forces teams to treat app-store distribution as part of their security perimeter, not marketing.

Sources