HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Apple’s App Store Hosted Fake Crypto Wallet That Stole $1.8 Million from Users

A lawsuit claims Apple let a counterfeit Sparrow Wallet app remain in its App Store, enabling attackers to capture recovery phrases and steal $1.8 million in Bitcoin. The breach highlights gaps in third‑party app vetting that SOC 2 vendor‑management controls are designed to address.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
malwarebytes.com

Apple’s App Store Hosted Fake Crypto Wallet That Stole $1.8 Million from Users

What Happened — A federal lawsuit alleges Apple allowed a counterfeit version of the Sparrow Wallet cryptocurrency app to remain in its App Store. Between May and August 2025 the fake app harvested users’ 12‑ or 24‑word recovery phrases, enabling attackers to empty the victims’ wallets of roughly $1.8 million in Bitcoin.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a breakdown in third‑party app vetting—a core component of SOC 2 vendor‑management controls.
  • Continuous monitoring of marketplace listings and rapid evidence collection are required to demonstrate due diligence during an audit.
  • A robust vendor‑risk program can provide the audit‑ready documentation needed to prove that an organization only endorses trusted software.

Who Is Affected — Cryptocurrency users (financial services), app‑store developers, and any organization that relies on Apple’s marketplace for distributing internal or customer‑facing tools.

Recommended Actions

  • Map the App Store vetting process to SOC 2 CC6.1 (Vendor Management) and ensure evidence of periodic review is captured.
  • Implement continuous monitoring of third‑party app listings and automated alerts for impersonation or policy violations.
  • Strengthen user‑education on recovery‑phrase handling and enforce a “never share recovery phrase” policy. Source: Malwarebytes Labs

Technical Notes – The malicious app requested the wallet’s recovery phrase (credential theft) and transmitted it to the attackers. No specific CVE is involved; the vector is a fraudulent app published in a curated collection. Source: BleepingComputer legal filing

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/07/apple-accused-of-letting-fake-crypto-app-steal-1-8-million

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →