How Counterfeit Crypto Apps Get Into App Stores
7 min read · Verified September 2026
Counterfeit crypto apps reach official stores through typosquatted names, compromised developer accounts and behaviour that changes after approval. Identify one by checking the developer name against the official website, reading the newest and lowest reviews, and treating any request for a seed phrase as conclusive proof of fraud.
The comforting assumption is that Apple and Google check things. They do check things. They also process a volume of submissions that makes exhaustive review impossible, and the people building counterfeit crypto apps have spent years learning exactly where the checking stops.
This is not a hypothetical category of risk. It is a steady, documented, industrialised one, and the specific cases are worth knowing because they show which of your instincts are useful and which are not.
How does a counterfeit app get past review?
Start with the case that made the point clearly. In January 2021 an app calling itself Trezor was approved for the App Store and stayed live for roughly two weeks, from 22 January to 3 February, collecting around a thousand downloads. One user, Phillipe Christodoulou, entered his recovery phrase and lost 17.1 BTC, worth about $600,000 at the time. Malwarebytes' account of the incident makes the uncomfortable observation that a wallet app sending cryptocurrency to an address is, from a reviewer's perspective, doing exactly what a wallet app does. The malice is in the destination, and the destination is not visible in a review.
Five years later the technique has scaled rather than disappeared. In April 2026, Kaspersky researcher Sergey Puzan documented 26 malicious applications on the App Store impersonating Bitpie, Coinbase, imToken, Ledger, MetaMask, TokenPocket and Trust Wallet, operating since at least autumn 2025. Several used deliberate misspellings such as "LeddgerNew". Others posed as games or calculators and produced a phishing page requesting a recovery phrase once installed. They were served primarily to accounts configured to China, which is worth understanding as a general principle: store catalogues differ by region, so an app being absent from your store proves nothing about whether the campaign exists.
The Android route is different and, in one respect, worse. Cyble's researchers found more than twenty phishing applications on the Play Store impersonating SushiSwap, PancakeSwap, Hyperliquid, Raydium and others, distributed not through freshly created accounts but through older developer accounts that had previously published legitimate gaming and streaming apps with over 100,000 downloads between them. The apps hid their phishing URLs inside privacy policy documents and used a webview wrapper framework to ship variants quickly.
That last detail deserves attention, because it invalidates the heuristic most people rely on. A developer account with history and installs is not evidence of legitimacy when the account itself has been bought or compromised.
Store links from thecrypto.app go to the verified listing, which is the only route worth using.
What signals actually identify one?
Work down this list in order of reliability.
A request for your seed phrase. Conclusive, on its own, with no further investigation required. No legitimate wallet asks for a recovery phrase outside a restore flow you deliberately initiated, and no tracker, exchange app or price app asks for one at all. Never share your seed phrase covers why the request is always the whole of the evidence.
Developer name mismatch. Every store listing names a publisher. Ledger's apps are published by Ledger SAS. If the name is unfamiliar, generic, or a slight variation on the real company, stop. Tap through to the developer's other apps; a real wallet company publishes a coherent set, while a counterfeit publisher often lists a photo editor, a flashlight and a wallet.
Permission requests that make no sense. On Android, accessibility services allow an app to read screen contents and simulate input, which is the standard route to stealing credentials as you type them. Screen overlay draws fake interfaces on top of real apps. SMS access intercepts one-time codes. A portfolio tracker needs network access and notifications. It does not need any of those, and a wallet does not either.
Review pattern rather than review score. Sort to newest and read the one-star reviews first. Counterfeits accumulate a burst of short, generic five-star reviews posted within a narrow window, alongside a small number of specific, furious one-stars from people describing exactly how they were robbed. A genuine app with years of history has boring reviews complaining about sync bugs and subscription pricing.
Version and update history. A real product has a long list of releases with mundane changelogs. A listing published six weeks ago, with one version and no history, is either new or fake, and for a wallet claiming to be an established brand there is no benign interpretation.
The interface itself. Counterfeits built as webview wrappers feel wrong in a way that is hard to articulate and easy to notice: fonts that do not match the platform, screens that scroll like a web page, spelling errors, settings menus that lead nowhere.
How do I verify I have the real listing?
The reliable method inverts the usual one. Do not search the store and reason about which result looks right, because surviving that reasoning is precisely what a counterfeit is built to do.
- Start at the official website, typed by hand or from a bookmark you saved earlier. Not from a search result, a sponsored ad, a QR code on a poster, or a link in a message.
- Follow the store link published on that site. The website is the anchor of trust in the chain, and the store link on it points to the listing the company controls.
- Compare the developer name on the listing that opens against the company name on the website. They should match.
- Check the version history and first release date before installing anything financial.
- Bookmark the listing, so the next install on a new device skips all of this.
- Cross-check through a second official channel if anything is ambiguous, such as the company's verified social account or its published documentation, both of which usually link the same listing.
For The Crypto App, the store links on thecrypto.app go where they should. The tracker buyer's checklist covers the wider set of questions worth asking of any tracker before you commit accounts to it.
One more habit is worth building. When you set up a new device, install from your own bookmarks or your store's existing purchase history rather than searching fresh, because a new phone is the moment people are most rushed and least careful. Restoring on a new phone walks through the sequence.
What if I already installed one?
Triage by what you gave it.
If you entered a recovery phrase, the wallet is gone as a secure container. Generate a new wallet on a clean device and move liquid assets first, racing automated sweeper bots rather than a person. The emergency sequence in never share your seed phrase covers the order and the gas-token trap that catches people mid-rescue.
If you entered exchange API keys, delete them at the exchange immediately. Uninstalling the app does not deactivate a key, and this is the most common way exposure quietly persists after someone believes they have cleaned up. How to revoke an API key covers where the control lives.
If you entered an exchange password, change it from a different device, confirm two-factor is on, and check the exchange's own login and withdrawal logs for entries you do not recognise.
Then uninstall, revoke any accessibility or overlay permission the app was granted, and report the listing to the store. Reporting genuinely works: both Apple and Google remove these on credible disclosure, and the campaigns Kaspersky and Cyble documented were pulled after being reported.
The durable lesson is not that app stores are dangerous. It is that the store is the last checkpoint in the chain and the weakest, so put your trust one step earlier, in a website address you typed yourself.
Common questions
Marginally, and not enough to rely on. Apple's review is stricter on average, but Kaspersky documented 26 seed-phrase-stealing wallet apps live on the App Store in 2026, and a fake Trezor app approved in 2021 cost one user 17.1 BTC. Both stores are filtered, neither is a guarantee.
Not reliably. Cyble found phishing apps published from older developer accounts that had previously hosted legitimate games and streaming apps with more than 100,000 downloads between them. The install history belonged to the account, not to the malicious app.
Accessibility services, screen overlay, SMS access and contacts. A tracker or wallet has no use for any of them, and accessibility services in particular allow an app to read everything on screen and simulate taps, which is the standard mechanism for on-device credential theft.
If you typed the phrase, treat the wallet as compromised and move funds to a newly generated wallet immediately, highest-value liquid assets first. If you did not type it, uninstall, and check what permissions the app was granted before deleting it.
Open the official website of the product, find its own store link, and compare the developer name shown on that listing with the one you were about to install from. Do not search the store and reason about which result looks right; that is the step counterfeits are designed to survive.
It can read your balances and trade history, which is a privacy loss rather than a theft. It cannot withdraw. Revoke the key at the exchange as soon as you realise, because deleting the app does not disable it.
Read-only connections and public wallet addresses only. No seed phrase is requested at any point in setup.
Scan to install
Keep reading
Nobody Legitimate Will Ever Ask for Your Seed Phrase
A seed phrase is the wallet, not a password for it. Why no real app or agent needs one, the scripts scammers use, and what to do if you shared it.
Is It Safe to Connect Your Exchange to a Portfolio Tracker?
A read-only key cannot move funds. A tracker breach still exposes your holdings. The real risk, why withdrawal permission is never granted, how to revoke.
What a Portfolio Tracker Can Actually See
Balances and trade history, yes. Private keys, seed phrases and moving funds, no. What the app, the company and the public can each actually see.
How to Revoke an Exchange API Key Properly
Deleting a connection in an app does not revoke the key. Where the real control lives on Binance, Kraken and Coinbase, and how to audit old keys.
Why a Portfolio App Needs Its Own Lock
A device passcode protects a locked phone. Most exposure happens on an unlocked one. What an app lock adds, and what it cannot possibly do.
What to Look For in a Crypto Tracker
A buyer's checklist: venue and chain coverage, DeFi handling, alert depth, read-only limits, export, pricing, and whether the company lasts three years.
Where Blockfolio and Delta Users Ended Up
Blockfolio became the FTX app and died with FTX in November 2022. What happened to the data, what the estate has repaid since, and where to move now.
Moving Your Portfolio to a New Phone Without Losing Anything
Connections and manual positions follow your account. Widgets, app lock and notifications do not. The migration order that avoids losing anything.