On August 15, the pseudonymous founder 0xngmi revealed that DefiLlama has delayed the public launch of its mobile application while addressing issues related to counterfeit apps impersonating the DeFi analytics platform on Apple’s App Store.
Summary
- DefiLlama decided to postpone its mobile launch until fake App Store listings were eliminated, as confirmed by founder 0xngmi.
- Apple removed one impersonating app within days after DefiLlama demonstrated that it could siphon off crypto funds.
- The official iPhone app for DefiLlama has now been released, with DEFILLAMA LIMITED recognized as the provider by Apple.
- Apple’s policies strictly prohibit app impersonation and the unauthorized use of another developer’s brand or product names.
- There have been multiple occurrences of fraudulent crypto apps appearing on Apple’s store, including recent incidents involving Ledger and Sparrow wallets.
The team eventually demonstrated that one deceptive app could deplete a funded crypto wallet before Apple removed it, according to 0xngmi’s update.
As stated by 0xngmi, DefiLlama had reported the problematic application for several months concerning trademark infringement and impersonation but had failed to have it removed. The team subsequently funded a small test wallet, downloaded the fake app, and noted the funds disappearing. “The app was taken down within days after that,” he said. The specifics of the amount drained from the test wallet were not disclosed.
DefiLlama waited until fake apps were removed
The security concern directly influenced DefiLlama’s product launch. 0xngmi mentioned that the company “waited until all the counterfeit apps were removed before we launched ours to prevent any user from getting scammed.” This timeline reflects DefiLlama’s viewpoint and has not been independently verified by Apple.
The legitimate DefiLlama application is now publicly available. The official page indicates that its mobile product can be accessed on both iOS and Android platforms. Apple’s listing identifies the iPhone app as “DefiLlama: DeFi Tracker,” lists DefiLlama as the developer, and shows DEFILLAMA LIMITED as the provider.
Meanwhile, Apple’s App Review guidelines disallow the creation of applications that imitate other apps or services. Additionally, the rules restrict developers from using another developer’s icon, brand, or product name without permission. Continuous impersonation can lead to expulsion from the Apple Developer Program.
Apple has not officially responded to 0xngmi’s specific claims in the official documentation reviewed for this report. Previously, the company stated that its App Review process screens applications for security and safety, reporting that over 320,000 submissions were rejected in 2024 for reasons including copycat applications, spam, or user misrepresentation.
Fake crypto apps have caused documented losses
The DefiLlama situation is not unique, as there have been other recorded cases where counterfeit cryptocurrency apps have infiltrated Apple’s marketplace. For instance, a fraudulent Ledger Live app drained 5.9 BTC, valued at around $420,000, from musician Garrett Dutton in April. On-chain researcher ZachXBT tracked the stolen Bitcoin to addresses connected to KuCoin.
Apple is also contending with a U.S. lawsuit involving three users who claim that fraudulent Sparrow Wallet apps resulted in $1.835 million in Bitcoin losses. These claims are yet to be proven in court. In this instance, Apple asserted that it removed impersonating applications and banned the related developer accounts.
Additionally, a fake Phantom Wallet application made its way onto Apple’s App Store before it was ultimately removed following user reports of lost funds.
What happens next
DefiLlama’s official app is now active, and its website provides direct access to the legitimate mobile product. The iOS listing currently shows version 1.0.5, indicating defillama.com as the developer’s website, which offers users several ways to confirm legitimacy prior to installation.
The founder has not disclosed details regarding the attackers’ addresses, the amount drained during DefiLlama’s testing phase, or any technical analysis of the malicious application. Such information would be essential for an independent reconstruction of the wallet drain incident. For users, the simplest verified precaution is to access the mobile application through DefiLlama’s official website and to confirm the developer and provider listed instead of relying solely on App Store search results.





