The fake wallet app was distributed through app stores, directing users to incorrect addresses or stealing their mnemonic phrases, ultimately leading to this loss. This incident once again illustrates that the download source and signature information of wallet apps remain the first things users should verify.
Amount of loss
Reports indicate that the victims lost a total of approximately $1.8 million, with their assets primarily consisting of Bitcoin.
The app in question masquerades as Sparrow Wallet, misleading users with a name and icon similar to the genuine version.
The problem lies in the distribution process.
These fake apps typically infiltrate download lists by using search results, ad placements, or similar names.
Once a user enters a mnemonic phrase or authorizes a transfer after installation, their assets could be quickly transferred out.
What do users need to verify?
Before downloading, you should verify the developer's name, the official website link, and the application's signature information.
For wallet, transaction, and signing applications, avoid installing them directly from unknown links.











