DefiLlama Delays Mobile App Over Fake Phishing Apps on Apple Store

Share

DefiLlama postponed its official iPhone app launch for several months, forced to prove concrete financial harm to Apple before the tech giant removed fraudulent clones that had been draining user wallets from the App Store.

🔑 Key takeaways

  • DefiLlama delayed its mobile app launch to protect users from fraudulent clones still listed on Apple’s App Store.
  • The team loaded a test wallet, downloaded the fake app and let it get drained to document the theft.
  • The fraudulent app was removed “within days” once the proof of harm was submitted to Apple.
  • The official “DefiLlama: DeFi Tracker” app is now available, published by DEFILLAMA LIMITED.

A trademark complaint ignored for months

DefiLlama’s pseudonymous founder 0xngmi detailed the episode in a series of X posts on August 15. The DeFi (decentralized finance) analytics platform had identified several apps imitating its service in Apple’s App Store, in clear violation of platform rules prohibiting app impersonation and unauthorized use of another developer’s brand name.

For several months, the team filed repeated reports with Apple citing trademark violations and impersonation. Despite what looked like an open-and-shut case — name, logo and screenshots reproduced identically — Cupertino did not act, letting the fraudulent apps continue to trap users.

The bait-wallet strategy

Faced with Apple’s inaction, DefiLlama changed tactics. Rather than rely on a theoretical complaint, the team deliberately loaded a small wallet with funds, downloaded the fake app and let it drain the wallet as expected. The full sequence was then documented and submitted to Apple — this time with concrete evidence of financial harm.

The approach worked. The fraudulent app was pulled “within days,” where months of written complaints had produced nothing. The founder commented on the situation with barely concealed irony:

“It is abnormal that we have to go this far to protect users.”

0xngmi, founder of DefiLlama

The delay in launching the official app, he explained, was specifically intended to prevent users from mistakenly downloading a clone and losing their funds: “We waited for all the fake apps to be removed before launching ours.”

A systemic impersonation problem across app stores

The DefiLlama episode is not isolated. It is part of a broader wave of fraudulent apps targeting crypto brands in mainstream app stores. In November 2023, a fake Ledger Live app on the Microsoft Store already enabled the theft of $588,000 in just 38 transactions — a record in this category. In 2024, the Rabby (DeFi wallet) and Curve Finance (decentralized exchange) brands were cloned on Apple’s App Store.

The table below summarizes the main documented incidents:

DateImpersonated brandPlatformDocumented harm
November 2023Ledger LiveMicrosoft Store$588,000 / 38 transactions
2024Rabby WalletApple App StoreNot publicly quantified
2024Curve FinanceApple App StoreNot publicly quantified
2025DefiLlamaApple App StoreTest amount undisclosed

In the DefiLlama case, the exact amount drained from the test wallet was not disclosed — the goal was not to incur a loss but to build a viable case. This approach turns a routine complaint into a demonstration of direct financial harm, the only form of report Apple appears to process promptly.

The official app is now live

DefiLlama’s official app is now listed on the App Store under the name “DefiLlama: DeFi Tracker,” with DEFILLAMA LIMITED listed as publisher. The service retains its analytical mission: tracking TVL (total value locked in protocols), yields, volumes and key indicators across the DeFi ecosystem.

Apple’s rules formally prohibit app impersonation and unauthorized use of another developer’s brand name or product. The contrast between the legal toolkit available and the slowness of its enforcement remains striking: DefiLlama had to suffer an actual theft for Apple to act, where a simple observation of name, logo and screenshot copying should have been enough.

Cointelegraph reached out to Apple for comment on the processing delay and the rise in cases; no response was received at the time of publication.


Conclusion: self-defense as the new norm?

The DefiLlama episode exposes a structural blind spot in app stores: proactive moderation of crypto brands remains largely ineffective, forcing legitimate protocols to prove actual harm before triggering any action. In the short term, serious players will have to bake an “anti-clone” budget into their roadmap — store monitoring, documented takedown requests and even formal legal complaints.

Two scenarios are emerging for the medium term. The optimistic one sees Apple and Google strengthen their detection tools through machine learning and brand partnerships, aligning the treatment of crypto reports with that of banks or e-commerce players. The more concerning one sees fraudsters professionalize their methods further (deepfakes of executives, near-perfect copies), forcing the ecosystem to develop its own app verification solutions — for example, on-chain signing or decentralized directories. In either case, downloading a crypto app will soon require the same vigilance as a self-custody transaction.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Disclaimer: this content is for information purposes only and is not financial advice. Cryptocurrencies are highly volatile: you may lose all of your capital. Always do your own research. Legal notice
Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Read More

Items