0xngmi, the pseudonymous founder of DeFi analytics site DeFiLlama, said he downloaded a fake DeFiLlama app from the App Store, funded a small wallet, and let the app steal the money as proof it was a scam.
Apple removed the app just days after his download, after ignoring months of trademark and impersonation complaints.
In a series of posts on X on August 15, 2026, 0xngmi said DeFiLlama had spent months flagging a fake DeFiLlama app on the App Store to Apple through its abuse and trademark channels, citing impersonation and trademark violations, and got no action.
The listing remained on the App Store until 0xngmi loaded a wallet with a small amount of crypto, installed the fake app, and confirmed it drained the funds. Once he reported that result to Apple, the app came down in days.
“I know it’s insane you have to do this to save users from obviously fake apps,” he wrote, adding that he was publicizing the episode so other crypto teams “don’t waste time like us.”
0xngmi described the fake app as a basic copy of DeFiLlama that somebody had “vibecoded,” all for the purpose of prompting users for their seed phrase, the secret recovery words that grant full control of a crypto wallet.
He said the same operators had been spamming lookalike apps for other major crypto brands and passing Apple’s identity checks by registering under dead companies. In DeFiLlama’s case, he said, the scammers completed know-your-customer verification using a mom-and-pop shoe-shine business that had been incorporated roughly 40 years earlier and no longer operates.
DeFiLlama’s team decided to push back the real launch of the app by months until every fake version was gone, so that no user would download a scam by mistake.
DeFiLlama already runs LlamaSearch, which is a directory of vetted crypto domains, precisely because search and app-store results are so often manipulated.
Cryptopolitan has tracked cases of impersonation similar to the App Store incident across other platforms. On August 14, 2026, a Hyperliquid trader lost about $550,000 in USDC after a paid Google ad sent them to a cloned version of the exchange. In May 2026, scammers pulled more than $400,000 from Uniswap users through fake Google ad listings, with roughly 146 ETH landing in two attacker addresses.
Cryptopolitan also flagged a fake Hyperliquid app on the Google Play Store last November.
If you're reading this, you’re already ahead. Stay there with our newsletter.