DefiLlama Postpones Mobile Launch to Combat Apple App Store Phishing Threats
Analytics platform DefiLlama delayed its mobile app release after spending months fighting fake apps that impersonated the platform and drained user wallets.
Launch Delayed Over Security Concerns
DeFi analytics platform DefiLlama has postponed the launch of its highly anticipated mobile application after an extended battle with phishing apps on Apple’s App Store. The company’s pseudonymous founder, 0xngmi, revealed on social media that the delay was a deliberate strategic decision designed to protect users from falling victim to fraudulent apps impersonating the legitimate DefiLlama platform and stealing their digital assets.
“We waited ’till all the fake apps were taken down before we launched ours to avoid any user getting scammed,” 0xngmi explained in a social media post on Saturday, emphasizing the company’s commitment to user security. The decision reflects growing concerns within the cryptocurrency community about how easily malicious actors can distribute cryptocurrency-targeting scams and phishing applications through major app distribution platforms, despite their stated security protocols.
Apple’s Delayed Response to Security Threats
DefiLlama’s experience reveals significant gaps in how Apple handles security reports. The company spent months repeatedly attempting to convince Apple to remove a particularly malicious app that impersonated the DefiLlama platform while actively stealing funds from user wallets. Despite submitting multiple complaints and detailed reports about the fraudulent application, Apple took considerable time to act on the company’s warnings and removal requests.
The situation changed dramatically once DefiLlama took additional action. After the team downloaded the deceptive app and documented concrete evidence of funds being drained from a small cryptocurrency wallet, Apple removed the fake app within days. This striking contrast between Apple’s slow initial response and its rapid action upon receiving proof of actual theft highlights a troubling pattern: major platforms appear to prioritize security only when presented with direct evidence of ongoing criminal activity rather than preventative warnings.
A Systemic Problem Across the Crypto Ecosystem
DefiLlama’s struggle against fraudulent impersonation is far from isolated. Multiple major cryptocurrency projects have faced similar challenges with phishing apps on Apple’s App Store. During 2024, both Rabby wallet and Curve Finance discovered and reported counterfeit apps impersonating their platforms. The problem extends well beyond Apple’s ecosystem—in November 2023, a counterfeit Ledger Live app distributed through the Microsoft Store resulted in $588,000 in stolen cryptocurrency across 38 transactions.
The persistence and frequency of these fraudulent apps underscore the inadequacy of current security measures at major app distribution platforms. This ongoing vulnerability particularly affects cryptocurrency users who may inadvertently download fake applications believing they are accessing legitimate platforms for managing or analyzing their digital assets.
This incident highlights critical security vulnerabilities affecting the broader cryptocurrency ecosystem, including digital asset platforms that many XRP holders and other cryptocurrency investors rely on for portfolio tracking and decentralized finance participation.
Source: DefiLlama, via Cointelegraph. Not financial advice.