App Store Wallet Clones Steal Crypto Recovery Phrases
The App Store is being used as a distribution layer for wallet theft. The standard defense is to trust Apple’s review and then focus on the wallet app itself. That misses the real break: the app can hand users off to a browser page that delivers a trojanized wallet and steals the recovery phrase or private key before the user realizes anything is wrong.
Researchers found more than twenty phishing apps in the Apple App Store posing as crypto wallets. The campaign targets MetaMask, Coinbase Wallet, Trust Wallet, TokenPocket, Bitpie, imToken, and OneKey, and metadata suggests it has been active since at least fall 2025. Kaspersky says the fake apps redirect users to lookalike browser pages and that the same theft pattern has resurfaced with new malicious modules and updated injection techniques.
The risk persists even if the App Store app is removed. Once a recovery phrase or private key is exposed, the attacker can move the wallet outside the victim’s control, and the distribution trick gives the campaign a way to scale past Apple’s normal protections.