DeFiLlama’s pseudonymous founder, known as 0xngmi, deliberately let a fake DeFiLlama app drain a small test wallet he had funded specifically to prove the app was fraudulent, after months of trademark and impersonation complaints to Apple went nowhere.
What Happened
DeFiLlama spent months reporting a fake DeFiLlama app on the App Store through Apple’s abuse and trademark channels, citing impersonation and trademark violations, but Apple took no action.
Those complaints followed Apple’s standard reporting process, the kind of formal notice a company is expected to use, and yet the listing remained live throughout.
0xngmi then loaded a small wallet with crypto, installed the counterfeit app himself, and confirmed it drained the funds exactly as expected.
He reported that result to Apple, and the app came down within days. “I know it’s insane you have to do this to save users from obviously fake apps,” he wrote in a post on X, adding that he was publicizing the episode so other crypto teams “don’t waste time like us.”
0xngmi described the app as a basic, quickly built copy of DeFiLlama whose sole purpose was prompting users for their seed phrase, the recovery words that grant full control of a crypto wallet.
How the Scammers Got Past Apple’s Verification
According to 0xngmi, the same operators behind the fake DeFiLlama app have been spamming lookalike apps impersonating other major crypto brands, passing Apple’s identity checks by registering under defunct companies.
In DeFiLlama’s case, he said the scammers completed know-your-customer verification using a small shoe-shine business incorporated roughly 40 years earlier that no longer operates.
DeFiLlama’s team decided to delay the launch of its own legitimate app by months until every fake version was removed from the App Store, so no user would download a scam by mistake while searching for the real thing.
The company already runs LlamaSearch, a directory of vetted crypto domains, built precisely because search results and app store listings get manipulated by impersonators so often.
This Echoes a Pattern Already in Litigation
This incident closely mirrors a lawsuit already working through the courts. Three Bitcoin holders sued Apple in late July 2026 over a fake Sparrow Wallet app that drained a combined $1.8 million after they entered their seed phrases, a case our earlier coverage of the Apple Sparrow Wallet lawsuit covers in detail.
In that case too, Sparrow Wallet’s actual creator had publicly flagged copycat apps since January 2024, and Apple was slow to act even after a direct report from the affected user.
That creator had reportedly tried submitting his own App Store listing specifically to warn iOS users that Sparrow doesn’t have a mobile version, only for Apple to reject it and separately flag his developer account over unrelated concerns, a decision later reversed on appeal.
The DeFiLlama case follows the same basic shape: a legitimate project’s team repeatedly warned Apple about impersonation, yet the App Store’s fake listing survived until something more dramatic than a standard complaint forced the issue.
What Comes Next
Apple has not publicly commented on this specific incident as of this reporting. Whether the company adjusts how it verifies developer identity or responds to impersonation complaints more quickly going forward will be the clearer signal of whether this case changes anything structurally, rather than resolving as one isolated fix.
What this means for you: the lesson holds regardless of which specific app or platform is involved. No legitimate crypto wallet or DeFi app will ever need your seed phrase entered directly into it, and verifying a download through the developer’s own official website, rather than trusting an app store listing or a search result on its own, remains the most reliable protection against this exact kind of impersonation. Our wallets guide and crypto scams to avoid guide both cover this in more depth.

