Fake DeFiLlama app stayed on Apple's App Store until it stole real funds
Security & Exploits ·
A fraudulent app impersonating DeFiLlama was removed by Apple only after it drained a developer's test wallet, despite months of prior complaints about it.
DefiLlama, the open-source DeFi analytics aggregator built by pseudonymous developer 0xngmi, tracks total value locked, fees, stablecoin flows, and protocol data across hundreds of chains and thousands of applications. According to a report cited by wublockchain.xyz, the DefiLlama team had filed repeated appeals with Apple over an app impersonating the platform on the App Store, but the listing remained live through months of reporting. It was taken down only after the fake app was shown to have drained a test wallet belonging to the development team.
The episode raises questions about the effectiveness of Apple's app review process for detecting crypto-impersonation apps before financial harm occurs. Reports alone, submitted over an extended period, were not sufficient to trigger removal; it took a demonstrated loss of funds to prompt action. The wallet involved was described as a test wallet used by the team, which limited the scope of the loss, but the same vector could expose ordinary users relying on the App Store's vetting to be legitimate.
The incident follows a separate case in which 0xngmi publicly identified an AI-generated DeFi project that used JavaScript's Math.random() function to fabricate arbitrage profits in an attempt to game a DefiLlama listing. Taken together, the two episodes point to a recurring pattern: DefiLlama's open, widely trusted data and brand make it a target for manipulation and impersonation, whether through fake listings gaming its metrics or fake apps exploiting its name on official platforms.
DefiLlama's role as a near-default reference point for DeFi metrics, cited by central banks and used across thousands of protocols, amplifies the stakes of any impersonation attempt, since users searching for the tool on official app stores would reasonably assume vetting had already occurred. The team's transparency-first, no-paid-listing model is designed to keep its own data auditable, but that model does not extend to policing third-party platforms like Apple's App Store, where fraudulent apps can persist despite direct reports from the affected project.
It remains unclear how long the fake app had been available before removal, how many users beyond the DefiLlama team's test wallet may have interacted with it, or what changes, if any, Apple has made to its review process in response. Whether other impersonation attempts targeting DefiLlama or similar DeFi infrastructure projects are currently active on app stores is also not established in available reporting.