DefiLlama Held Back App Launch for Months as Fake Clone Drains a Wallet, Apple Acts in Days
DefiLlama delayed its mobile app for months fighting phishing clones on Apple's App Store; a documented wallet drain got one pulled in days.

DeFi analytics platform DefiLlama held off releasing its own mobile app for months while it pushed Apple to strip fake clones impersonating the service from the App Store, according to the project’s pseudonymous founder, 0xngmi. One malicious listing came down only after DefiLlama documented it draining funds from a small crypto wallet — a fix that arrived in days after months of unsuccessful requests.
“We waited ’till all the fake apps were taken down before we launched ours to avoid any user getting scammed,” 0xngmi wrote in a post on X on Saturday. The founder said the team had tried for months to get the impersonating app removed through normal channels, with limited success until they escalated the case with hard evidence of an actual theft.
A wallet drain as proof, not just a warning
What changed Apple’s response, according to 0xngmi, was DefiLlama’s team downloading the fraudulent app themselves and recording it siphoning funds from a small wallet in real time. That documentation reportedly moved Apple to pull the listing within days, a stark contrast to the months the team had already spent flagging the same app without resolution.
The episode underscores a recurring gap in App Store moderation for crypto-adjacent software: static reports and impersonation complaints appear to carry far less weight than concrete evidence of funds being stolen. For a platform like DefiLlama, whose entire business is built on being a trusted aggregator of on-chain and market data, that gap directly delayed its own legitimate product reaching users.
Part of a wider pattern of App Store impersonation
DefiLlama is not the first crypto brand to be cloned on major app marketplaces. Fake apps impersonating Rabby Wallet and Curve Finance surfaced on the App Store in 2024, and in November 2023 a counterfeit Ledger Live app distributed through the Microsoft Store led to roughly $588,000 stolen across 38 transactions before it was removed.
Those incidents share a common thread with DefiLlama’s experience: platform operators tend to act quickly once a theft is documented, but slower moderation processes leave a window during which fake apps can sit live and actively harvest wallet credentials or seed phrases from unsuspecting users searching for a legitimate brand name.
Why it matters for holders and builders
For everyday crypto users, the takeaway is practical: app store rankings and official-looking branding are not proof of legitimacy, especially for wallet and analytics tools that request permissions or connections to funds. Verifying developer names, checking official project links, and treating any newly listed “crypto” app with caution remains the most reliable defense until platforms tighten pre-launch vetting.
For builders, DefiLlama’s decision to delay its own launch rather than risk brand confusion highlights a cost that rarely shows up in headlines — legitimate projects effectively competing with, and being slowed down by, the fraudulent copies of themselves that marketplaces allow to circulate.
Sources
Related articles
Trezor Breach Grows by 67,000 US Records After ShipMonk Data Wasn’t Deleted
Trezor confirms 67,000 more US customers exposed via ShipMonk; three outlets agree on the figure, but initial breach counts differ.
Robinhood Chain’s $2.66M Daily Revenue Tops Ethereum, Confirmed by Two Trackers
Two independent outlets confirm Robinhood Chain's $2.66M 24-hour app revenue beat Ethereum mainnet; transaction and token figures remain single-sourced.
Ethena Foundation Buys Back Locked ENA, Proposes Buyback Fee Switch as Token Jumps
Two outlets confirm Ethena's buyout of early-investor ENA and a fee-switch proposal, but neither reports exact size, price or rally percentage.