When you report a scam to one of the world’s most valuable companies and they do nothing for months, what’s left? Apparently, you let the scam happen on purpose, document it, and hand over the receipts.
That’s exactly what DeFiLlama did. The popular DeFi analytics platform, tired of Apple ignoring repeated trademark violation reports about a fake DeFiLlama app on the App Store, took a creative and slightly unhinged approach to the problem. The team funded a small wallet, connected it to the fraudulent app, and watched it get drained. Armed with undeniable evidence of theft, they went back to Apple. This time, the app was removed within days.
Months of silence, then a sting operation
DeFiLlama founder 0xngmi disclosed the ordeal publicly, describing a frustrating cycle of filing reports that went nowhere. The team flagged the fake app for trademark infringement multiple times over a period of several months. Apple, for its part, apparently needed more than a well-documented complaint to act.
So DeFiLlama gave Apple exactly what it seemed to require: proof that the app was actively stealing money.
The setup was straightforward. The team loaded a small amount of funds into a wallet, connected that wallet to the impersonating app, and let the app do what scam apps do. Once the funds were drained, DeFiLlama presented the evidence to Apple. The response was swift, a stark contrast to the months of inaction that preceded it.
The cost of waiting
While the team was battling the fake app, DeFiLlama made the decision to delay the launch of its own official app. The reasoning was simple: releasing a legitimate version while an impersonator was still live would only create more confusion for users.
DeFiLlama is one of the most widely used analytics dashboards in decentralized finance, aggregating data on total value locked across hundreds of protocols. An official mobile app would serve millions of users who currently rely on the web version.
0xngmi did not disclose how much was in the sacrificial wallet or specify the exact dates of the test drain. No information about the developers behind the fraudulent app has been made public either. The focus of the public disclosure was squarely on Apple’s process, or lack thereof.
A broader pattern in crypto app security
Apple’s walled-garden approach to its App Store has long been marketed as a feature, not a bug. The company positions its review process as a safeguard that protects users from malicious software. That narrative takes a hit when a known scam app survives months of reports and only gets pulled after a project engineers its own theft as evidence.
For users, the lesson is older but no less important. Always verify the developer of any app before connecting a wallet. Check a project’s official website or social channels for direct links to their app.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
14









English (US) ·