The post iPhone Users Beware: Kaspersky Flags 26 Fake Crypto Wallet Apps That Could Drain Your Funds appeared on BitcoinEthereumNews.com. Home » Crypto News TheseThe post iPhone Users Beware: Kaspersky Flags 26 Fake Crypto Wallet Apps That Could Drain Your Funds appeared on BitcoinEthereumNews.com. Home » Crypto News These

iPhone Users Beware: Kaspersky Flags 26 Fake Crypto Wallet Apps That Could Drain Your Funds

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Home » Crypto News


These fake iOS apps appear legitimate but redirect users to phishing pages, leading to malware installation and eventual theft of crypto assets.

‘;
}
function loadTrinityPlayer(targetWrapper, theme,extras=””) {
cleanupPlayer(targetWrapper); // Always clean first ✅
targetWrapper.classList.add(‘played’);
// Create script
const scriptEl = document.createElement(“script”);
scriptEl.setAttribute(“fetchpriority”, “high”);
scriptEl.setAttribute(“charset”, “UTF-8”);
const scriptURL = new URL(`https://trinitymedia.ai/player/trinity/2900019254/?themeAppearance=${theme}${extras}`);
scriptURL.searchParams.set(“pageURL”, window.location.href);
scriptEl.src = scriptURL.toString();
// Insert player
const placeholder = targetWrapper.querySelector(“.add-before-this”);
placeholder.parentNode.insertBefore(scriptEl, placeholder.nextSibling);
}
function getTheme() {
return document.body.classList.contains(“dark”) ? “dark” : “light”;
}
// Initial Load for Desktop
if (window.innerWidth > 768) {
const desktopBtn = document.getElementById(“desktopPlayBtn”);
if (desktopBtn) {
desktopBtn.addEventListener(“click”, function () {
const desktopWrapper = document.querySelector(“.desktop-player-wrapper.trinity-player-iframe-wrapper”);
if (desktopWrapper) loadTrinityPlayer(desktopWrapper, getTheme(),’&autoplay=1′);
});
}
}
// Mobile Button Click
const mobileBtn = document.getElementById(“mobilePlayBtn”);
if (mobileBtn) {
mobileBtn.addEventListener(“click”, function () {
const mobileWrapper = document.querySelector(“.mobile-player-wrapper.trinity-player-iframe-wrapper”);
if (mobileWrapper) loadTrinityPlayer(mobileWrapper, getTheme(),’&autoplay=1′);
});
}
function reInitButton(container,html){
container.innerHTML = ” + html;
}
// Theme switcher
const destroyButton = document.getElementById(“checkbox”);
if (destroyButton) {
destroyButton.addEventListener(“click”, () => {
setTimeout(() => {
const theme = getTheme();
if (window.innerWidth > 768) {
const desktopWrapper = document.querySelector(“.desktop-player-wrapper.trinity-player-iframe-wrapper”);
if(desktopWrapper.classList.contains(‘played’)){
loadTrinityPlayer(desktopWrapper, theme,’&autoplay=1′);
}else{
reInitButton(desktopWrapper,’Listen‘)
const desktopBtn = document.getElementById(“desktopPlayBtn”);
if (desktopBtn) {
desktopBtn.addEventListener(“click”, function () {
const desktopWrapper = document.querySelector(“.desktop-player-wrapper.trinity-player-iframe-wrapper”);
if (desktopWrapper) loadTrinityPlayer(desktopWrapper,theme,’&autoplay=1’);
});
}
}
} else {
const mobileWrapper = document.querySelector(“.mobile-player-wrapper.trinity-player-iframe-wrapper”);
if(mobileWrapper.classList.contains(‘played’)){
loadTrinityPlayer(mobileWrapper, theme,’&autoplay=1′);
}else{
const mobileBtn = document.getElementById(“mobilePlayBtn”);
if (mobileBtn) {
mobileBtn.addEventListener(“click”, function () {
const mobileWrapper = document.querySelector(“.mobile-player-wrapper.trinity-player-iframe-wrapper”);
if (mobileWrapper) loadTrinityPlayer(mobileWrapper,theme,’&autoplay=1′);
});
}
}
}
}, 100);
});
}
})();


Summarize with AI


Summarize with AI

Cybersecurity firm Kaspersky has identified 26 fraudulent cryptocurrency wallet applications on Apple’s App Store that are designed to steal users’ digital assets.

The company’s Threat Research team found that the apps imitate popular crypto wallets, such as MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie, by copying their names and visual branding to appear legitimate. Once opened, these applications redirect users to phishing pages that resemble the App Store interface and prompt them to download a second application, which is actually a trojanized wallet that can drain cryptocurrency funds.

How The Scam Works

Kaspersky said the campaign has been active since at least fall 2025 and, with “moderate confidence,” linked it to the threat actors behind SparkKitty, a previously identified iOS malware strain. Official versions of many of these wallet apps are not available in the Chinese iOS App Store; most of the detected phishing apps were distributed specifically to users in China, though the malicious payload itself does not include regional restrictions. This essentially means that users outside China could also be affected. Kaspersky confirmed it has reported all identified apps to Apple.

According to the findings, the fraudulent apps include basic, unrelated features such as games, calculators, or task managers to create an appearance of legitimacy and pass initial scrutiny. After installation, they guide users through a process that opens a fake App Store webpage and encourages them to download what appears to be the intended wallet application.

This installation process works similarly to SparkKitty, using Apple’s enterprise developer tools for corporate app distribution. Users are prompted to install a developer profile on their device, which allows them to install apps from outside the App Store. Attackers rely on users overlooking this step, enabling the installation of malicious software.

Once installed, the trojanized wallet applications are designed to mimic the behavior of the specific wallet they impersonate. They target both hot and cold wallets.

Kaspersky’s mobile malware expert, Sergey Puzan, stated that while the apps themselves may not contain harmful code, they serve as entry points in a broader attack chain that ultimately leads to malware installation. The researcher further warned,

You may also like:

Counterfeit Ledger Device

The latest report comes days after a counterfeit Ledger Nano S Plus device sold through an online marketplace was exposed as part of a sophisticated phishing operation designed to steal crypto wallet credentials by a Brazilian cybersecurity researcher. The device, which was marketed and priced like an official product, initially appeared genuine but failed verification when connected to Ledger Live.

Upon opening the device, the researcher found internal components that did not match legitimate hardware, including a chip with its markings removed and additional WiFi and Bluetooth antennas not present in authentic Ledger wallets. Further examination of the firmware revealed that both PIN codes and seed phrases were stored in plaintext, along with references to external servers, indicating that the device was designed to capture and transmit sensitive data.

The researcher acknowledged that this attack does not involve any flaw in Ledger’s security, but instead uses fake devices, harmful apps, and phishing tricks to target users.

SPECIAL OFFER (Exclusive)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Source: https://cryptopotato.com/iphone-users-beware-kaspersky-flags-26-fake-crypto-wallet-apps-that-could-drain-your-funds/

Market Opportunity
Helium Mobile Logo
Helium Mobile Price(MOBILE)
$0.000137
$0.000137$0.000137
-3.85%
USD
Helium Mobile (MOBILE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!