Fake DefiLlama Apps Were Draining Wallets on Apple's App Store, and Apple Knew
Scammers were running live, fund-draining fake DefiLlama apps inside Apple's App Store, and that is exactly why the real app never launched, according to the protocol's founder.
This wasn't a close call. DefiLlama's team documented a fraudulent clone actively pulling funds from a real crypto wallet before Apple finally acted. Once the evidence was submitted, Apple removed the fake app within days. But here is the part that should concern every DeFi user: the app was already live, already trapping victims, and the only reason you're hearing about it now is because DefiLlama chose to delay its own launch rather than let users walk into a trap.
Apple's App Store Is Not the Safe Haven You Think It Is
The App Store carries a reputation for rigorous review, and scammers know that reputation works in their favor. When a fake app appears in Apple's ecosystem, most users assume it passed scrutiny. They trust the platform. They connect their wallets. They lose funds.
DefiLlama's founder made the calculated decision to hold the mobile product back entirely until the phishing threat could be documented and removed. That is an unusual move in an industry where shipping fast is treated as a virtue. It also suggests the team believed the risk was serious enough to sacrifice momentum.
Apple's response, removing the app within days of receiving documented proof, raises its own uncomfortable question. What happens to the users who encountered that app before the evidence was compiled and submitted? There is no public count of victims. There is no compensation mechanism. There is just a removed listing and a gap in the timeline.
This Is a Bigger Pattern Than One Fake App
Phishing apps targeting DeFi users are not new, but the App Store angle matters. Most security warnings in crypto point users toward hardware wallets, seed phrase hygiene, or avoiding sketchy browser extensions. The official mobile app store of the world's most valuable company is not where most people expect the threat to live.
Any DeFi protocol with name recognition is a phishing target. If DefiLlama was cloned and listed before its real app even launched, protocols that are already live on mobile should be treating fake app discovery as an active security responsibility, not a PR problem to handle after the fact.
What You Should Do Right Now
Before opening any DeFi app on your phone, verify the developer name matches the official project website. Check the app's review date, download count, and listed developer against the project's own social channels. If something feels off, it probably is.
Watch for DefiLlama's official mobile launch announcement directly from their verified accounts. When it comes, that is the only version worth downloading.