Apple CEO Tim Cook and incoming CEO John Ternus at Apple Park

Apple Faces a $1.8 Million Bitcoin Lawsuit. The Timeline Is the Part It Will Have to Answer

July 28, 2026 10:01 am Comments

Three Bitcoin owners filed a proposed class-action complaint against Apple in federal court on July 24, 2026, alleging that a fraudulent iPhone app impersonating Sparrow Wallet enabled the theft of approximately $1.835 million in Bitcoin after they entered their seed phrases. These are unproven allegations, and the case remains at the complaint stage.

The complaint’s central challenge for Apple is chronological. James Ramirez alleges that he reported the app and his own loss on July 25, 2025; Christopher Ellis says he downloaded the same app around August 3, just over a week later, and then lost Bitcoin valued at roughly $840,000.

Ramirez, Ellis, and Jalen Delgado are the named plaintiffs. Their alleged losses are about $875,000, $840,000, and $120,000, respectively, and they want to represent a larger class whose scope would have to be tested in court.

The 54-page federal complaint says Delgado downloaded the fake app around May 1, 2025, entered his phrase, and later saw 1.05033242 BTC transferred without authorization. The filing identifies that event as the earliest alleged loss among the three named plaintiffs.

Ramirez says he downloaded the purported Sparrow app on July 25, entered his seed phrase, and then had 7.4 BTC transferred out. He alleges that he reported both the app and the theft to Apple that same day, making his claimed notice the key fact in the later sequence.

Ellis alleges that he downloaded the same impersonating app around August 3, supplied his phrase, and then had approximately $840,000 in Bitcoin removed. He says he immediately reported his incident to Apple, but the complaint’s sharper question is what happened between the two alleged reports.

Entering a seed phrase does not move Bitcoin by itself. The plaintiffs’ theory is that the fraudulent app captured those credentials, allowing attackers to control the wallets and make the disputed transfers.

They also allege that Apple ranked or featured the app in curated cryptocurrency collections. That placement matters to their case because the App Store presents review and curation as trust signals, and the plaintiffs say those signals gave an impersonator credibility.

A wallet listing carries unusual stakes because a recovery phrase can unlock control of the underlying funds. The plaintiffs’ argument is that Apple’s curation changed how users judged that risk before entering their phrases.

The complaint adds that legitimate Sparrow developer Craig Raw had warned about fake Sparrow mobile apps as early as January 2024. That allegation supplies background, although it does not establish when Apple learned of this particular listing or what information reached its review teams.

BleepingComputer independently reported the complaint’s July 25-to-August 3 sequence and drew an essential product distinction: the legitimate Sparrow Wallet is desktop-only. It is offered for Windows, macOS, and Linux, with no iPhone or iOS release.

In response to BleepingComputer, Apple said it acts quickly to remove impersonating apps and terminates the associated developer accounts. The company also said users can report suspected fraud and that it takes immediate action when an app violates its guidelines.

Those are general statements about Apple’s practices, rather than a concession that any fact in this lawsuit occurred as pleaded. They leave the case-specific timing disputed until Apple answers and the evidence is developed.

The plaintiffs seek compensatory, treble, and punitive damages, along with reimbursement, restitution, attorney fees, injunctive relief, and stronger warnings and procedures. The case remains a proposed class action; no class has been certified.

Litigation will test basic factual questions: whether and how the reports were received, what records exist, how the app was reviewed, and what action followed. The complaint supplies one side of that record; Apple will have the chance to answer, and liability remains for the court.

Apple’s May fraud report describes the scale of its broader defense operation. Apple says it stopped more than $2.2 billion in potentially fraudulent transactions during 2025, reviewed more than 9.1 million app submissions, and rejected more than 2 million.

The same report says more than 371,000 submissions were rejected for copying other apps, spam, or misleading users. Apple says nearly 7,800 deceptive apps were blocked from search and another 11,500 were prevented from appearing on charts.

That portfolio-wide record shows a large review system confronting a large volume of abuse. It cannot establish what happened with the fake Sparrow listing, and it does not resolve the plaintiffs’ allegation that a second loss followed Ramirez’s report.

Fraud controls can be effective at scale while a single disputed listing still becomes the focus of litigation. Here, the issue is operational rather than statistical: what Apple knew, when it knew it, and what response followed.

The complaint alleges answers, but discovery and Apple’s account will determine whether those answers hold.

The cleanest authenticity check was available outside the store. Sparrow’s official download page offers software for macOS, Windows, and Linux and offers no iOS version, so any iPhone listing using the Sparrow name should have triggered further verification before a recovery phrase was entered.

Users should reach a wallet through the developer’s official site, confirm that the operating system is actually supported, and compare the publisher and download path before installing anything. Store placement can help discovery, but it should never replace a direct product check.

A recovery phrase deserves an even harder stop. If an app’s identity or platform support is uncertain, do not type the phrase; anyone who captures it may be able to take control of the wallet without needing the original device.

The lawsuit now puts two forms of trust on the same record: users’ duty to protect irreversible credentials and Apple’s promise of a curated marketplace. The alleged July-to-August sequence gives that tension a concrete shape, leaving the court to test whether the store’s trust signals carried legal consequences in this case.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.