Is a cryptocurrency wallet app in the official app store always safe to use?
Not always. Fake wallet apps do occasionally appear in official stores, and can drain your funds or steal your seed phrase.
Last reviewed: 1 August 2026
Explanation
Both the Apple App Store and Google Play have been exploited by fraudsters who publish convincing fake wallet apps for popular cryptocurrencies and hardware wallet brands. These apps may look identical to the genuine product, use stolen branding, and receive fake positive reviews. When you enter your seed phrase to 'restore' your wallet, the phrase is immediately sent to the attacker who drains your funds. Before downloading any crypto wallet, verify the developer name matches the official brand website, check the number of reviews and download count against the genuine app, and visit the project's official website to find the correct download link. Never enter a seed phrase into an app you are not completely certain is genuine.
The seed phrase deserves its own mental category, because its properties differ from every credential you are used to: it is the wallet, not a password to it. Anyone who has ever seen the phrase can take everything, from anywhere, at any time — and no reset, support ticket, or fraud department exists afterwards. This is why fake wallets do not need elaborate functionality; a convincing setup screen with a 'restore your wallet' field completes the theft the moment you finish typing. Some fakes go further, functioning normally for a while and forwarding your phrase quietly, so the drain happens weeks after the download when suspicion has faded.
A legitimate wallet asks you to write your phrase down during creation and confirm you have; what none legitimately does is need your existing phrase typed in outside of a restore flow you deliberately initiated on an app you verified first. Make the official project website your single source of truth for download links, checked character by character, and treat every other route — search results, ads, QR codes in communities, DM'd links 'to the new version' — as untrusted. If a phrase may have been exposed, move funds immediately to a fresh wallet whose phrase has never touched a screen you doubt.
Common red flags
- Developer name differs slightly from the genuine brand
- App has few reviews or reviews are very recent
- App requests your seed phrase during setup
- App found through a search result or social media link rather than the official website
- App requests excessive device permissions
What to do now
- Find download links only through the official project website
- Compare developer name and review count to the genuine app
- Never enter your seed phrase into any app you did not download from the official source
- Report fake wallet apps to the app store and the genuine project
Frequently asked questions
What if the fake app has thousands of reviews?
Review count and ratings can be purchased or faked. Always cross-reference by going to the official project website first and following their download link.
Why is a seed phrase so much more dangerous to expose than a password?
The phrase is the wallet itself — anyone who has ever seen it can take all funds, from anywhere, permanently, with no reset or fraud process afterwards. A leaked password can be changed; a leaked seed phrase can only be abandoned.
I typed my phrase into an app I now distrust but nothing has been taken — am I safe?
No. Some fake wallets forward phrases quietly and drain funds weeks later. Move everything now to a new wallet whose phrase has never been entered anywhere you doubt, and stop using the suspect app entirely.