TLDR
DefiLlama founder 0xngmi reportedly let a fake app drain his own wallet to force Apple to remove the impersonator from the App Store.
- 0xngmi says he knowingly signed a malicious transaction from the fake DefiLlama app so Apple would have a clear, undeniable fraud case.
- The stunt spotlights serious gaps in App Store screening, where convincing fake crypto apps can still slip through and drain real user funds.
- Crypto users should treat official app store listings as untrusted by default, verify publishers, and watch how Apple responds to rising pressure over crypto scams.
Deep Dive
1. What The Founder Actually Did
According to a detailed community writeup, the DefiLlama founder 0xngmi claimed he deliberately used an app impersonating DefiLlama, allowed it to drain funds from his wallet, then documented the loss as evidence for Apple to remove the listing from its store.
He framed the move as sacrificing his own wallet to build a stronger case against the fraudulent app, turning a personal loss into a test of platform accountability rather than quietly avoiding the scam.
This followed earlier reporting of an App Store crypto scam lawsuit in July 2026 that alleged about $1.8 million in user losses, suggesting Apple was already under scrutiny for how it vets crypto apps.
A respected DeFi founder felt he had to take a real financial hit to get a fake app taken seriously by a major platform.
2. What It Shows About Fake Crypto Apps
The episode illustrates how polished impersonator apps can pass basic App Store checks and still be available to ordinary users as if they were legitimate.
It also echoes broader self custody risks, similar in spirit to hardware wallet incidents where a single compromised interface can lead to large losses, even when the underlying blockchain is functioning correctly.
Platforms like Apple are a critical trust layer for mainstream users. When fake apps get through, that trust can translate into misplaced confidence and direct exposure of wallets.
Marketplace approval is not proof of safety. In crypto, assuming if it is in the App Store it must be fine can be an expensive mistake.
3. How Crypto Users Can Respond
In practice, crypto users can reduce risk by only installing apps from verified publisher accounts, cross checking the app link from the projects official website, and avoiding any wallet connection until they have done that verification.
For existing installs, regularly auditing connected apps and permissions, and being cautious about signing transactions or approvals from any new interface, helps catch issues before funds move.
Watching whether Apple tightens crypto app review or responds publicly to cases like 0xngmis will be important for understanding how safe mainstream platforms are for self custody users.
Treat every new crypto app as untrusted until you can independently confirm the publisher, then keep permissions as minimal as possible.
Conclusion
0xngmis decision to sacrifice his own wallet highlights both the persistence of fake crypto apps and the limits of current app store defenses. For crypto users, the takeaway is simple: platform listing is not a security guarantee, and careful verification of any wallet connected app remains essential, regardless of how polished or official it appears.
