45 Cryptocurrency Wallets in the App Store Put Users' Funds at Risk
- Igor Korsakov, CTO of BlueWallet, audited a universe of 494 applications in the store.
- The study differentiated the level of threat in 23 critical cases and 22 of high severity.
A technical analysis of 494 cryptocurrency wallets in the App Store, extracted from a total of 904 applications registered as non-custodial, revealed that 45 of them contain serious security flaws.
The study, conducted by Igor Korsakov, CTO of BlueWallet, identified that nearly 1 in 10 audited applications on iOS exposes users' funds. The report documents other specific attack vectors in the Apple store:
Sending secret phrases, mnemonic seeds, and private keys to remote databases such as Firestore, Heroku, or external domains. Among the exposed cases is Aura: Bitcoin Wallet, whose public code on GitHub suggests local execution, but its commercial binary on iOS sends recovery data to the server coffer.agency.
Poor encryption: creating seed phrases on centralized servers and using predictable mathematical functions (like Math.random for the BIP39 standard), eliminating the necessary entropy for the wallet to be secure.
Remote execution: unsigned JavaScript modules loaded from external servers without verifying if they have been altered by an attacker.
In practice, these deficiencies nullify the fundamental promise of self-custody: exclusive control of digital assets. By using one of these vulnerable applications, users' secret keys, equivalent to the access keys to a safe, are exposed to unauthorized transmissions to external servers.
Moreover, generating recovery phrases using predictable mathematical formulas allows third parties to calculate or guess access combinations, opening the door to remote draining of funds without requiring the owners' interaction.
<<There may be false positives, and an app not appearing on the list does not mean it is 100% secure>>, Korsakov clarified in his report published on kek.lol.
To audit the universe of 904 registered wallets, Korsakov extracted application packages using the ipatool tool and conducted a static code inspection, focused on JavaScript, supported by the Grok 4.6 xhigh model. Korsakov's report classifies 23 cryptocurrency wallets as critical and 22 with high vulnerability. Image created using Gemini.
The Real Impact: What Do These Flaws Mean for Users?
The finding raises doubts about Apple's security review. Although the App Store promises a closed and secure environment, this is not the first time its controls have failed.
In May 2026, Kaspersky detected 26 fake apps on iOS impersonating well-known brands like MetaMask and Coinbase. Apple faces legal lawsuits following the emergence of a fake Sparrow Wallet app that caused the theft of $1.8 million in Bitcoin.
So far, Apple has not commented on the removal of the flagged applications.
The report reignites the discussion about the fragility of single-signature solutions in mobile environments connected to the Internet. In light of the vulnerability of major app stores, the technical recommendation suggests:
Use the mobile app only for consultation: Set up the phone wallet solely to prepare transactions and check the balance, without storing secret keys on the device.
Use the mobile app only for consultation: do not store secret keys on the phone. Set up the mobile wallet solely to prepare transactions and check the balance, and require that the final authorization (the signature) is always done from a physical device disconnected from the internet (like Keystone or Foundation Devices).
Researcher Korsakov warns about the risks of using a single device to safeguard funds and recommends adopting multisignature schemes to protect digital assets. Source: X / overtorment.
In any case, it is also worth noting that the recent revelations about the App Store confirm that security in the bitcoin and cryptocurrency ecosystem is going through a critical stage, marked by the multiplication of attack vectors.
However, Igor Korsakov's analysis uncovers a new dynamic in cybersecurity, such as the use of artificial intelligence like Grok 4.6 xhigh to audit hundreds of applications in record time.
This same automation capability that now allows independent researchers to detect hidden flaws on a large scale is what malicious actors use to refine their deceptive offerings, automate malware creation, and find code breaches at unprecedented speed.
Therefore, the battle for digital custody no longer only pits users against cybercriminals, but also two faces of AI in a constant race to get ahead of the next security flaw.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Crypto vs Cash: 3 Clandestine Trading Posts Raided in London

Ethereum co-founder Vitalik Buterin argues that local AI can protect your privacy without losing speed

WEB3 Digital Nomads Don't Need a U Card That Only Allows Payments

Dialogue with OneKey's Wang Yishi: In the AI Era, Is the Hardware Wallet's Offensive and Defensive Battle Only 'Two Weeks' Left?

Vitalik Buterin Rejects the Idea That AI Hacks Condemn Cybersecurity

Sparrow Wallet Releases Version 2.5.5, Enhancing Security and Hardware Wallet Support

There are reportedly 290 individuals holding over 100 million dollars in crypto worldwide, including 23 billionaires

Arc Coin: Circle Minted 10 Billion Tokens, But Won't Commit to a Public Launch
Circle minted 10 billion ARC tokens for its new Arc blockchain but stressed it's not a commitment to ever let the public trade them.

All bank deposits in Venezuela now generate interest

Researchers Uncover Scheme of Fake Crypto Requests in Revolut

Bubblemaps Strengthens Pre-Verification System to Prevent 'Hunter Biden Meme Coin Crash'

How Foreign Institutions View the Diesel Crisis in September: Crack Spreads, Cost Transmission, and Stagflation Risks

Crypto Data Sent to Tax Authorities: Paymium and Bull Bitcoin Rejected

Bitcoin’s newest mobile privacy feature can make your incoming money completely invisible

Did LayerZero lose the private key that allows the creation of stablecoins for the State of Wyoming?

AI and the extinction of humanity: the $2 trillion danger?

18 Attorneys General Oppose Clarity Act Ahead of Key Senate Vote

From Concrete to Compute: Why Clichmont Is Building AI Infrastructure Instead of Renting It

NBIS Stock Faces a $200 Billion Funding Gap: Is Nebius Growing Too Fast?

Why Circle Is Building Its Own Blockchain? A Complete Breakdown Before the Arc Mainnet Launch

Digital Renminbi, Changed

Trump Opposes Strengthening AI Regulations, Emphasizes Technological Competition

Bankless's Successful Methodology for Portfolio Reallocation: How to Identify Undervalued Tokens from VVV to Hyperliquid?

Turing Quantum Releases TuringQ Gen3 Photonic Quantum Computer

The New Crypto Tycoon’s Gold Rush: Coinbase Co-Founder’s Venezuelan Oil Field Adventure

Ruthnick Reveals $250 Million Income... The Connection Between Tether, Cantor, and His Children Comes to Light

Planned Financial Crisis: the new global monetary architecture of the dollar

Morpho Proposes Transition of Mini App Operations to Feather

Dialogue with Fejau: The Next Round of the Bull Market for Digital Assets is Finally Here






