45 Cryptocurrency Wallets in the App Store Put Users' Funds at Risk
- Igor Korsakov, CTO of BlueWallet, audited a universe of 494 applications in the store.
- The study differentiated the level of threat in 23 critical cases and 22 of high severity.
A technical analysis of 494 cryptocurrency wallets in the App Store, extracted from a total of 904 applications registered as non-custodial, revealed that 45 of them contain serious security flaws.
The study, conducted by Igor Korsakov, CTO of BlueWallet, identified that nearly 1 in 10 audited applications on iOS exposes users' funds. The report documents other specific attack vectors in the Apple store:
Sending secret phrases, mnemonic seeds, and private keys to remote databases such as Firestore, Heroku, or external domains. Among the exposed cases is Aura: Bitcoin Wallet, whose public code on GitHub suggests local execution, but its commercial binary on iOS sends recovery data to the server coffer.agency.
Poor encryption: creating seed phrases on centralized servers and using predictable mathematical functions (like Math.random for the BIP39 standard), eliminating the necessary entropy for the wallet to be secure.
Remote execution: unsigned JavaScript modules loaded from external servers without verifying if they have been altered by an attacker.
In practice, these deficiencies nullify the fundamental promise of self-custody: exclusive control of digital assets. By using one of these vulnerable applications, users' secret keys, equivalent to the access keys to a safe, are exposed to unauthorized transmissions to external servers.
Moreover, generating recovery phrases using predictable mathematical formulas allows third parties to calculate or guess access combinations, opening the door to remote draining of funds without requiring the owners' interaction.
<<There may be false positives, and an app not appearing on the list does not mean it is 100% secure>>, Korsakov clarified in his report published on kek.lol.
To audit the universe of 904 registered wallets, Korsakov extracted application packages using the ipatool tool and conducted a static code inspection, focused on JavaScript, supported by the Grok 4.6 xhigh model. Korsakov's report classifies 23 cryptocurrency wallets as critical and 22 with high vulnerability. Image created using Gemini.
The Real Impact: What Do These Flaws Mean for Users?
The finding raises doubts about Apple's security review. Although the App Store promises a closed and secure environment, this is not the first time its controls have failed.
In May 2026, Kaspersky detected 26 fake apps on iOS impersonating well-known brands like MetaMask and Coinbase. Apple faces legal lawsuits following the emergence of a fake Sparrow Wallet app that caused the theft of $1.8 million in Bitcoin.
So far, Apple has not commented on the removal of the flagged applications.
The report reignites the discussion about the fragility of single-signature solutions in mobile environments connected to the Internet. In light of the vulnerability of major app stores, the technical recommendation suggests:
Use the mobile app only for consultation: Set up the phone wallet solely to prepare transactions and check the balance, without storing secret keys on the device.
Use the mobile app only for consultation: do not store secret keys on the phone. Set up the mobile wallet solely to prepare transactions and check the balance, and require that the final authorization (the signature) is always done from a physical device disconnected from the internet (like Keystone or Foundation Devices).
Researcher Korsakov warns about the risks of using a single device to safeguard funds and recommends adopting multisignature schemes to protect digital assets. Source: X / overtorment.
In any case, it is also worth noting that the recent revelations about the App Store confirm that security in the bitcoin and cryptocurrency ecosystem is going through a critical stage, marked by the multiplication of attack vectors.
However, Igor Korsakov's analysis uncovers a new dynamic in cybersecurity, such as the use of artificial intelligence like Grok 4.6 xhigh to audit hundreds of applications in record time.
This same automation capability that now allows independent researchers to detect hidden flaws on a large scale is what malicious actors use to refine their deceptive offerings, automate malware creation, and find code breaches at unprecedented speed.
Therefore, the battle for digital custody no longer only pits users against cybercriminals, but also two faces of AI in a constant race to get ahead of the next security flaw.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Understanding the Tokenomics of Crypto Projects and Why It Matters

The biggest vulnerability in your Bitcoin wallet might be the shipping label

Wealth Managers Prepare for More Crypto Allocations

Commodity Market Exchange: What to Consider Before Trading

Ethereum Tests Glamsterdam Ahead of Expected Launch in December

Can Bitcoin Really Reach $400,000 by 2030?

Cryptocurrencies as an Economic Noose for Russia: Pyramids, Bitcoin, and the Global Casino

ChatGPT Serves Criminals: Crypto Investor Lost $2,100,000 After Chatbot's Advice

Cryptocurrency for Consultants: Hyperliquid and the Future of Financial Markets

Lean Ethereum: the most ambitious plan in crypto, or a last chance overhaul?

XRP in Japan: The Price of a Billion-Dollar Bet Reshaping the Banking System

Italy's Second Largest Bank Evaluates Offering Services with Bitcoin and Cryptocurrencies

唐华斑竹: WEEX Covers Over 2,500 Global Assets, Platinum Sponsor at TOKEN2049 Singapore

Visa's $2.5 Billion On-Chain Business: Pre-Funding Issuers and Using Smart Contracts for Collections

The dilution trap where Bitcoin holdings rise while shareholder value stalls

BRICS: Russia Settles 90% of Its Transactions in Local Currencies

What is Bifrost (BFC)? The Reason 40.79% of the Supply is in the Burn Address

What is ORE (ORE)? Reasons for Minting Authority Activation on Solana

Bankless's Successful Methodology for Portfolio Reallocation: How to Identify Undervalued Tokens from VVV to Hyperliquid?

UK crypto firms get five-month window to seek FCA approval

Follow the Money: Over $200 Million in Venture Investments, $400 Million Purchase, and Weak Activity from Corporate Investors

The New Crypto Tycoon’s Gold Rush: Coinbase Co-Founder’s Venezuelan Oil Field Adventure

Crypto VC funding: Payward’s $100M deal leads Latitude’s $35M round

Blockstream bets 600 Bitcoin by rejecting Liquid hacker’s $50 million bounty demand

Blockchain, Rupee and Bonds: India Modernizes Its Financial Market

Raoul Pal in Conversation with Wall Street Strategist Jordi Visser: Why Now is the Best Time to Invest?

What is FOMO and FUD? The Trading Minute

FTX Founder Sam Bankman-Fried Appeals Fraud Conviction to U.S. Supreme Court

Ruthnick Reveals $250 Million Income... The Connection Between Tether, Cantor, and His Children Comes to Light





