45 Cryptocurrency Wallets in the App Store Put Users' Funds at Risk
- Igor Korsakov, CTO of BlueWallet, audited a universe of 494 applications in the store.
- The study differentiated the level of threat in 23 critical cases and 22 of high severity.
A technical analysis of 494 cryptocurrency wallets in the App Store, extracted from a total of 904 applications registered as non-custodial, revealed that 45 of them contain serious security flaws.
The study, conducted by Igor Korsakov, CTO of BlueWallet, identified that nearly 1 in 10 audited applications on iOS exposes users' funds. The report documents other specific attack vectors in the Apple store:
Sending secret phrases, mnemonic seeds, and private keys to remote databases such as Firestore, Heroku, or external domains. Among the exposed cases is Aura: Bitcoin Wallet, whose public code on GitHub suggests local execution, but its commercial binary on iOS sends recovery data to the server coffer.agency.
Poor encryption: creating seed phrases on centralized servers and using predictable mathematical functions (like Math.random for the BIP39 standard), eliminating the necessary entropy for the wallet to be secure.
Remote execution: unsigned JavaScript modules loaded from external servers without verifying if they have been altered by an attacker.
In practice, these deficiencies nullify the fundamental promise of self-custody: exclusive control of digital assets. By using one of these vulnerable applications, users' secret keys, equivalent to the access keys to a safe, are exposed to unauthorized transmissions to external servers.
Moreover, generating recovery phrases using predictable mathematical formulas allows third parties to calculate or guess access combinations, opening the door to remote draining of funds without requiring the owners' interaction.
<<There may be false positives, and an app not appearing on the list does not mean it is 100% secure>>, Korsakov clarified in his report published on kek.lol.
To audit the universe of 904 registered wallets, Korsakov extracted application packages using the ipatool tool and conducted a static code inspection, focused on JavaScript, supported by the Grok 4.6 xhigh model. Korsakov's report classifies 23 cryptocurrency wallets as critical and 22 with high vulnerability. Image created using Gemini.
The Real Impact: What Do These Flaws Mean for Users?
The finding raises doubts about Apple's security review. Although the App Store promises a closed and secure environment, this is not the first time its controls have failed.
In May 2026, Kaspersky detected 26 fake apps on iOS impersonating well-known brands like MetaMask and Coinbase. Apple faces legal lawsuits following the emergence of a fake Sparrow Wallet app that caused the theft of $1.8 million in Bitcoin.
So far, Apple has not commented on the removal of the flagged applications.
The report reignites the discussion about the fragility of single-signature solutions in mobile environments connected to the Internet. In light of the vulnerability of major app stores, the technical recommendation suggests:
Use the mobile app only for consultation: Set up the phone wallet solely to prepare transactions and check the balance, without storing secret keys on the device.
Use the mobile app only for consultation: do not store secret keys on the phone. Set up the mobile wallet solely to prepare transactions and check the balance, and require that the final authorization (the signature) is always done from a physical device disconnected from the internet (like Keystone or Foundation Devices).
Researcher Korsakov warns about the risks of using a single device to safeguard funds and recommends adopting multisignature schemes to protect digital assets. Source: X / overtorment.
In any case, it is also worth noting that the recent revelations about the App Store confirm that security in the bitcoin and cryptocurrency ecosystem is going through a critical stage, marked by the multiplication of attack vectors.
However, Igor Korsakov's analysis uncovers a new dynamic in cybersecurity, such as the use of artificial intelligence like Grok 4.6 xhigh to audit hundreds of applications in record time.
This same automation capability that now allows independent researchers to detect hidden flaws on a large scale is what malicious actors use to refine their deceptive offerings, automate malware creation, and find code breaches at unprecedented speed.
Therefore, the battle for digital custody no longer only pits users against cybercriminals, but also two faces of AI in a constant race to get ahead of the next security flaw.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Trump Opposes Strengthening AI Regulations, Emphasizes Technological Competition

Bankless's Successful Methodology for Portfolio Reallocation: How to Identify Undervalued Tokens from VVV to Hyperliquid?

Turing Quantum Releases TuringQ Gen3 Photonic Quantum Computer

The New Crypto Tycoon’s Gold Rush: Coinbase Co-Founder’s Venezuelan Oil Field Adventure

Ruthnick Reveals $250 Million Income... The Connection Between Tether, Cantor, and His Children Comes to Light

Planned Financial Crisis: the new global monetary architecture of the dollar

Morpho Proposes Transition of Mini App Operations to Feather

Dialogue with Fejau: The Next Round of the Bull Market for Digital Assets is Finally Here

Real Review of World.xyz: Millisecond Trading and Betting Against Market Makers

CLARITY Act After September 15: Three Scenarios for How Crypto Markets Could React
Three different outcomes could follow September 15's vote and the market reaction depends less on pass or fail than on which specific version actually happens.

Ethereum Tentatively Sets Test Implementation Date for Glamsterdam

Teacher's Day: How Much Teachers Earn in Argentina and Which Province Pays the Best

ZEC Rises into the Top Ten, Old Controversies Resurface

Canadian Financial Authority Treats Tokenized Deposits as Equivalent to Traditional Deposits

Solana Launches Prediction Market Amid Technical Hurdles

Dark energy may be changing, according to a study of 3,000 supernovae

Rising Oil Prices Recalibrate the Landscape for Argentine Investors: Which Alternatives Are Gaining Ground

Novig Launches First Brand Ad 'Just Sports' Featuring Star Sydney Sweeney

What is Beldex (BDX)? Why are over 2 billion unlisted?

Bankless Latest Podcast: How to Find Undervalued Tokens from VVV to Hyperliquid?

Is the Current Pullback a Buying Opportunity as Long as We Are Not in a Rate Hike Cycle?

Residency in Paraguay: the hidden cost of the new exit door for Brazilians

Apple Unveils iPhone 18 Pro: Camera, Battery, and Siri AI

Bonk Guy Turns Bullish on Solana, Supports On-Chain Community

Decentralized Bitcoin Poker: Satoshi's Vision Redefines On-Chain Gaming

What is Kaspa (KAS)? The Mechanism of BlockDAG that Recovered a $1 Billion Scale

US Police Warn of Meta Glasses Recording Inside Facilities

European Funds Leave the US: A Chance for France and Bitcoin?

Digital Euro Privacy: The Technical Detail That Compromises Autonomy







