Invest2 publishers3 min readPublished Updated
Apple removed a fake DeFiLlama app only after it stole money. Budget accordingly.
DeFiLlama says months of trademark reports achieved nothing, so it fed a funded wallet to the impersonator. Brand enforcement on the App Store now looks like a cost line, not a right.
The Investor · Invest desk

What happened
- DeFiLlama funded a small wallet, connected it to a fraudulent app impersonating DeFiLlama on Apple's App Store, and allowed the app to drain the funds; it then presented the evidence of theft to Apple, and the app was removed within days.
- DeFiLlama flagged the fake app to Apple for trademark infringement multiple times over a period of several months, and the reports went nowhere.
- DeFiLlama founder 0xngmi disclosed the episode publicly, describing a cycle of filed reports that produced no action.
- The effective removal threshold was documented loss rather than a documented trademark complaint: several months of trademark reports produced no removal, while evidence of a drained wallet produced removal within days.
- 0xngmi did not disclose how much was in the sacrificial wallet or specify the exact dates of the test drain.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
DeFiLlama funded a wallet, connected it to a counterfeit version of itself on Apple's App Store, and let the app drain the money so it would have documented theft to hand to Apple; the app was removed within days [1]. According to founder 0xngmi's public account, the team had already filed trademark infringement reports against the same app multiple times across several months and got nowhere [2][3].
Read those two facts together and you get a working policy, whatever the written one says: a trademark complaint, however well documented, did not move the queue, and evidence of funds leaving a wallet did [4]. The latency gap is the point. Months of correctly filed reports produced no removal; one drained wallet produced action in days [4].
The direct cost of that experiment was small. DeFiLlama loaded only a small amount into the sacrificial wallet, and 0xngmi did not disclose the exact figure or the dates of the test [1][5]. The expensive part was the waiting. While the impersonator stayed live, DeFiLlama held back the launch of its own official app on the reasoning that shipping a legitimate version alongside a fake one would only confuse users [6]. DeFiLlama aggregates total value locked across hundreds of protocols [7], and Cryptobriefing reports that an official mobile app would serve millions of users who currently rely on the web version [8]. So the counterfeit did not just steal from one test wallet. It occupied a distribution channel the real product had decided it could not safely enter.
For anyone running a consumer-facing crypto or fintech brand, that reframes impersonation from a legal problem into a budget problem with three lines. First, detection and repeat filing, which on this evidence may produce no result on its own [2][3]. Second, an evidence kit, which in DeFiLlama's case meant deliberately paying a thief in order to generate an admissible-looking loss [1]. Third, and largest, the deferred launch: revenue and adoption you postpone because your own store listing would sit next to a clone [6].
Two caveats worth keeping. The whole account comes from the affected party's public disclosure, and Cryptobriefing, republishing via blockchainreporter.net, reports no identifying information about the developers behind the fraudulent app [3][9][10]. And the method itself is awkward to institutionalise: it requires knowingly sending customer-adjacent funds to a criminal to create the record [1], which is a different risk posture than filing paperwork.
Apple has long marketed its review process as a user safeguard rather than a restriction [11]. Cryptobriefing's assessment is that a known, repeatedly reported scam app surviving months of complaints undercuts that positioning [11].
What to watch: whether DeFiLlama now ships its official app, and how fast a replacement clone appears once it does [6]; whether Apple's trademark-only reporting path shows any change in response time for other projects filing the same kind of complaint [2]; and whether teams start pre-provisioning a small monitored wallet as standard brand-protection tooling rather than improvising one under pressure [1]. In the meantime the user-side advice has not changed: verify the developer and take app links from the project's own site or channels before connecting a wallet [12].