Ethereum Seed-Phrase Scam App Removed After 1 Test Drain

ETH

ETH/USDT

$1,885.05
+0.27%
24h Volume

$1,740,879,996.02

24h H/L

$1,886.59 / $1,876.01

Change: $10.58 (0.56%)

Long/Short
66.5%
Long: 66.5%Short: 33.5%
Funding Rate

+0.0043%

Longs pay

Data provided by COINOTAG DATALive data
Ethereum
Ethereum
Daily

$1,883.03

0.04%

Volume (24h): -

Resistance Levels
Resistance 3$2,021.00
Resistance 2$1,932.58
Resistance 1$1,899.99
Price$1,883.03
Support 1$1,878.82
Support 2$1,840.42
Support 3$1,788.81
Pivot (PP):$1,879.26
Trend:Sideways
RSI (14):51.1
(09:29 PM UTC)
4 min read
AI SummaryAI
  • DeFiLlama founder 0xngmi installed a counterfeit App Store app on Aug. 15, 2026, and let it drain a small wallet.
  • Apple removed the fake DeFiLlama app within days after receiving evidence that it drained funds.
  • The counterfeit app requested secret recovery phrases, which can authorize transfers of Ether and other tokens.
  • The disclosure said know-your-customer checks were completed through a defunct shoe-polish business founded about 40 years ago.

Crypto News

The most urgent security event in the past 24 hours centers on a fake analytics application that targeted self-custody wallets, including wallets that hold Ethereum (ETH). On Aug. 15, 2026, 0xngmi, the anonymous founder of DeFiLlama, publicly described how he deliberately installed a counterfeit DeFiLlama app from Apple's App Store after months of unresolved impersonation complaints. He funded a small wallet, allowed the app to drain it, and submitted that live demonstration to Apple as evidence that the listing was malicious. The company removed the app within days, according to the founder's account. The underlying mechanism was simple but dangerous: the fake product presented itself as a basic version of DeFiLlama and prompted users to enter their secret recovery phrase. That phrase is the master key for a self-custody wallet and can authorize transfers of Ether and other tokens without further consent. The founder said the same operators had repeatedly submitted lookalike apps for well-known crypto brands and had cleared App Store verification by using dormant corporate identities. In the DeFiLlama case, the disclosure said the bad actors completed know-your-customer checks through a small shoe-polish business that was founded roughly 40 years ago and no longer operates. The team also said it delayed its legitimate app launch by several months so users would not accidentally download a scam during the cleanup period. He said he published the sequence so other crypto teams would not waste months navigating the same reporting channels. DeFiLlama also maintains LlamaSearch, a directory of vetted crypto domains, because search results and app-store listings are frequently manipulated. This is a warning for every altcoin user: distribution through a major app marketplace does not guarantee authenticity, and any interface requesting a seed phrase should be treated as hostile. Even a product associated with a widely used AI crypto wallet workflow can be imitated, so verification must happen before funds are exposed.

The second layer of the story is that impersonation is not confined to app stores. The same incident timeline describes paid-search and cloned-website attacks that directly hit users of decentralized trading venues. On Aug. 14, 2026, one Hyperliquid user lost about $550,000 in USDC after a paid Google ad directed the victim to a counterfeit version of the platform. In May 2026, a separate fake Google advertising campaign drained over $400,000 from Uniswap users, with the on-chain trail showing roughly 146 ETH sent to two attacker-controlled addresses. Those flows show why Ethereum (ETH) remains central to this security discussion: when a seed phrase or site interaction is compromised, the resulting transfers are visible on-chain and often rapid. The DeFiLlama founder's disclosure said the operators behind the fake apps also mimicked other prominent crypto brands and passed identity checks using defunct companies, which suggests an organized effort rather than a one-off listing abuse. For users, the practical lesson is that an official storefront or a sponsored search result is not a safety certificate. Before connecting a wallet, the domain should be checked against a trusted directory, bookmarks should be used for frequent destinations, and any request for a recovery phrase should be refused outright. Teams building around AI trading bot interfaces or analytics dashboards need to treat brand protection as part of user safety, not merely legal hygiene. The warning applies regardless of whether a token is trading near an all-time-high or far below it. The delay of DeFiLlama's authentic mobile release underscores the cost: even a well-known analytics provider had to postpone its app for months while counterfeit listings were pursued. This pattern also matters for market integrity, because a victim who loses funds in a fake interface may be holding any altcoin, but Ethereum-based tokens and decentralized exchange flows remain among the most visible targets.

COINOTAG's analysis ties both episodes to one arc: crypto users are being attacked through trusted distribution channels rather than protocol failures. The primary evidence is direct: the DeFiLlama founder's Aug. 15 disclosure documents a seed-phrase harvesting app, a deliberately funded test wallet, and Apple's removal after demonstrated theft; on-chain records referenced in the wider phishing timeline show about 146 ETH moving to two addresses in the May Uniswap case. No attacker hash or formal post-mortem for the DeFiLlama test drain was published in the available disclosure, and the amount was intentionally small. The root cause is credential capture, not a smart-contract exploit. Remediation is removal of the fake listing, delayed official launch, and user-side refusal to enter recovery phrases.

Add COINOTAG as a Preferred Source

Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.

Add on Google
James Mitchell

James Mitchell

COINOTAG author

View all posts
AI-AssistedSenior Technical Analyst·James Mitchell is a senior technical analyst with over six years of dedicated cryptocurrency market analysis experience.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Comments

Comments