Simple Base SwapSimple Base SwapOpen app
← All articles
Sep 13, 2026·5 min read

Fake Wallet Apps: How to Spot a Malicious Download

basesecuritywalletsscams
base

Most people assume that anything listed in the Apple App Store or Google Play has already been checked and is safe to install. For crypto wallets, that assumption does not always hold. Fake wallet apps show up in official stores on a regular basis, and once a new seed phrase is typed into one, the funds behind it can be gone within minutes.

This article explains how these fake apps operate, what has actually been found in the wild, and a practical checklist you can use before installing any wallet.

What a fake wallet app actually does

A fake wallet app is built to look and feel like a real one. It usually copies the icon, the name (with small spelling changes), the color scheme, and the onboarding flow of a well known wallet. The core trick is almost always the same: the app asks you to "import" or "restore" a wallet by typing in your recovery phrase, and that phrase is quietly sent to a server controlled by the attacker.

Because a recovery phrase gives full control over every address it generates, the attacker does not need to hack anything else. They simply load your phrase into their own copy of a real wallet and move your funds out. Some fake apps skip this step entirely and instead present a wallet address that belongs to the attacker, so anything you send "into" the app goes straight to them.

What has been found in official app stores

This is not a hypothetical risk. In April 2026, security researchers at Kaspersky reported a campaign called FakeWallet: 26 malicious apps on Apple's App Store impersonating well known wallets, including MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie. The fake listings used names like "LeddgerNew," "TrustWalet," "Coinbsae," "imTokenPlus," "BitpiePro," and "TokenPocketX," close enough to the real names to pass a quick glance. Kaspersky linked the campaign to activity going back to at least the fall of 2025, and Apple removed many of the apps after the findings were disclosed.

A separate wave was found on Google Play around June 2026: more than 20 phishing apps impersonating decentralized exchange brands such as SushiSwap, PancakeSwap, and Hyperliquid, again designed to collect mnemonic phrases from anyone who tried to "connect" or "restore" a wallet inside them.

Both campaigns share the same pattern: a familiar brand name, a slightly altered spelling, a convincing interface, and a single screen asking for a recovery phrase.

Why this keeps happening

App store review processes check for things like malware signatures, disallowed API usage, and policy violations. They are not designed to verify that an app claiming to be "MetaMask" is actually made by the MetaMask team, especially when the app's code does not do anything technically illegal, such as making a normal-looking API request. A well made fake wallet can pass automated review and stay listed for weeks before it is reported and taken down.

Search rankings make this worse. A fake app with a generic name and a handful of paid or fake reviews can rank close to the real one, especially in regions where reviews are sparse or in less common languages.

How to check a wallet app before you install it

A few minutes of verification removes almost all of the risk.

  • Get the link from the source, not the store's search bar. Go to the wallet's official website (typed directly, not clicked from a search ad) and use the download link listed there. Coinbase Wallet, MetaMask, Trust Wallet, and other major wallets all link directly to their real store listings from their own sites.
  • Check the developer name, not just the app name. Every store listing shows a publisher name below the app title. Compare it against the developer name published on the wallet's official website or documentation. A mismatch is disqualifying on its own.
  • Look at install count and review history together. A wallet with millions of downloads and a two week old listing with 300 installs is not the same app, even if the icon matches exactly.
  • Be suspicious of anything that asks for a recovery phrase to "restore," "sync," or "verify" a wallet you did not previously create on that device. A real wallet only asks for your recovery phrase when you deliberately choose to import an existing wallet, and it does that inside the app itself, not on a web page it redirects you to.
  • Never enter a recovery phrase to receive a reward, airdrop, or support "fix." No legitimate wallet, exchange, or support agent will ever ask for it.

What Simple Base Swap does not need from you

Simple Base Swap connects to your existing wallet on Base. It never asks for your recovery phrase or private key, and it never asks you to import a wallet inside the app. If you are ever asked for that phrase while using a swap tool, a bridge, or a wallet app, stop and treat it as a red flag rather than a normal step.

The habit worth keeping

Treat every wallet app install the same way you would treat installing banking software: confirm the source before you confirm the install. A recovery phrase typed into the wrong app is not something a refund or a support ticket can undo. Checking the developer name and the install source takes less time than setting up the wallet itself, and it is the one step that actually protects the funds behind it.

Ready to try it yourself?

Create a non-custodial wallet on Base in seconds. No account, no sign-up.

Open the web app