pull down to refresh

One of the Blue Wallet guys did a nice little survey of scammy self-custodial wallet apps in the app store.

  • Forked wallets used to be the usual move (there are a few BlueWallet forks), often reskinned poorly, now they moved to AI-recreated wallets from scratch ("Claude, make a wallet just like BlueWallet but with a brand-new codebase")
  • Appstore search, just like Google search, and ad placements, cannot be trusted
  • Reputation alone is not enough to trust software with lots of money
  • These apps get put wherever they can, even trying to get listed on bitcoin.org
  • Some have fake reviews ("been using this app for 2 years!" when the app is 2 months old)
  • Single device should NOT be the single signer for any meaningful amount of money

I doubt that many stackers would fall for scams like these, but it's important to remember that you should probably recommended a specific wallet to newbie friends and family or when orange-pilling someone. The app store is a jungle.

Single device should NOT be the single signer for any meaningful amount of money

Hmm I saw this exact text elsewhere yesterday. It sounds smart. Until someone needs to figure out multisig. Sees a "multisig manager" app on the same app store and it just replaces recipients in a psbt before signing.

Then what's the next word of caution gonna be? Never use apps.

Fine, so we buy a hardware wallet that we don't understand. Problem solved. Right?

Oh wait no now we need 3 hardware wallets.

reply

I'm curious how these scam apps optimize for their discoverability. Bot review farms?

And what is the point of marketing these app stores as curated if Apple/Google are gonna allow this shit?

reply

I suspect bitcoin wallets (and crypto generally) are just a really tiny portion of Apple/Google appstore downloads, so the scams just don't even register as far as they are concerned.

But it would be interesting to know how they hack the rankings so that they come up highly ranked.

reply

Yeah its fairly easy to automate reviews. Especially now that you can have a cowork agent do them from your phone or laptop.

reply

I would probably recommend Cake Wallet to most people despite it being multichain, since it handles both onchain and Lightning elegantly and allows beginners who have potentially e-waste worthy android phones to turn that old phone into an external signer (the Cupcake app).

Also Blitz is good for a pure-Lightning wallet that uses Spark and has some stablecoin and onchain BTC capabilities. They also introduced "managed accounts" so that you can manage the recovery for someone that trusts you who doesn't want to deal with seed phrases.

reply

Great report. I checked http://kek.lol/research and many of those wallets use closed-source code and request seed phrase backup to their server. That's not self-custody. One should be vigilant and always verify if the wallet is open source + doesn't upload seed. Thanks for sharing @Scoresby.

reply