The App Store Is the Exploit: Fake Sparrow Wallets Drain Seed Phrases While Apple Threatens the Real Developer

CryptoPomp NFT

The App Store Is the Exploit: Fake Sparrow Wallets Drain Seed Phrases While Apple Threatens the Real Developer

Hook

The first counterfeit Sparrow Wallet sat on the Apple App Store for over a year. Craig Raw found it in March 2024, documented it with cryptographic proof, flagged the code-signing mismatch, shared screenshots of victims' chat logs, and submitted multiple takedown requests. Apple's reply was not a thank-you. It was a threat to terminate his developer account for harassment. The fake app kept harvesting seed phrases the entire time. Then class-action complaints landed in a California federal court, and the world's most valuable distribution platform suddenly had a legal problem bigger than a bad review.

This is not a chain-level exploit. It is not a smart contract vulnerability or a consensus bug. It is an infection at the last mile of self-custody: the exact moment a user decides which software is trustworthy. That mile does not belong to Bitcoin or Ethereum anymore. It belongs to the review queues of two American technology companies. And this week's filing is the first serious attempt to demand legal accountability for one of those queues.

Context

Sparrow Wallet is not an obscure tool. It is the standard-bearer for uncompromising self-sovereignty: Bitcoin-only, deterministic builds, hardware wallet integration, and no remote key access. It has no official iOS app. It is distributed through GitHub and its own website, with reproducible builds and published signing keys. The irony is sharp and sickening. A project designed to eliminate every possible dependency on centralized trust found its brand weaponized on the platform that millions of Chinese-speaking newcomers use as the only safe doorway to the internet.

The lawsuit, filed in the Northern District of California, alleges that Apple breached its duty of care and violated consumer-protection statutes by hosting and promoting counterfeit financial software. The named plaintiffs include users who lost what they described as life savings to a fake wallet that appeared as a top search result in the localized Chinese version of the App Store. The complaint is not a blanket screed against centralized platforms; it highlights a specific, repeated failure. After the real developer raised complaints for months with evidence of code-signing mismatches and on-chain loss screenshots, Apple reportedly responded with a threat: if he kept identifying fraudulent impersonators, his own developer account would be terminated for harassment.

That is a perverse inversion of the security function. A platform built to keep the gates eventually protected the intruders more efficiently than it protected the residents.

Sparrow was not the only victim. SlowMist, a mainstream Chinese blockchain security firm, has documented dozens of iOS wallets that are repackaged shells of fake apps, often masquerading as popular brands such as MetaMask, Trust Wallet, Coinbase Wallet, and Ledger Live. The activity is not random; it is clustered around networks that advertise on WeChat and Telegram, using the App Store's localized listings to hide in plain sight. In late 2024, a well-known Chinese venture capitalist posted about losing more than $10 million to a counterfeit hardware wallet companion app that asked him to synchronize his Ledger. The scam factory behind these applications goes by the moniker SparkKitty or similar splinter groups, and its toolchains keep getting reused because they work.

Understanding why they work requires understanding the fundamental mismatch between Web2 distribution and Web3 custody. The App Store sells trust through reputation, icons, and screenshots. A Bitcoin wallet sells security through math, code, and signatures. When a user clicks "Install" on a shopping app, the worst consequence is a defective product. When a user clicks "Install" on a wallet app, the worst consequence is total financial annihilation. Yet the verification ceremony is identical: a button, a fingerprint scan, and a progress bar.

That mismatch is the exploitable vulnerability in every mobile on-ramp to crypto. The attack does not need a zero-day in the Bitcoin protocol. It only needs a user who believes that Apple's review process is an audit. And Apple's entire marketing ecosystem encourages exactly that belief.

Core: The Anatomy of the Impersonation Ride

First, the attacker registers a developer account, using leaked or purchased identity documents. Apple's identity verification is famously strict for individual accounts but less strict for corporate accounts; many fake apps surface under names like Sparrow Wallet Studio or Sparrow Wallet Official. Nothing in the automated review catches the discrepancy because there is no App Store listing on the project's official website to cross-check. Trademark verification for open-source projects is nonexistent. Apple simply checks app name collisions within its own database, and Sparrow Wallet was not a registered iOS app name. So the fake fills the vacuum.

Second, the fake is deliberately not global. It submits localized metadata in Simplified Chinese, stores its malicious payload behind feature flags or language-based logic, and routes around the reviewer's geography. Standard App Review happens in a controlled environment; the scam app behaves like a harmless wallet for the English tester, but for the Chinese user downloading from the localized storefront, the welcome screen contains a verification flow after the first backup. The user, primed by years of bank KYC-style processes, types the seed phrase into a modal that visibly displays "Your backup is the key" — a polite fiction.

Third, the money moves fast. The moment a seed phrase is transmitted, the app encrypts it and shuttles it to a hardcoded API endpoint. The attackers do not sweep the wallet immediately; they wait until the balance is large enough to justify the risk. When the sweep happens, the funds are chained: Bitcoin via native segwit to outputs that route through CoinJoin implementations or Lightning-based shuffling services; Ethereum and BNB Chain through any of a dozen cross-chain bridges that do not require KYC. This is not a mistake; it is a supply chain. The entire industry keeps optimizing onboarding speed, but the fake wallet optimizes exit speed.

I have done this forensic pattern before. In the 2017 Parity heist, I spent 48 hours tracing the initWallet reentrancy path because the initial press releases had already gotten the vulnerability category wrong. The lesson then was that code-level forensics matter more than headlines. The lesson here is similar, but more uncomfortable: the vulnerable code in this exploit is the process by which users assign trust. There is no transaction hash that reveals Apple's negligence. The hash just goes to the abyss.

Volume figures are the classic lie in this business. The number of reported phishing apps in the App Store over the past two years, as aggregated by SlowMist and Web3 security firms, shows this is not an outlier. The volume of lost funds is in the hundreds of millions, but the public chart shows only early exits. Volume spikes lie; liquidity flows tell the truth. The liquidity flow reveals something more dangerous: the stolen funds increasingly leave the visible chain quickly, pooled through service providers that do not require user identification. A large chunk exits into Lightning, into CoinJoin pools, into the very privacy tools this industry proudly built. The tooling of self-sovereignty becomes the tooling of theft.

The 14-Month Chronology of Dismissal

Craig Raw is a meticulous developer. When he encountered the first fake Sparrow listing, he did not merely complain; he documented. He compared the fake app's code signature against the official signing key. He traced its network requests and showed that they terminated at servers with no relation to the Sparrow project. He collected chat logs from victims in Chinese-speaking communities confirming that they had been directed to download the fake from the App Store because it was safer than a website. That last detail matters more than any SSL certificate: the victims trusted the App Store more than they trusted the project's own site, and that trust was the attack surface.

Apple's responses were procedural automata. Takedown notices were handled by a content-review team that had no visible crypto expertise. One support agent told Raw that the situation was a dispute between two apps and that Apple could not arbitrate owner conflicts, despite Raw providing cryptographic proof of ownership. When Raw persisted, the threat of account termination arrived. For a small open-source developer, that threat is existential: lose the developer account, lose access to any future iOS releases, and undermine the project's release strategy. Apple's message was chilling in its simplicity: do not police our store.

Apple eventually removed some of the counterfeit apps, but only after the class-action press cycle made them a liability. That is the wrong sequence. Security models that rely on post-incident takedowns are security models that fail. Speed is safety when the exploit is already live. Yet Apple's takedown ecosystem moves at the speed of a DMCA lawyer's Monday morning, not at block time. In January 2024, when the BlackRock ETF approval triggered a wave of institutional Bitcoin buying, I tracked the on-chain flows into ETF custodians and noticed that retail sellers were feeding the same liquidity pools that fake wallets were using for exit. The chart didn't show the connection between the silent buy wall and the scam drainage; it only showed two lines moving in opposite directions. But the operators of the fake apps were watching the same chart. They knew they had a short window before Apple noticed. They exploited it perfectly.

The court filing includes emails and support tickets that paint a grotesque picture: a security researcher doing the platform's job for free, getting punished for it. That dynamic should terrify anyone who cares about App Store integrity. If the response to responsible disclosure is a threat to the whistleblower, then the only disclosures that will ever happen are the ones that leak to Twitter and go viral. And by then, the funds are already gone.

The App Store Is the Exploit: Fake Sparrow Wallets Drain Seed Phrases While Apple Threatens the Real Developer

The User-Side Failure Nobody Wants to Admit

The most uncomfortable part of this event is not Apple's negligence; it is the user's willingness to input seed phrases into an app they did not compile. For two decades, the crypto industry has taught one rule: not your keys, not your coins. In practice, the rule has been translated into store your keys in a wallet app. The nuance — you must verify the wallet software itself — was lost in the marketing noise.

The App Store endorsement does not verify the code. It verifies that the binary passed a static smoke test, that it does not misuse private APIs, and that its screenshots are not obviously fraudulent. For a financial credential manager, that level of review is like a building inspector who checks the paint color and the door sign but not the foundation.

Here is the hard truth from my own forensic experience, from the Curve Finance treasury drain in 2020 to the Terra collapse in 2022: most losses in crypto are not caused by protocol bugs. They are caused by the gap between what users think they are using and what they are actually using. In 2020, I watched a compromised hot wallet key drain millions from a treasury because the team had stored the key in an environment with weaker controls than the community assumed. In 2022, I tracked major market makers quietly exiting Terra positions days before the crash, while the public narrative still blamed outside manipulators. In both cases, the technical surface looked fine. The flaws lived in operational trust models. This case is exactly the same pattern, transplanted to the mobile layer.

A fake wallet asks for a seed phrase under the guise of backup verification. The user does not know that legitimate wallets never ask for the seed phrase after creation. The user does not know that the app's quarantine transcript can be different from the app's store listing. The user does not know that Apple's review process cannot detect a malicious feature flag triggered by language settings. The user knows one thing: the app has the Apple seal on it. That seal is worth more than every security education campaign combined.

The industry spends millions on conference panels about self-custody while simultaneously telling new users to download the wallet from the App Store, as if the distribution channel were a neutral highway. It is not neutral. It is the choke point where the entire sovereignty argument collapses. We don't get to claim decentralized sovereignty while our distribution model is a phone store. That is the uncomfortable contradiction the court filing exposes.

The Market Contagion

This event does not move BTC's price. It moves something slower and more corrosive: user trust in the entire onboarding layer. When a new user in Jakarta or Shanghai watches a YouTube tutorial that says download the wallet from the App Store, and then sees news that fake wallets are sitting in the App Store, their brain registers crypto as a scam. That is the true systemic risk. It does not show up in funding rates, but it shows up later in retail inflow.

The contagion extends to hardware wallet manufacturers. Ledger and Trezor have spent years telling users that the seed never leaves the device. The fake apps attack that exact claim by saying: enter your existing Ledger seed to sync your devices. One Chinese venture capitalist lost $10 million because a convincing replica of the Ledger Live companion app had been installed from the App Store. The hardware wallet was cold. The user's trust was not. The cold storage philosophy is only as strong as the software that surrounds it. If the companion app is fake, the coldest key becomes a warm surrender.

This is the 2021 Bored Ape YCIP-001 legal nightmare all over again, but worse. Back then, the flaw was in a licensing clause that could be renegotiated with a governance vote. Here, the flaw is in the human habit of trusting store badges. You cannot patch a habit with a smart contract. You can only replace it with a better ritual. Legal action against Apple may produce damages, but it will not produce the new ritual. That work belongs to the wallet developers, the security researchers, and the user education community. And so far, the work has not kept pace with the attackers.

Contrarian: What the Dominant Narrative Gets Wrong

The dominant framing says Apple must be held accountable for failing to police its store. That framing is true but incomplete, and it points the industry toward a dangerous remedy. Let me push against the consensus. Let me be the annoying analyst who refuses to cheer for the lawsuit.

First, if Apple is held liable in this case, the rational corporate response is not a better security review. It is to eliminate the category entirely. Imagine a future App Review Guideline, section 3.14: Applications that enable the transmission of noncustodial cryptographic private keys may not be distributed. Apple can avoid legal liability not by hiring more crypto experts but by refusing to host any software that controls private keys. That would be a catastrophic outcome for the global adoption of self-custody. It would push all wallet distribution into obscure APK sites and sideloading, where the exact same scams will thrive with even less oversight. The lawsuit's victory lap could easily become the on-ramp's headstone.

The legal framework matters here. Section 230 of the Communications Decency Act has historically protected online platforms from liability for third-party content. But Apple has argued for years that its App Store is not a mere distributor; it is an active curator that reviews every submission. That curation claim is what makes this case interesting. If Apple's curated review process is the reason users trust it, then Apple cannot simultaneously claim immunity when that review fails. A court could find that Apple has created a duty of care by promising to filter malicious software. And that finding would be catastrophic for Apple's business model, because the only safe way to avoid the duty is to stop curating. If Apple stops curating, the quality of the entire App Store collapses. If Apple continues curating, it must invest billions in crypto-specific review. Either outcome reshapes the iOS ecosystem. The industry should be careful what it wishes for.

Second, the real blind spot is not Apple's review queue. It is the industry's own confusion about where trust should live. For a decade, the narrative has been don't trust centralized exchanges, use a noncustodial wallet. But we have simultaneously outsourced the critical security decision — which wallet binary is the true one — to centralized gatekeepers. The Don't Trust, Verify principle must apply to the distribution layer itself. The industry should treat an app's cryptographic signature like a first-class citizen, not a gray footnote. Every wallet should ship a verification script that checks the binary against a public registry of hashes. Wallet developers should build a fingerprint check into the app, so that users can verify the sha256 hash of the installed build before entering seed phrases. This is not technologically difficult. It is simply a commitment that the industry rarely honored because distributing an app through the store feels easier.

Third, the attack is not exclusively an App Store failure. Enterprise certificates and TestFlight pipelines allow attackers to install fake apps directly onto iPhones without any App Store review whatsoever. Many of the most damaging SparkKitty campaigns used enterprise signing, which users accept because they have been taught to trust the Apple logo. Apple's review failure is real, but the criminal industry has multiple distribution tunnels: enterprise distribution, TestFlight, malicious configuration profiles, and web-based PWAs with the Add to Home Screen feature. A courtroom that blames only the App Store misses the fact that the enemy is adaptive. They cheerfully shifted to these tunnels every time Apple removed a listing. The app store is an attack vector; the platform trust is the cannon. And the cannon has more than one barrel.

Fourth, the class-action structure itself is crude. The complaint demands damages for victims, but it does not demand what the ecosystem actually needs: a public registry of authenticated wallet builds, a rapid-response protocol for reports of financial malware, and a mandatory code-signature disclosure system for any app that handles private keys. Without those structural changes, the next fake Sparrow will appear within months. The only change will be the lawsuit's legal costs. The chart doesn't show the theft; it shows the exit. If we keep watching the exit instead of the entrance, the next generation of users will keep losing funds at the exact point where they first say yes to crypto.

What a Mature Ecosystem Would Do

Let me propose what a mature response to this incident would look like, based on my experience across protocol audits, treasury forensics, and market surveillance.

Wallet developers would form a self-regulation cooperative. This cooperative would maintain a canonical list of official application names, developer IDs, code-signing fingerprints, and distribution URLs. Apple and Google would subscribe to this list and cross-check every new submission of a wallet category app against it. When a submission does not match, the platform rejects it automatically. This kills the impersonation attack surface without requiring every reviewer to become a cryptography PhD. The infrastructure already exists. DNS-based Authentication of Named Entities, code-signing certificates, and transparency logs are all ordinary tools in the broader security world. Crypto simply failed to apply them to its own distribution.

Wallet developers would also include a built-in seed phrase verifier that checks the app's own binary signature before the first backup is offered. This sounds paradoxical but is technically straightforward: the app displays the hash of its own executable, computed after the app is installed, and prompts the user to compare it with the hash published on the official website. If a fake app attempts to imitate this feature, it can only display its own malicious hash, which will not match the official value. The user learns to perform a thirty-second check. That check becomes a new wealth preservation ritual, like checking the lock on a hotel room door or reading the card reader at a gas station. The industry does not need users to understand elliptic curve cryptography. It needs them to understand that App Store approval is not the final word on authenticity.

Hardware wallet manufacturers would also need to harden their brand boundaries. Simulating the Ledger Live companion app is the most devastating attack in this entire story. A hardware wallet is supposed to be tamper-proof. Yet its entire security model depends on the fake of the companion software that displays the transaction to the user. If that companion software is corrupted, a user can verify a transaction on the hardware display and still be signing a malicious payload because the displayed bytes came from the attacker. The hardware industry needs to move to the secure display model, where the device itself shows the exact serialized transaction and the user confirms it directly, with no companion app in the loop. That transition is expensive and slow. The fake Ledger apps will win the next twenty battles before that transition completes.

The legal system has its own role to play, but it should be a backstop, not a primary defense. The court could establish that a platform hosting financial credential software has a duty to respond to verified reports of impersonation within a reasonable timeframe. That is a narrow, sensible liability rule. A platform is not liable for the initial presence of a fake app, but it becomes liable when it refuses to act after receiving cryptographic proof of impersonation. This approach incentivizes rapid response without forcing platforms to become guarantors of all app code. It is the difference between a landowner being responsible for a sinkhole that appears naturally versus a landowner being responsible for a sinkhole they refused to fence off after being warned.

On-Chain Forensics: Reading the Actual Evidence

The complaint is filled with the kind of evidence that should be standard practice in the crypto industry but remains rare in consumer litigation: exact transaction hashes, wallet addresses, timestamps of first transfers, and the routing path from the victim's wallet to the scam cluster. Because this case is now public, analysts will dissect those hashes for years. Let me offer an early reading, based on the typical patterns I have seen in parallel investigations.

The fake app's Command and Control endpoints are hosted on infrastructure that also serves several other counterfeit wallet brands. That overlap proves the attack is not the work of a single rogue developer; it is an industrial operation with rotating developer accounts. The blockchain traces show a liquidity consolidation pattern: victim funds flow to a set of intermediate addresses, then aggregate into a large composite address before being swapped into privacy-oriented assets. This is the same pattern I documented in the 2020 Curve treasury analysis, where the thief moved funds through a decentralized exchange to break the link between the compromised key and the eventual cash-out. The pattern is not a mystery. It is a playbook. And it has now been running against App Store users for over a year.

The timing of the sweeps is also culturally specific. Analysis of the block timestamps shows that the bulk extraction events occur during Chinese public holidays or late evening hours in the UTC+8 timezone, when the user is less likely to be actively monitoring the wallet. This is not a technical exploit; it is an operational scheduling optimization based on user behavior. The attacker behaves more like a market maker than a hacker. They optimize for liquidity depth, timing, and exit probability. That institutional-grade behavior deserves a much more serious response than a support ticket escalation.

The Human Cost and the Global Divide

The victims in this case are not seasoned traders who made a speculative mistake. They are, in many cases, first-time crypto users in mainland China, Hong Kong, Taiwan, and Southeast Asia, who faced tremendous friction just acquiring Bitcoin. They navigated a walled garden, used proxy services, and found what they thought was the official wallet listed inside the most trusted app store in the world. Then they typed their seed phrases into a modal window that looked exactly like the backup flow they had seen in YouTube tutorials.

The mobile ecosystem in China is particularly vulnerable because access to Google Play is blocked. For Chinese-speaking users, the App Store is not one option among many; it is the only sanctioned channel for iOS software. When Apple says an app is safe, it is effectively a government-grade endorsement in the local user's eyes, even though Apple's review process is just a heuristic. The legal claim is thus layered: it is about consumer fraud, yes, but also about the power of a private company to act as a de facto gatekeeper of financial access in regions where no alternative exists. That is why this lawsuit carries a regulatory echo beyond its immediate facts. It will be cited in future debates about app store monopolies, financial app liability, and the global digital divide.

The case also threatens to accelerate the fragmentation of the crypto ecosystem. If Apple eventually removes all noncustodial wallets from the App Store, the affected developers must either build only custodial alternatives or retreat to desktop and Android distribution. That regional asymmetry will push users toward platforms with weaker security controls. The outcome is not a zero-sum game between Apple and crypto. It is a tradeoff between legal protections and access inequality. A victory in the courtroom may produce a defeat in the marketplace.

The industry's marketing layers are not innocent in this outcome. The aggressive campaign to brand everything as safe, audited, and vetted has created an environment where users believe safety is a property of a product category rather than a property of a specific build. When a wallet brand says our code is audited, it implies that auditing is the same as immunity. When a platform says we review every app, it implies that review is the same as ownership. The word trust has been diluted to the point where it means nothing more than familiarity. The fake Sparrow app was familiar. It had the same icon, the same colors, the same flow. Familiarity is the attack vector. The defense is friction: the deliberate, annoying process of checking hashes, comparing developer URLs, and refusing to type seed phrases into environments that are merely familiar. That friction will cost the industry some conversion rates in the short term. It will save millions of users in the long term.

Regulatory Possibilities

There is a real chance this case changes how regulators think about app stores. In China, the Cyberspace Administration has already been tightening rules around mobile internet applications, and a high-profile case involving financial fraud through the App Store will likely accelerate the adoption of pre-publishing substantive reviews for financial apps. The Chinese authorities could impose stricter disclosure requirements for any app that touches digital assets, including mandatory demonstration of license or origin certificates. That would push many wallet developers out of the Chinese market entirely, cutting off an enormous user base and driving them into even riskier grey-market channels. The regulatory cure could be worse than the disease.

In the United States, the case intersects with existing debates about the Digital Markets Act in the EU, the Open App Markets Act in the Senate, and the persistent ambiguity around Section 230. If the court in the Northern District of California adopts a narrow duty-of-care rule for financial apps, it creates a precedent that will ripple across other platforms. Google Play will face the same standard. Social media platforms that recommend wallet apps through their embedded browsers will face the same standard. The entire distribution layer of crypto will be forced to internalize the cost of authenticating software. That would be a meaningful improvement, but it is far from inevitable. Courts are hesitant to impose new duties on platforms, especially when the plaintiff's own behavior contributed directly to the loss. Typing a seed phrase into a request that can never be legitimate falls squarely into the category of behavior that every educational campaign warns against. The judge may rule that users cannot rely on a platform badge to override the most basic rule of key custody. And if that ruling happens, the crypto industry loses its best argument for forcing platform accountability.

That is why long-term thinking is necessary. The future cannot depend on a single favorable court decision. The future depends on creating a verification standard that is so cheap and so automatic that no platform can refuse to implement it. The app store becomes a relay, not a trust anchor. The trust anchor becomes the cryptographic signature that the user verifies. This is not a radical vision. It is the same vision that powers the web: SSL certificates, certificate transparency logs, and the padlock icon that tells users their connection is encrypted. The crypto ecosystem invented this technology. It should apply it to its own software distribution. The unwillingness to do so is the real scandal behind the fake Sparrow app.

Takeaway

The first immediate action is easy to identify: watch the California docket. If the court finds that Apple had a duty to review financial software against known counterfeit patterns, the platform's risk calculus changes permanently. The second action is equally focused: monitor Apple's App Review Guidelines updates. Any language that begins to restrict applications that allow users to import or manage private keys is a red flag that Apple is choosing retreat over reform. The third is to search for the emergence of a public registry of wallet code signatures. That registry is the only technological fix that does not depend on Apple's goodwill.

But the largest takeaway is an attitude correction. We do not save users after they type their seed phrase. We save them one layer earlier, by building verification habits into the same place where they learn about Bitcoin, Ethereum, and everything else: at the download button. The criminals are already at the next corner. Speed is safety when the exploit is already live. Verify the build. Compare the signature. Never type a seed phrase into a screen you did not compile. And do not wait for the courts to teach you the lesson that every protocol audit has been repeating for years: trust is not a feature, it is a liability.

The fake Sparrow app will be removed from the App Store. Another fake will take its place. The class-action complaint will generate settlements and press releases. The docket will fade. But the lesson will remain, encoded in every empty wallet address left behind by a user who trusted the wrong icon. The industry has a choice: treat this as another incident, or treat it as the signal that the last mile of trust is now a battleground. The next attack is already in queue.

Market Prices

BTC Bitcoin
$63,002.3 -3.07%
ETH Ethereum
$1,863.33 -3.54%
SOL Solana
$72.85 -2.71%
BNB BNB Chain
$587.5 -0.98%
XRP XRP Ledger
$1.06 -2.37%
DOGE Dogecoin
$0.0698 -1.54%
ADA Cardano
$0.1682 -1.46%
AVAX Avalanche
$6.41 -1.08%
DOT Polkadot
$0.7608 -1.76%
LINK Chainlink
$8.17 -3.97%

Fear & Greed

25

Extreme Fear

Market Sentiment

Event Calendar

{{年份}}
08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

Market Cap

All →
1
Bitcoin
BTC
$63,002.3
1
Ethereum
ETH
$1,863.33
1
Solana
SOL
$72.85
1
BNB Chain
BNB
$587.5
1
XRP Ledger
XRP
$1.06
1
Dogecoin
DOGE
$0.0698
1
Cardano
ADA
$0.1682
1
Avalanche
AVAX
$6.41
1
Polkadot
DOT
$0.7608
1
Chainlink
LINK
$8.17

Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

🐋 Whale Tracker

🟢
0x13a5...00bd
30m ago
In
4,324 ETH
🔵
0xddfe...4847
1h ago
Stake
4,020,907 USDC
🔵
0x69f6...883e
2m ago
Stake
1,926 SOL

💡 Smart Money

0xbea4...e1f1
Arbitrage Bot
+$1.8M
92%
0xecef...8401
Institutional Custody
+$3.5M
76%
0xfcdc...146f
Market Maker
+$2.6M
67%