A new technical audit of crypto wallet applications on Apple's App Store has found that nearly one in ten carries serious security flaws capable of exposing user funds, a finding likely to unsettle European holders who rely on mobile apps to manage self-custodied assets.

The analysis, published on kek.lol and authored by Igor Korsakov, chief technology officer at BlueWallet, examined 494 of the 904 non-custodial wallet apps registered on the App Store. Of those reviewed, 45 were flagged for issues including data leaks, weak encryption and unsigned remote code execution — vulnerabilities that could allow private keys or recovery phrases to fall into the wrong hands.

Korsakov's methodology relied on ipatool to extract app packages for inspection, with static code review assisted by the AI model Grok 4.6 xhigh. According to the report's infographic, 23 of the flagged apps were classified as carrying a critical vulnerability, while 22 were rated high risk.

One example cited in the report is Aura: Bitcoin Wallet, which the audit found sends recovery data to an external server run by coffer.agency, a practice that undermines the basic premise of non-custodial storage, where users alone are meant to control their keys.

Caution over false positives

Korsakov cautioned that the findings should not be treated as definitive proof of danger for every app not on the list, nor as a guarantee of safety for those left off it. "There may be false positives, and an app not appearing on the list does not mean it is 100% safe," he said.

He also urged users not to place blind trust in any single device or provider when it comes to private keys. "Never trust a single device, or a single provider, with a private key. They can leak it, or they can generate it incorrectly," he said, recommending that mobile wallets be used only to view balances or prepare transactions, with the actual keys kept on offline hardware devices such as those made by Keystone or Foundation Devices.

A wider pattern of App Store risk

The audit lands against a backdrop of recurring security incidents tied to the App Store's crypto offerings. Kaspersky detected 26 fake iOS apps impersonating MetaMask and Coinbase in May 2026, and a fraudulent version of the Sparrow Wallet app on iOS is reported to have cost users 1.8 million dollars in stolen Bitcoin, a scam that has since drawn lawsuits against Apple. Apple has not commented on whether it intends to remove the apps flagged in Korsakov's audit.

For European users, who increasingly rely on mobile-first custody solutions for everyday crypto transactions, the findings reinforce a long-standing piece of security advice: convenience on a smartphone should not come at the cost of where the private key actually lives.