
Fake wallet apps: how to make sure you installed the real one
The simplest way to steal someone's crypto isn't to break their wallet. It's to give them a fake one. A counterfeit app or browser extension that looks exactly like the real thing can collect your recovery phrase the moment you type it in, or quietly swap the addresses you send to.
Fake wallets turn up in app stores, browser extension stores, search ads and social media links. They're often polished, well reviewed and hard to tell apart from the original. The good news: a handful of habits makes them easy to avoid.
How fake wallets reach people
- Search ads. Searching for a wallet's name can show a paid ad above the real site, leading to a lookalike download page. Attackers buy ads on exactly the terms people search when they're about to install.
- Store listings. Fake apps and extensions do slip through app-store and extension-store review, sometimes with copied screenshots, inflated ratings and a near-identical name.
- Links in messages. "Update your wallet", "claim your airdrop" or "support says to reinstall" — all pointing to a download you'd never otherwise touch.
- Lookalike domains. One changed letter, an extra word, or a different ending (
.appinstead of.io) is enough to fool a quick glance. - Sideloaded files. APKs and extension packages shared directly, outside any store, skip whatever checks the store would have done.
What a fake wallet does
Most fakes do one of two things:
- Harvest your recovery phrase. The fake asks you to "import" or "restore" your wallet. When you type your phrase, it's sent to the attacker, who empties the wallet from their own device — sometimes days later, so you don't connect the theft to the install.
- Control what you see. A fake that you set up fresh can generate addresses the attacker controls, or alter recipients when you send.
Either way, the damage is done by the time anything looks wrong.
Five habits that stop it
- Start from the official website. Type the address yourself or use a bookmark, and follow the links to the stores from there. For SSP that's sspwallet.io, which links to SSP Wallet's browser store listings and SSP Key's app store pages.
- Check the publisher, not just the name. In any store, look at who published the app or extension and whether it matches the official developer. A different publisher name is the clearest red flag there is.
- Distrust urgency. A real wallet doesn't message you to reinstall, migrate or "validate" your wallet. Anyone urging you to do that is running the fake-support playbook.
- Never type your recovery phrase into anything you just installed unless you are deliberately restoring and you've verified the app first. A phrase request on first launch, from an app you meant to set up fresh, is a stop sign.
- Keep extensions few and known. Every extension is software with access to your browser. Good extension hygiene reduces both the chance of a fake and the damage a compromised one can do.
Going further: verifying the build
Store listings and websites tell you where an app came from. For people who want stronger assurance, some wallets let you check that the app is built from the code they publish.
SSP is open source, and SSP Wallet releases are built reproducibly: the same source code always produces the same output, so anyone can rebuild a release and confirm it matches what's distributed. Those releases are also GPG-signed, so you can check they came from the SSP team. It's a step most people never need to take — but it's what turns "trust the store" into something you can verify. Supply-chain attacks and deterministic builds explains why that matters.
Why two devices help — and where they don't
SSP's 2-of-2 design adds a margin here. A fake SSP Wallet alone can't move funds held by your real setup, because every transaction also needs SSP Key on your phone. Equally, a fake SSP Key alone can't spend without the wallet's key.
But there's a limit, and it's important. If you type both recovery phrases into fake apps, the attacker has both keys and the multisig can't help. The second device protects you from one compromised app; it can't protect you from handing over everything. No genuine part of SSP will ever ask you to enter a recovery phrase except when you choose to restore a wallet.
If you think you installed a fake
- Don't enter anything else into it, and uninstall it.
- If you typed a recovery phrase, treat that wallet as compromised. Set up a new wallet from the official source on a clean device and move your funds immediately — speed matters more than anything else.
- Report the listing to the store, so it can be taken down before it catches someone else.
The honest summary
Fake wallets win by being the first result you find. Start from the official site, check the publisher, ignore urgent "update" messages, and never feed a recovery phrase to something you just installed.
A two-device setup makes a single fake far less dangerous — but the strongest protection is never installing one in the first place.


