sparrow-wallet.app Independent guide Buy bitcoin to self-custody

Impostor apps · reviewed 2026-08-10

The Sparrow Wallet mobile app does not exist

There is no official Sparrow Wallet app for Android or iOS, and any app in the App Store or on Google Play using that name is an impostor. Sparrow is desktop-only software for Windows, macOS and Linux. If you searched for a Sparrow mobile app and found one, you did not find Sparrow — you found something built to take your recovery phrase, and you are one screen away from losing whatever it protects.

Android app
None. No APK, no Play Store listing, no beta track.
iOS / iPhone app
None. No App Store listing, no TestFlight build.
Anything you found in a store
Published by someone other than the Sparrow project.
"Tailfeather" companion
Not in the Sparrow project's GitHub organisation.
Where Sparrow does run
Desktop only. Verified desktop downloads.

Check bitcoin prices on your phone

Unofficial

The evidence, and who said it

This is not our inference from a missing download button. The developer of Sparrow has publicly reported fake "Sparrow Wallet" applications published on the Apple App Store, stating flatly that "There is no iOS Sparrow app" and warning that "App stores will not protect you". Those two sentences are worth reading twice, because the second is the part most people get wrong.

The assumption that a curated store implies vetted custody is doing enormous damage. Store review confirms that a submission meets policy and technical requirements. It does not verify that the publisher is who they claim to be in the description, and it certainly does not verify what happens to a recovery phrase typed into the app. Fake wallet listings have repeatedly survived review, sometimes for weeks, and in July 2026 press coverage described a fake crypto app on the App Store implicated in roughly 1.8 million dollars of losses.

The pattern repeats because it works and because the economics are absurd in the attacker's favour. Publishing a plausible wallet app costs a developer account and a weekend. One victim with meaningful savings pays for both several thousand times over. Takedowns happen, but only after somebody reports the listing, which usually means after somebody has already been robbed.

The "tailfeather sparrow wallet" search

People searching for a Sparrow companion app frequently land on the word Tailfeather, so it needs a straight answer. There is no Tailfeather application in the Sparrow project's GitHub organisation, and the name as it appears in ordinary commerce belongs to an unrelated leather-goods brand. Whatever else that means, it means the name carries no endorsement from the Sparrow project.

So treat anything marketed under that name as a Sparrow companion the way you would treat a stranger offering to hold your keys. Names are free. The only thing that establishes provenance for wallet software is a download you can trace to the project's own domain and repository, and a signature you can check against a published key.

How a fake wallet app actually steals from you

Nobody falls for a screen that says "give us your bitcoin". The mechanics are quieter than that, and understanding the sequence is what makes it recognisable at step three instead of step five.

  1. It looks completely normal

    An icon, a splash screen, a tidy onboarding flow, a privacy policy, a handful of screenshots. A convincing interface is the cheapest part of the whole operation — the attacker only has to imitate a design, not implement a wallet. Some fakes do not contain wallet code at all: they are forms with a logo on top.

  2. It offers to "import" or "restore" your existing wallet

    This is the entire point of the app. Creating a new wallet gives the attacker nothing, so the restore path is the one that is polished and prominent. The prompt sounds routine: enter your 12 or 24 word recovery phrase to sync your existing wallet.

  3. Your words leave the phone the moment you type them

    Every word goes to the attacker's server, often as you type, sometimes before you press the final button. Some versions accept a photo of your backup card and read the words with text recognition, which is why "import from a screenshot" is such a damning feature to see in a wallet app.

  4. Then a delay, deliberately

    Sometimes the sweep happens within minutes. Often it does not. Waiting weeks breaks the mental link between the app you installed and the coins that vanished, which keeps the listing alive and unreported for longer. A balance that is still intact tonight proves nothing about tomorrow.

  5. Meanwhile the app keeps behaving

    Many fakes display a real balance, fetched from a public block explorer using the addresses derived from your seed. Everything looks right. That reassuring screen is reading the same public chain data anyone can read, and it is doing so with keys the attacker now also holds.

The rule that survives every variation

Real wallet software generates your recovery phrase and shows it to you once. Software that asks for a phrase it did not generate is asking for the only secret that matters. The direction of that exchange is the whole test, and it works even when you cannot tell the interfaces apart.

Check the app you are looking at

Nine signals, weighted by how conclusive they are. Two of them settle the question on their own.

Tick everything that matches the app you are looking at right now. The two heaviest signals are on their own conclusive: nothing legitimate asks for your recovery phrase, and nothing legitimate charges you to unlock your own coins.

Risk score 0 / 27

No red flags ticked yet

Nothing here condemns the app yet — but remember the fixed fact this page exists for: there is no official Sparrow app on any mobile store, so anything using that name is an impostor regardless of your score.

Sparrow Wallet on mobile: the questions people search

Is there an official Sparrow Wallet app for Android?

No. Sparrow is desktop software for Windows, macOS and Linux, and the project publishes no Android build of any kind. There is no APK, no Play Store listing and no beta track. Anything on Google Play using the Sparrow name is published by someone else and should be treated as an attempt to collect recovery phrases.

Is there a Sparrow Wallet iOS app on the App Store?

No. Sparrow does not build for iOS or iPadOS. The project developer has publicly reported fake "Sparrow Wallet" listings on the Apple App Store and stated plainly that there is no iOS Sparrow app, adding that app stores will not protect you from them. Store review checks a submission process, not who controls your keys.

What is Tailfeather, and is it the Sparrow mobile app?

There is no Tailfeather application in the Sparrow project’s GitHub organisation, and the name in general commerce belongs to an unrelated leather-goods brand. If you find something marketed as a "Tailfeather" companion for Sparrow, treat it with the same suspicion as any other unofficial app carrying the name: verify it from the Sparrow project’s own domain, or leave it alone.

Can I use my Sparrow wallet from my phone at all?

Not as a wallet app. What you can do is use a phone as a signing device in an airgapped setup: Sparrow exports a PSBT as an animated QR code, an offline signer scans it, signs, and shows the result back as a QR code. That is the phone as a component of the desktop workflow, not Sparrow running on the phone.

Will Sparrow release a mobile app in future?

We know of no announced mobile build, and we will not speculate. The practical rule is unchanged either way: a real release would appear on the project’s own domain and in its own repository first. Until you can trace a download back to there, an app store listing is not evidence of anything.

I typed my recovery phrase into a mobile app. What do I do?

Assume the phrase is compromised, even if the balance has not moved. Generate a brand-new wallet with a brand-new seed on a clean computer and move every coin to it immediately, highest-value first. Never reuse those words for anything, and check whether the same backup secured any other wallet or account.

What to do if you want bitcoin on your phone

Wanting a wallet on your phone is completely reasonable, and the answer is not "suffer without one". The answer is to stop looking for Sparrow there and use software that was designed for a phone, while keeping the amounts appropriate to the device you are carrying through the world.

Think of it the way you think about cash. A phone wallet is the notes in your pocket: convenient, exposed, and holding an amount you could lose to a stolen handset without your year being ruined. Savings belong in the setup Sparrow exists for — a desktop wallet paired with a hardware signer, ideally airgapped, ideally multisig once the balance justifies the extra ceremony.

We are not going to name a brand, because a recommendation made once and never revised is how people end up installing something abandoned three years ago. Name the criteria instead, and apply them yourself each time.

Reachable from the project's own domain

Find the project's website first, then follow its link to the store listing. Never the other way round. If you cannot find a real project site behind an app, that is the answer.

Open source, with a repository you can open

Public source under a real licence, with commits from named people. You will not read it, and that is fine — the point is that others can, and that the publisher accepted being watched.

Self-custody, stated without hedging

You hold the keys, you get a recovery phrase you can back up, and you can restore it in other compatible software. If the app can freeze or restore your balance, it is a custodian with a wallet-shaped interface.

Actively maintained, and boring about it

Recent releases, a visible changelog, no promises of yield or returns. A wallet offering interest on bitcoin is either lending your coins to someone or lying about having them.

Your phone can still be a signer

Here is the genuinely useful thing that survives all of the above. Sparrow supports PSBTs — partially signed bitcoin transactions, a standard file format — and can move them as animated QR codes using the UR standard. That means the online desktop never needs to hold a private key, and the device that does hold one never needs a network connection.

Sparrow builds an unsigned transaction and displays it as a QR sequence. An offline signing device — a dedicated signer, or a phone kept in airplane mode running signing software you trust — scans it, signs, and shows the signed result back as QR codes for Sparrow to scan. Nothing secret crosses the gap. The phone is a camera and a signature, not a wallet you carry.

That is the closest thing to "Sparrow on mobile" that will ever be honest, and it is better than what people were hoping to find. Devices and airgap modes covers which signers work over QR, SD card and USB.

EXPORT Online: Sparrow on your laptop AIR GAP unsigned PSBT → ← signed PSBT Offline: signing device keys stay here Private keys never cross the gap. Only transaction data does.
The airgapped workflow. The online machine holds a watch-only wallet; the signing device never touches a network.

"I already typed my seed into an app I now suspect"

The order to do it in

Work from a device you have reason to trust, which usually means not the phone that ran the suspect app. Install or open Sparrow on a desktop you control, generate a new wallet, and write the new words on paper before you move anything into it. If you have a hardware signer, use it for the new wallet — this is exactly the moment that spending the money on one pays for itself.

Then move the funds in order of value. If you are worried about fees, move the largest UTXOs first — a UTXO is an unspent output, one discrete chunk of coin your wallet controls — because an attacker who is watching will take whatever is easiest to take. Partial rescue beats a perfect plan you execute tomorrow.

Then check what else that backup protected

This is the step people skip. Ask whether the compromised words were ever used anywhere else: a second wallet you restored from the same seed, a passphrase variant of it, another coin derived from the same phrase, or an exchange withdrawal address book pointing at those addresses. One phrase often turns out to be the root of more than one wallet.

Check the device too. If you entered the phrase on a computer rather than a phone, treat that machine as suspect: a keylogger that captured the words once will capture the next set as well, which is why the new wallet must be created somewhere else. And if you typed the words into a website rather than an app, the same logic applies.

Finally, if the balance has not moved yet, resist the temptation to conclude you were lucky and keep using the wallet. The delay is a documented tactic, not an acquittal.

Once the funds are safe, rebuild properly: the security and threat model page explains what each configuration actually protects against, and seed and passphrase setup covers testing a restore while the balance is still zero.