Skip to main content

How to Recognize a Fake Gem Wallet App

Why Fake Wallet Apps Are Dangerous​

A fake wallet app can imitate Gem Wallet's name, icon, screenshots, and interface. Its purpose may be to steal a Secret Phrase, replace receiving addresses, manipulate transaction details, or persuade users to send funds.

Visual similarity is not proof that an app is official. Verify the download source before creating or importing a wallet.

danger

Do not enter a Secret Phrase into an app downloaded from an advertisement, message, search result, file-sharing site, or link sent by an unknown person.

Use an Official Download Source​

Start from the official Gem Wallet website or use one of these project links:

The official Android application ID is com.gemwallet.android. The official iOS application uses App Store ID 6448712670.

note

Store availability can vary by device and region. If a link does not open in your local store, return to gemwallet.com rather than searching for an installer on an unrelated website.

Verify the App Before Importing a Wallet​

Complete these checks before entering any Secret Phrase:

  1. Open gemwallet.com by typing the address yourself or using a trusted bookmark.
  2. Follow the download link from the official website to your platform's store.
  3. Confirm the store URL or application identifier matches the official value above.
  4. Check that the listing does not contain misspellings, unusual domains, or instructions to contact an individual for activation.
  5. Compare the store listing with the official website and GitHub project.
  6. Install updates through the same official store or source.

Do not rely only on the icon, app name, rating, review count, or position in search results. Those details can be copied or manipulated.

Requests an Official Wallet Should Never Make​

Treat an app or person as malicious if they ask you to:

  • Send your Secret Phrase or private key to support.
  • Enter the phrase to receive an airdrop, reward, refund, or technical fix.
  • Pay a fee to activate, validate, synchronize, or unlock the wallet.
  • Send crypto to a verification or recovery address.
  • Share the phrase through email, chat, a support ticket, or a website.
  • Install remote-access software so someone can operate the wallet for you.

Gem Wallet uses a Secret Phrase when you intentionally create, back up, or import a wallet. Support does not need the phrase, and ordinary app updates do not require you to submit it.

Check an App Already Installed​

Do not type a Secret Phrase merely to test whether the app is legitimate.

Instead:

  1. Find the app's listing from the device's installed-app or store page.
  2. Compare its store URL or identifier with the official links above.
  3. Check how the app was installed. Treat an unexpected configuration profile, enterprise installer, or downloaded package as suspicious.
  4. Review whether the app opened websites or requested actions unrelated to normal wallet use.
  5. Check your real wallet addresses on a blockchain explorer from a separate trusted device if unauthorized activity is suspected.

The public source repository allows technically experienced users and independent reviewers to inspect how Gem Wallet is built. A claim that an app is β€œopen source” is not enoughβ€”the source must correspond to the official gemwalletcom/wallet project and trusted distribution channel.

If You Installed a Suspicious App but Did Not Enter a Secret​

If you did not create, import, reveal, copy, or enter a Secret Phrase and did not sign a transaction:

  1. Do not open the suspicious app again.
  2. Save non-secret evidence such as its store URL, website, developer name, and screenshots of the listing.
  3. Remove the app and any related configuration profile or downloaded installer.
  4. Review the device for unfamiliar apps and remote-access tools.
  5. Install Gem Wallet using an official source.
  6. Report the fake listing to the store or platform.

Continue to monitor public wallet activity if the suspicious app was given access to addresses or connected services.

If You Entered a Secret Phrase​

Assume the wallet is compromised even if no unauthorized transaction is visible yet.

  1. Stop using the suspicious app and device.
  2. On a trusted device, install Gem Wallet from an official source.
  3. Select Create a New Wallet to generate a new Secret Phrase.
  4. Back up the new phrase securely and offline.
  5. Move remaining assets from the exposed wallet to addresses in the new wallet.
  6. Stop using every address derived from the exposed phrase.

Follow the complete Secret Phrase exposure response. Deleting the fake app does not make an exposed phrase safe again.

If You Signed a Suspicious Transaction​

Check the affected address and transaction on the correct blockchain explorer. Record the public transaction ID, recipient, asset, amount, token approvals, and contract interactions.

If assets moved without your authorization or you also exposed the Secret Phrase, follow What to Do If Your Crypto Wallet Is Compromised. Revoking a token approval may reduce further contract access, but it cannot reverse a completed transaction.

Report a Fake Gem Wallet App​

Report the listing or website to the platform where you found it. Include:

  • The exact store or website URL.
  • The displayed app and developer names.
  • Screenshots that do not contain Secret Phrases, private keys, or personal data.
  • The date and how you discovered it.
  • Public transaction IDs if theft occurred.

Use Settings > Support in an official Gem Wallet installation, or email [email protected].

For broader reporting guidance, see How to Report Scams.

Fake App Verification Checklist​

  • The download starts from gemwallet.com or an official project link.
  • Android uses application ID com.gemwallet.android.
  • iOS uses App Store ID 6448712670.
  • The source project is github.com/gemwalletcom/wallet.
  • No support agent asks for a Secret Phrase or private key.
  • No activation, synchronization, or recovery payment is requested.
  • Updates come through the same trusted distribution channel.