A malicious app posing as WalletConnect on the Google Play Store stole $70,000 in cryptocurrency over five months. It used fake reviews and branding to trick users into connecting their wallets, allowing the app to drain their assets via smart contract permissions. Over 150 users were affected, though the app achieved more than 10,000 downloads. The app evaded detection by redirecting users based on their IP address. Google has since removed it, but the incident highlights the growing sophistication of DeFi-related cybercrime.