App Store scammers are making thousands of dollars by exploiting TouchID

The developers are raking it in despite worthless apps.
 By 
Karissa Bell
 on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

Shady developers have found a new way to trick users into spending ridiculous sums of money on worthless services.

The scheme, which was discovered by Redditors and reported by the welivesecurity blog, uses TouchID to trick users into in-app purchases, which can be as high as $99.99.

The blog uncovered two such examples, both from purported fitness apps. In both cases, the apps instruct users to hold their finger over their iPhone's home button in order to "scan" their fingerprint for health data. While the "scan" is happening, though, the app triggers an in-app purchase, which is then authenticated via TouchID and completed before the user even realizes what is happening.

Welivesecurity blog uncovered two examples of this tactic, one called "Calories Tracker app" and one called "Fitness Balance." Both apps have since been removed by from the App Store by Apple, but you can see it in action in the video below. Apple didn't immediately respond to a request for comment.

Shady though they are, it appears that these developers' tactics were extraordinarily successful. "Calories Tracker app," pulled in $60,000 in November while "Fitness Balance" made $10,000, according to data from app analytics firm Sensor Tower.

The incident also raises the questions about Apple's ability to detect scams in the first place.

Though Apple's App Store has a reputation for being safer than other app stores, this isn't the first time shady developers have been allowed to get their apps into the store. Last year, a number of barely-functional apps were removed for tricking users into paying for exorbitantly-priced subscriptions.

One such app, which also took advantage of the App Store's search ads, was charging $99.99 weekly for a worthless VPN service. The app was pulling in $80,000 a month before it was eventually removed.

Topics Apple

Mashable Image
Karissa Bell

Karissa was Mashable's Senior Tech Reporter, and is based in San Francisco. She covers social media platforms, Silicon Valley, and the many ways technology is changing our lives. Her work has also appeared in Wired, Macworld, Popular Mechanics, and The Wirecutter. In her free time, she enjoys snowboarding and watching too many cat videos on Instagram. Follow her on Twitter @karissabe.

Mashable Potato

Recommended For You
Scammers are increasingly posing as loved ones, survey suggests
smart phone with text reading 'i love you can you send me some money'

Hackers are exploiting a vulnerability in lots of e-commerce sites
Fish-eye lens view of a computer screen with hacking stuff on it

Apple boots vibe coding app Anything from App Store
Apple App Store icon

Gossip app Tea is back — but not on the App Store
screenshot of tea browser login page, with several women crossing their arms

Sony sued over high PlayStation Store 'monopoly' prices and download fees
Sony and PlayStation Store logos

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma


What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!