The genuine Pump.fun app is the one whose Apple App Store listing shows the numeric id 6717572591 and whose Google Play listing shows the package name com.batonresearch.pump. A copycat can clone the name, the icon, and even the developer label, so those two fixed identifiers, above the branding, are what confirm you have the real download.
Those two fields hold up because of how the stores work. Apple assigns that id once, and Google ties the package string to a single developer account, so a lookalike is locked out of republishing under either. It can only sit next to the real listing under a near-identical name and hope you tap it by the logo.
The same two listings that settle this legitimacy check also state, in plain text, the things the marketing pages leave out.
The check that actually works: the id and the package
To confirm the app, look past the name and the icon and read the two identifiers the store assigns rather than the uploader. On iPhone that is the App Store id, 6717572591, and the listing also names the developer as Maius Imperium Limited (source: App Store listing). On Android it is the app's package name, shown on the official Google Play page. Each identifier is unique to one app, so together they settle which listing is genuine.
The reason to trust these two identifiers is that every other detail is reproducible. An impersonator can register a developer account, upload an application called Pump.fun with the same green logo, and write a description that reads exactly like the original. The one thing beyond reach is Apple's already-assigned id or Google's existing package string. This vulnerability is real and documented: a fake DeFiLlama app remained on Apple's App Store for months, impersonating the analytics platform, and was removed only after DeFiLlama's own team demonstrated to Apple that the impersonator could drain a funded wallet (source: crypto.news). A familiar name and a position on a legitimate store are weak proof of authenticity. For how a mistaken install becomes a specific loss, the ranking of Pump.fun risks lays out the ways money actually disappears from a wallet.
The verification takes three steps. First, open the store listing you intend to install from, rather than a link forwarded in a conversation. Second, on iPhone confirm that the number in the App Store address ends in 6717572591, and on Android confirm the package on the Google Play page matches the official listing. Third, if either identifier is different by even a single character, it is a separate application, whatever the name and icon claim.
Three checks that feel smart but come up short
Three habits that sound like good due diligence fall short of confirming this app, and one of them breaks on the real listing. The developer name resolves messily. The privacy policy looks like a scam tell even though the app is real. And arriving from the official website drops you somewhere other than an inspectable store page.
Start with the developer name, because the mismatch is genuine and worth understanding. Both stores publish the app under Maius Imperium Limited, while the platform's terms name the operator as "Baton Corp., Bracket Ltd., and other affiliated entities" behind the service, and the name Maius appears nowhere in them (source: Pump.fun terms of use). A name-matching check therefore returns a contradiction on the authentic app. That falls short of proving fraud, and the public documents stop short of establishing how Maius Imperium Limited relates to the operating companies, so the developer name stays a field you verify around, which is why you fall back to the id and the package instead.
The second weak check is the privacy policy. A classic fake-app warning is a privacy policy that points to a personal Google Doc, and both Pump.fun store listings do exactly that. The iOS listing's link opens a shared Google Doc whose saved filename still carries a July 2024 date, the kind of thing a checklist would flag as suspicious. Here it sits on the real listing, so the just-a-Google-Doc signal says little about which app is genuine. The third weak check is the website route. The prompt to get the app opens an AppsFlyer tracking link, a step short of a plain App Store or Google Play button, so arriving from the official site can still leave you away from an inspectable store page (source: Pump.fun). The identifier check is what survives all three.
The lookalike already on the App Store
Impersonation on this name is live now. A search of the App Store for pump fun returns two results: the genuine app under id 6717572591, and a separate app called Pump Fun Tokens & Analitycs, listed under id 6792874438 by a developer named Inna Kylyan, close enough to catch a hurried tap (source: App Store listing for the lookalike). It is filed under Utilities rather than Entertainment, and both its support link and its privacy policy point at the same throwaway host, polymarketterminal.privacyapps.click, which is unrelated to Pump.fun.
That stops short of proving the app is malicious, and it describes itself as a notes-and-bookmarks utility rather than a trading app. The point is narrower and more useful: the name alone left the operator's real listing ambiguous, and the id resolved it. A support-and-privacy pair pointing at a random host, a mismatched category, and a slightly-off name are surface signals, and the identifier settles it. Confirming the app is only the first check anyway. Once you are in the real app, checking the wallet behind a coin is the next read, because a genuine app leaves a given coin as risky as ever. And if you already installed a lookalike and lost funds, the steps to report a crypto scam matter more than any hope of a refund.
Verifying the app costs you nothing; trading the PUMP token that these lookalikes chase is a separate decision with its own costs, and BloFin's fee page lays out what an open position runs before you commit to one.
What the Google Play listing spells out, and why no sideload beats it
The app's official Android home, published under the package com.batonresearch.pump, is worth reading past the install button (source: Google Play listing). It states in plain text what the marketing pages omit. The wallet is self-custodial, meaning you alone control it, and the operator says access and freezing stay beyond its reach. Wallet services come from Privy.io, and Pump.fun itself stays out of that role. Memecoins, the listing says, have no intrinsic value and are for entertainment only, and the price data shown in the app may be inaccurate or delayed. The whole app is filed under Entertainment, well outside Finance. Reversing a bad transfer is beyond any operator here, which is exactly why the identity check belongs before the install rather than after a loss, and why keeping the app's wallet safe is a separate discipline once you are in.
This is also why a sideloaded build is the wrong move. Because an official Google Play listing exists, there is little reason to hunt down an APK file from an app-mirror site or a link in a group chat. A sideloaded APK sits outside the single distribution route the operator actually uses, and it slips past the package check that a live Play listing passes, because anyone can rename a file. The safe way to obtain the APK is the verified store listing itself, ahead of any file downloaded from somewhere else.
Looking to trade PUMP? To get started, you'll need to first create a BloFin account, fund your account with cryptocurrency, and open the PUMP Spot trading page or the PUMP perpetual futures page.
Frequently asked questions
I already installed a lookalike Pump.fun app and connected a wallet. What should I do?
Treat it as a possible wallet compromise, well beyond a bad download. If you entered or created a wallet inside an app you now doubt, move any funds to a wallet you generated somewhere you trust, and abandon the seed phrase that app saw for good. Delete the app, then report it inside the App Store or Google Play so the store can review it. Because these wallets are self-custodial, any reversal is beyond the operator, so speed matters more than waiting for support.
Does the Entertainment category mean the app handles real money?
Yes. The app holds a live, self-custodial crypto wallet and moves real funds on-chain, whatever the store label says. The category is set by the developer, and Pump.fun sits under Entertainment on both stores, matching its own description of memecoins as holding no intrinsic value. Read the tag as a statement about how the operator frames the coins, and treat the money as real.
The developer name differs from the company in the terms. Is the app fake?
A mismatch here is expected rather than alarming. The stores name Maius Imperium Limited as the developer, while the operating companies in the platform's terms are a different set of names, and public documents leave the two unlinked. Large applications commonly ship under a publishing or holding entity separate from the operating company, so a name mismatch is weak evidence at best. It does mean the developer name is a field you verify around, which is the reason to rely on the numeric id and the package instead.
How do I find the App Store id or Android package before I install?
Both sit in the listing's web address. On the App Store, the id is the number after id in the URL, so id6717572591 is the genuine one. On Google Play, the package is the value after id= in the URL, which is com.batonresearch.pump. Open the listing in a browser, read the address bar, and match those exact strings. If you only have the app open on a phone, the App Store shows the developer and a share link that carries the same id.
Is a high rating or big download count proof I have the real app?
Ratings and install counts belong to whichever listing accumulated them, so a strong rating is reassuring but falls short of proof. A fresh lookalike can still display a handful of planted five-star reviews, and an impersonator's copy needs only a good position in search results to catch someone who searched the name and tapped the first result. The id and the package are the two fields a copy cannot reproduce, so let them decide.
Researched and written by the BloFin Academy editorial team with AI-assisted drafting. Primary sources include the Pump.fun App Store and Google Play listings, the Pump.fun terms of use, and reporting on fake crypto apps. All facts independently verified against cited documentation current as of September 2026.
This article is for informational and educational purposes only. It is not financial, investment, trading, or legal advice. Memecoins are extremely high-risk and most lose all of their value. App names, listings, and store details change frequently, and a listing being live is not an endorsement of the app or its coins. Always verify current details against primary sources before installing anything or moving funds. Do your own research and never risk money you cannot afford to lose.
