Fake Ledger Live app in Apple’s App Store was linked to $9.5 million in crypto losses

THE BRIEF
A malicious macOS application impersonating Ledger Live appeared in Apple’s App Store and was linked by blockchain investigator ZachXBT to approximately $9.5 million in cryptocurrency losses across about 50 victims. Users were prompted to enter wallet seed or recovery phrases, giving the attacker the information needed to move assets to wallets under their control. Investigators traced funds across multiple blockchains and reported several individual seven-figure losses. The fake app used a publisher account not associated with Ledger and created a misleading version history to appear established. Apple later removed the application and terminated the developer account after user reports. The incident exploited an important availability gap: Ledger provides a macOS app from its own website but does not distribute that Mac application through the App Store. Users who assumed that an App Store listing was the official desktop client were therefore vulnerable to a convincing impersonation.
WHY IT MATTERS
This is a fraud story as much as a malware story. Digital-wallet recovery phrases are effectively master keys, so a single disclosure can bypass passwords, multifactor authentication and the protections of the legitimate wallet provider. The case also challenges a common consumer assumption that software downloaded from a major app store is automatically authentic. For banks, exchanges and fraud teams, losses can move rapidly across chains and laundering infrastructure, making customer education and transaction monitoring important complements to platform moderation.
WHO SHOULD CARE
Cryptocurrency users, digital-asset exchanges, fraud teams, consumer-protection teams and anyone responsible for security guidance around wallet software should care. Banks and consumer-support teams handling scam-related transfers should also understand the pattern.
WHAT TO DO NOW
- Install wallet software only from links published by the wallet vendor itself.
- Never enter a seed or recovery phrase into software merely because it appears in an app store.
- Treat any exposed seed phrase as permanently compromised and move assets to a newly generated wallet.
- For exchanges and fraud teams, monitor rapid transfers from newly compromised wallets and preserve tracing data for law enforcement.
VERIFICATION NOTE
Historical backfill verified against the cited BleepingComputer report and blockchain-investigator findings described there.