{"id":45387,"date":"2026-04-15T01:20:44","date_gmt":"2026-04-14T17:20:44","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/15\/fake-ledger-live-app-on-apples-app-store-stole-9-5m-in-crypto\/"},"modified":"2026-04-15T01:20:44","modified_gmt":"2026-04-14T17:20:44","slug":"fake-ledger-live-app-on-apples-app-store-stole-9-5m-in-crypto","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/15\/fake-ledger-live-app-on-apples-app-store-stole-9-5m-in-crypto\/","title":{"rendered":"Fake Ledger Live app on Apple\u2019s App Store stole $9.5M in crypto"},"content":{"rendered":"\n<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2026\/04\/14\/Ledger.jpg\" width=\"1600\" alt=\"Fake Ledger Live app on Apple\u2019s App Store stole $9.5M in crypto\"><\/p>\n<p>A malicious Ledger Live app for macOS available from Apple&rsquo;s App Store has drained approximately $9.5 million in cryptocurrency from 50 victims in just a few days this month.<\/p>\n<p>Users who downloaded the fake Ledger app were tricked into entering their seed\/recovery phrases, thus giving attackers full access to their wallets and allowing them to send digital assets to external addresses under their control.<\/p>\n<p>According to blockchain investigator <a href=\"https:\/\/t.me\/investigations\/313\" target=\"_blank\" rel=\"nofollow noopener\">ZachXBT<\/a>, the attackers used <a href=\"https:\/\/chainabuse.com\/report\/d64b1096-1699-40f6-af9a-85158c2e4ad0\" target=\"_blank\" rel=\"nofollow noopener\">several wallet addresses<\/a>&nbsp;to receive funds across multiple chains, including Bitcoin, Ethereum, Tron, Solana, and Ripple.<\/p>\n<div align=\"center\" style=\"width:98%; margin:0 auto; text-align:center; padding:4px; background:#f0f0f0; border:1px solid #ccc; border-radius:6px;\">  <a href=\"https:\/\/www.adaptivesecurity.com\/demo\/security-awareness-training?utm_source=display_network&amp;utm_medium=paid_display&amp;utm_campaign=2026_04_display_bleepingcomputer&amp;utm_id=701Rd00000fE8REIA0&amp;utm_content=970x250\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/a\/as-tour-the-platform-970-x250.jpg\" style=\"margin-top: 0px;\" alt=\"Fake Ledger Live app on Apple\u2019s App Store stole $9.5M in crypto\"><\/a> <\/div>\n<p>The stolen amounts were then laundered through more than 150&nbsp;deposit addresses on KuCoin, linked to a centralized mixing service called &ldquo;AudiA6,&rdquo; which launders crypto in exchange for high fees.<\/p>\n<div style=\"text-align:center\">\n<figure style=\"display:inline-block\"><img loading=\"lazy\" decoding=\"async\" height=\"597\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/April\/transactions.jpg\" width=\"900\" alt=\"Fake Ledger Live app on Apple\u2019s App Store stole $9.5M in crypto\"><figcaption><strong>Malicious transactions<\/strong><br \/><em>Source: ZachXBT<\/em><\/figcaption><\/figure>\n<\/div>\n<p>The investigator tracked three individual victims losing seven-figure amounts ($3.23 million, $2.08 million, and $1.95 million) between April 8 and April 11.<\/p>\n<p>Musician G. Love stated on X that he also lost 5.9 BTC (currently $430k) after downloading the app. This loss was also traced and confirmed by ZachXBT.<\/p>\n<p style=\"text-align:center\"><a href=\"https:\/\/x.com\/glove\/status\/2043047396322451700\" target=\"_blank\" rel=\"nofollow noopener\"><img loading=\"lazy\" decoding=\"async\" height=\"238\" src=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto\/data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" width=\"555\" data-src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/April\/tweet.jpg\" alt=\"Fake Ledger Live app on Apple\u2019s App Store stole $9.5M in crypto\"><\/a><\/p>\n<p>According to a <a href=\"https:\/\/www.reddit.com\/r\/ledgerwallet\/comments\/1skbing\/warning_fake_mac_app\/\" target=\"_blank\" rel=\"nofollow noopener\">Reddit discussion<\/a>, the fake app was submitted to the Apple App Store under the publisher name &lsquo;Leva Heal Limited,&rsquo; an account not associated with the real Ledger development team.<\/p>\n<p>The malicious actor also created a fake version history by releasing major new versions every few days, going from 1.0 to 5.0 within just two weeks.<\/p>\n<div style=\"text-align:center\">\n<figure style=\"display:inline-block\"><img loading=\"lazy\" decoding=\"async\" height=\"600\" src=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto\/data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" width=\"465\" data-src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/April\/appdits.jpg\" alt=\"Fake Ledger Live app on Apple\u2019s App Store stole $9.5M in crypto\"><figcaption><strong>Details of the fake Ledger app<\/strong><br \/><em>Source: Reddit<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Following multiple user reports, Apple has now removed the fake app from the App Store, but not before 50 users lost a total of $9.5 million.<\/p>\n<p>BleepingComputer has reached out to Apple for a comment, but we have not received a response yet.<\/p>\n<p>Meanwhile, KuCoin, which has been accused of <a href=\"https:\/\/www.bleepingcomputer.com\/news\/cryptocurrency\/kucoin-charged-with-aml-violations-that-let-cybercriminals-launder-billions\/\" target=\"_blank\" rel=\"nofollow noopener\">violating anti-money laundering laws<\/a> in the past and was even ordered to pay <a href=\"https:\/\/www.bleepingcomputer.com\/news\/cryptocurrency\/kucoin-to-pay-nearly-300-million-in-penalties-after-guilty-plea\/\" target=\"_blank\" rel=\"nofollow noopener\">$300 million in penalties<\/a> in the U.S. last year, announced that it has <a href=\"https:\/\/x.com\/kucoincom\/status\/2043979158125195550\" target=\"_blank\" rel=\"nofollow noopener\">frozen the accounts<\/a> involved in the latest scheme.<\/p>\n<p>However, the platform noted that the freeze will only last until April 20. Beyond that date, the freeze can be extended via an official request from law enforcement authorities.<\/p>\n<p>It is important to note that Ledger <a href=\"https:\/\/support.ledger.com\/article\/4404389606417-zd\" target=\"_blank\" rel=\"nofollow noopener\">offers a Mac app<\/a> on its website, but not in the Apple App Store, where only an iOS-compatible version <a href=\"https:\/\/apps.apple.com\/us\/app\/ledger-wallet-crypto-app\/id1361671700\" target=\"_blank\" rel=\"nofollow noopener\">is available<\/a>.<\/p>\n<p>Threat actors have attempted to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-use-fake-ledger-apps-to-steal-mac-users-seed-phrases\/\" target=\"_blank\" rel=\"nofollow noopener\">exploit this availability gap<\/a> again in the past, even targeting the Microsoft Store in 2023, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-ledger-live-app-in-microsoft-store-steals-768-000-in-crypto\/\" target=\"_blank\" rel=\"nofollow noopener\">stealing $768,000<\/a> worth of cryptocurrency.<\/p>\n<style> .ia_ad {     background-color: #f0f6ff;     width: 95%;     max-width: 800px;     margin: 15px auto;     border-radius: 8px;     border: 1px solid #d6ddee;     display: flex;     align-items: stretch;     padding: 0;     overflow: hidden; }  .ia_lef {     flex: 1;     max-width: 200px;     height: auto;     display: flex;     align-items: stretch; }  .ia_lef a {     display: flex;     width: 100%;     height: 100%; }   .ia_lef a img {     width: 100%;     height: 100%;          border-radius: 8px 0 0 8px;     margin: 0;     display: block; }  .ia_rig {     flex: 2;     padding: 10px;     display: flex;     flex-direction: column;     justify-content: center; }  .ia_rig h2 {     font-size: 17px !important;     font-weight: 700;     color: #333;     line-height: 1.4;     font-family: Georgia, \"Times New Roman\", Times, serif;     margin: 0 0 14px 0; }  .ia_rig p {     font-weight: bold;     font-size: 14px;     margin: 0 0 clamp(6px, 2vw, 14px) 0; }  .ia_button {     background-color: #FFF;     border: 1px solid #3b59aa;     color: black;     text-align: center;     text-decoration: none;     border-radius: 8px;     display: inline-block;     font-size: 16px;     font-weight: bold;     cursor: pointer;     padding: 10px 20px;     width: fit-content; }  .ia_button a {     text-decoration: none;     color: inherit;     display: block; }  @media (max-width: 600px) {     .ia_ad {         flex-direction: column;         align-items: center;     }      .ia_lef {         max-width: 100%;     }      .ia_lef a img {         border-radius: 8px 8px 0 0;     }       .ia_rig {         padding: 15px;         width: 100%;     }      .ia_button {         width: 100%; \tmargin: 0px auto;     } } <\/style>\n<div>\n<div>         <a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\">             <img decoding=\"async\" src=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto\/data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" data-src=\"https:\/\/www.bleepstatic.com\/c\/p\/picus-whitepaper.jpg\" alt=\"Fake Ledger Live app on Apple\u2019s App Store stole $9.5M in crypto\"><\/a>     <\/div>\n<div>\n<h2><a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\">Automated Pentesting Covers Only 1 of 6 Surfaces.<\/a><\/h2>\n<p>Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.<\/p>\n<p>This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.<\/p>\n<p>           <button><a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\">Get Your Copy Now<\/a><\/button>     <\/div>\n<\/p><\/div>\n<div>\n<h3>Related Articles:<\/h3>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-still-working-to-fix-exchange-online-mailbox-access-issues\/\">Microsoft still working to fix Exchange Online mailbox access issues<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/snail-mail-letters-target-trezor-and-ledger-users-in-crypto-theft-attacks\/\">Snail mail letters target Trezor and Ledger users in crypto-theft attacks<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/48m-in-crypto-stolen-after-korean-tax-agency-exposes-wallet-seed\/\">$4.8M in crypto stolen after Korean tax agency exposes wallet seed<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/openai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow\/\">OpenAI rotates macOS certs after Axios attack hit code-signing workflow<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/police-identifies-20-000-victims-in-international-crypto-fraud-crackdown\/\">Over 20,000 crypto fraud victims identified in international crackdown<\/a><\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A malicious Ledger Live app for macOS available from Ap [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[],"class_list":["post-45387","post","type-post","status-publish","format-standard","hentry","category--bleepingcomputer"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45387","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=45387"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45387\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=45387"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=45387"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=45387"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}