Fake Ledger App on Apple's Mac App Store Stole $9.5M in Six Days, ZachXBT Finds
A counterfeit version of Ledger's wallet management software sat in Apple's Mac App Store for nearly a week in April 2026, harvesting seed phrases from over 50 victims and draining more than $9.5 million in cryptocurrency before Apple took it down. On-chain investigator ZachXBT traced the laundering trail through more than 150 deposit addresses at KuCoin, raising sharp questions about both Apple's app review process and the exchange's compliance controls.

The fraudulent application was live between April 7 and 13, 2026. It impersonated Ledger Live, the desktop software used to manage assets stored on Ledger hardware wallets. The attack was technically simple: the fake app prompted users to type in their 24-word Secret Recovery Phrase, which is the master key that controls every wallet address derived from a hardware device. Anyone who entered that phrase handed the attackers complete, irrevocable access to their funds across Bitcoin, Ethereum, Tron, Solana, and XRP. Apple removed the app on April 13 but has not publicly explained how it cleared the review process or how long it may have been available on the store before victims began losing funds on April 7.
Three victims individually lost seven-figure sums. The largest recorded theft was $3.23 million in USDT on April 9, followed by $2.08 million in USDC on April 11, and approximately $1.95 million spread across Bitcoin, Ether, and staked Ether on April 8. Among the most widely reported cases was Philadelphia musician Garrett Dutton, known professionally as G. Love, who lost 5.92 BTC worth roughly $424,175. Posting as @glove on X, he wrote: "I lost my retirement fund in a hack/scam… All my BTC gone in an instant."
ZachXBT tracked those specific coins through nine rapid on-chain transactions before they landed in KuCoin deposit wallets.
ZachXBT also linked a separate Bitcoin Depot incident involving $3.5 million to more than 25 additional KuCoin deposit addresses during the same week, putting total alleged KuCoin-facilitated laundering for both incidents above $13 million. Stolen funds from the fake Ledger app were routed through a centralized mixing service called AudiA6, which charges high fees to obscure transaction histories. ZachXBT publicly challenged KuCoin to account for the activity: "Want to explain to the community why KuCoin allowed a threat actor to launder $9.5M+ tied to a fake Ledger app via 150+ KuCoin deposit addresses over the past week?" KuCoin did not respond to media requests for comment. The exchange settled anti-money laundering violations with U.S. authorities for more than $300 million in 2025. In February 2026, Austrian regulators separately blocked KuCoin from onboarding new EU customers, an action that came shortly after the exchange received a MiCA license.
This incident is not without precedent. A counterfeit Ledger Live app on Microsoft's App Store stole roughly $600,000 in Bitcoin through the same seed-phrase method in 2023. In June 2025, Apple faced a separate class-action lawsuit in U.S. federal court after another fraudulent crypto app called Swiftcrypt passed its review process. ZachXBT noted that "[the scale of losses] could form the foundation for class-action litigation against [Apple]." He also alleged that Apple had blocked the third-party archiving tool urlscan.io from saving App Store listings, writing: "It seems Apple does not want people documenting the fact they allow fake apps on the App Store." The company has not commented on that claim either.
Ledger's official policy is unambiguous: the company does not distribute Ledger Live through any consumer app store. Its software is available only through its own website. Any listing on the Apple App Store, Google Play, or Microsoft App Store claiming to be Ledger Live is fraudulent by definition. Ledger serves an estimated 7 to 8 million users globally, making the population at risk far larger than the 50-plus confirmed victims of this particular incident. That guidance is critical context for users in high-growth crypto markets where awareness of it may be limited. Nigeria is on track to reach nearly 26 million active crypto users in 2026, and the Ledger Nano X is widely cited as the recommended hardware wallet in Nigerian self-custody guides.
India's retail crypto base is large and mobile-first. Indian investors have suffered more than ₹2,300 crore in losses to Ponzi-style crypto fraud in recent years, and phishing attacks targeting hardware wallet users are a documented part of that pattern. Across the Middle East and Africa combined, over 380,000 hardware wallet units sold in 2024 alone. Many first-time self-custody users in these markets locate software through app stores rather than official websites, and they may not have access to security advisories written in Hindi, Yoruba, Swahili, Amharic, or other regional languages.
The trust that app store presence signals legitimacy is precisely what this attack exploited.
The $9.5 million theft lands against a deteriorating backdrop for the industry. Chainalysis recorded approximately $17 billion stolen in crypto fraud globally in 2025, a record year, with impersonation scams growing 1,400 percent year over year. In the United States alone, the FBI reported $8.6 billion in crypto-linked investment fraud losses for the same year.
Neither India's Financial Intelligence Unit nor Nigeria's Securities and Exchange Commission has issued specific guidance on software distribution risks for hardware wallets. As self-custody adoption accelerates across emerging markets, regulators and platform providers alike face mounting pressure to extend consumer protections beyond exchange oversight and into the app ecosystems where users first encounter wallet software.