A Bitcoin user has suffered a loss of 5.92 BTC (worth approximately $400,000) after downloading a counterfeit version of the Ledger hardware wallet management app from the Apple App Store. The fake app mimicked the official Ledger Live interface but contained malicious code designed to steal recovery phrases or private keys.
How the Scam Worked
According to security analysts, the victim searched for “Ledger” on the App Store and accidentically installed the fraudulent app. Upon logging in, the app prompted the user to enter their seed phrase for “device synchronization,” effectively handing over full wallet control. The attacker then immediately transferred the 5.92 BTC to a centralized exchange (CEX) address and laundered the funds via mixing services and cross-chain bridges, making them nearly untraceable.
Apple App Store is Not Immune
This incident is not the first time fake crypto apps have infiltrated official app stores. In the past, fake MetaMask and Trust Wallet apps have also appeared on Google Play. Although Apple enforces strict review policies, attackers can still slip through using tactics such as temporary certificates or submitting benign versions before pushing malicious updates. Security experts warn: any app that asks for a private key or seed phrase is almost certainly a phishing attempt.
How to Stay Safe
Before downloading a crypto wallet app, always verify the developer’s name, download count, ratings, and user reviews. The genuine Ledger Live is developed by “Ledger SAS” with over 10 million downloads. Never enter your seed phrase into any third-party app, website, or pop-up. If you have already downloaded a suspicious app, immediately transfer your assets to a newly generated wallet and contact official support.

