Musician G. Love says he lost nearly 5.92 BTC after downloading a fraudulent Ledger application from Apple’s Mac App Store and entering his wallet recovery phrase into the fake software. At the time cited in the original report, the stolen bitcoin was worth about $424,175. The case has renewed attention on a long-standing weakness in self-custody: once a seed phrase is exposed, even a hardware wallet cannot protect the funds.
A fake Ledger app triggered the theft
According to the report, Garrett Dutton, the frontman of G. Love & Special Sauce, disclosed the incident publicly on X on the same day it happened. He said he was setting up his Ledger hardware wallet on a new Apple computer and searched the App Store for Ledger Live, the software commonly used to interact with Ledger devices. The application he downloaded appeared legitimate, but it was not an official Ledger product.
The fraudulent app then prompted him to enter his 24-word seed phrase, also described as a secret recovery phrase. Once that phrase was entered, the attackers were able to take control of the wallet and drain his bitcoin. Dutton characterized the loss as his retirement fund and said he had held the bitcoin for roughly a decade.
He later clarified that only his bitcoin holdings were affected and that no other assets were involved. The public discussion that followed reflected a common misunderstanding around hardware wallets: the device itself may remain uncompromised, but if the recovery phrase is handed over voluntarily to a scammer, the protection offered by the hardware wallet is effectively bypassed.
Onchain tracing points to KuCoin deposit addresses
Onchain investigator ZachXBT said he traced the stolen funds and confirmed that approximately 5.92 BTC was taken. He further stated that the assets were allegedly laundered through nine transactions into KuCoin deposit addresses. Because bitcoin transactions are publicly viewable, the movement of funds can be examined on blockchain explorers, although attribution beyond that depends on exchange cooperation and investigative work.
KuCoin responded to the report by saying it is committed to a compliance-first approach and takes the prevention of illicit activity seriously. The company also rejected any implication that it had knowingly “allowed” such activity and said the matter was under review. Due to security, privacy, and ongoing investigative considerations, KuCoin said it was not in a position to comment on specific details.
Why the scam worked despite the use of a hardware wallet
The mechanics of the attack were straightforward, but highly effective. The victim searched an app marketplace, found a convincing wallet-related listing, installed it, and then typed in the seed phrase when prompted. That final step is what gave the attackers full and permanent access to the wallet derived from the phrase. In other words, the critical security failure was not a cryptographic break or a flaw in the hardware wallet itself, but a social engineering attack designed to trick the user into revealing the one secret that must never be shared.
This distinction is important. Ledger devices are built to keep private keys isolated from internet-connected computers. But the recovery phrase is the ultimate backup to those keys. If it is entered into a fake app, phishing page, or malicious website, the attacker no longer needs the physical hardware device. They can simply restore the wallet elsewhere and transfer out the funds.
Ledger’s standing warning: download only from ledger.com
The report noted that Ledger has said for years that its software should only be downloaded from ledger.com. The company does not distribute its core desktop wallet software through consumer app stores, and any app listed under another developer name instead of Ledger SAS should be treated as suspicious or outright fraudulent.
This warning is particularly relevant on macOS, where similar attack patterns have been documented before. Cybersecurity firm Moonlock reported in 2025 that malware targeting Mac users was designed to replace legitimate Ledger Live installations or imitate them, then ask users for their seed phrases. The appearance of impostor wallet apps in marketplace search results has therefore become a recurring risk rather than an isolated anomaly.
Community reaction was mixed
Reaction on X was divided after Dutton shared the incident. Many users expressed sympathy, especially given his statement that the stolen bitcoin represented his retirement savings. Others questioned the plausibility of the story, pointing out that Ledger wallets normally require physical confirmation on the device for outgoing transactions. Some users also viewed the public donation address he shared with skepticism.
Dutton responded by clarifying that he was not claiming the hardware wallet had been remotely hacked in the traditional sense. Instead, he said he had been caught off guard and socially engineered into entering the recovery phrase himself. He acknowledged that it was his own mistake and said the episode should serve as a warning about how widespread scams have become.
A broader lesson for self-custody users
The incident underscores one of the most basic but most frequently violated rules in crypto security: a seed phrase should never be typed into a computer application, website, or any third-party interface unless the manufacturer explicitly requires that action under tightly controlled conditions. In the Ledger model specifically, the recovery phrase should remain offline and should only be entered directly on the physical device when appropriate during setup or restoration procedures.
For self-custody users, fake wallet apps remain a serious threat because they exploit trust and urgency rather than software vulnerabilities. App store placement, familiar branding, and convincing user interfaces can all create a false sense of legitimacy. Once the recovery phrase is exposed, there is generally no technical way to reverse the damage.
As of the report’s update, no legal action had been announced. Dutton said he intended to move forward and expressed gratitude for his health, his family, and his music career despite the loss. The case now stands as another reminder that in crypto, operational security around seed phrases can matter just as much as the wallet hardware itself.

