Blockchain security investigator ZachXBT has publicly disclosed that a counterfeit Ledger Live cryptocurrency wallet app found on the Apple App Store drained more than $9.5 million from over 50 users between April 7 and 13. The fake app mimicked the genuine Ledger Live interface to trick users into revealing their seed phrases or private keys. ZachXBT traced the stolen funds to over 150 deposit addresses associated with the KuCoin exchange, primarily laundered through a centralized mixing service called AudiA6. Apple removed the malicious app on April 13, one day before the findings were made public, but the damage has reignited concerns over app store vetting processes.
Victims Include Musician G. Love; Three Seven-Figure Losses
Among the victims is Philadelphia-based musician G. Love (Garrett Dutton), who lost approximately 5.92 BTC (worth around $460,000 at the time) after downloading the fake app. ZachXBT published detailed fund flow charts showing three largest individual losses each surpassing $1 million: one user lost 3.23 million USDT on April 9; another lost 2.079 million USDC on April 11; and a third lost a total of $1.95 million in crypto assets on April 8, including 20.64 BTC, 211 stETH, and 70 ETH. The thefts spanned multiple blockchains: Bitcoin, EVM chains, Tron, Solana, and Ripple, indicating a multi-chain attack strategy.
ZachXBT Takes on KuCoin: KYC Failures Exposed
ZachXBT directly challenged KuCoin on social media, demanding to know why the exchange allowed the attacker to funnel nearly $10 million in stolen funds through over 150 deposit addresses. He accused KuCoin of having “broken KYC” that enables services like AudiA6 to process illicit transactions with impunity. The investigator further noted that days before the Ledger incident, another threat actor had laundered over $3.5 million from the Bitcoin Depot hack through more than 25 KuCoin deposit addresses. When KuCoin's official account responded asking for a UID and ticket number to investigate, ZachXBT posted a screenshot of a baby's identity document, mocking the exchange's KYC verification as worthless. KuCoin has not issued a formal response to these specific allegations as of press time.
Apple's App Review Under Scrutiny: Potential Class Action
The fact that a fake Ledger Live app remained available on the Apple App Store for an entire week has raised serious questions about Apple's application review process. ZachXBT suggested that Apple’s vetting system failed to identify the fraudulent nature of the app, potentially providing grounds for a class-action lawsuit by affected users. Apple has long marketed its App Store as a secure ecosystem, yet this incident demonstrates that malicious software can still bypass its defenses. Security experts urge users to always verify the developer name, description, and download counts before installing any wallet app, and to never enter seed phrases into any application—even those from official stores.
Ledger's CTO Issues Urgent Reminder: Never Share Your 24 Words
Ledger's Chief Technology Officer Charles Guillemet reiterated the company's core security principle: “Ledger will never ask for your 24 words. If any app or website asks for them, assume something is wrong. Your 24 words are your wallet.” He emphasized that users cannot trust software environments—not their browser, app store, or desktop. Attackers exploit opportunities wherever they exist, including official distribution platforms. The only effective protection is to keep private keys on a dedicated device with a secure screen, like a Ledger hardware wallet, and never type the recovery phrase into any app or website. He advised all users to double-check the apps installed on their devices and ensure they are using only the official Ledger Live application.

