A counterfeit app disguised as Ledger Live managed to bypass Apple's security filters and drained 5.9 BTC (roughly $420,000) from American musician Garrett Dutton, known as G. Love. The theft wiped out nearly a decade of crypto savings he had set aside for retirement.
Dutton revealed the incident in a series of posts on X. He downloaded the malicious software onto his new MacBook Neo, believing it was the official Ledger Live app. Tricked into entering his 24-word recovery phrase, the funds vanished “in an instant.” “I’ve been in the crypto circus since 2017. Today they caught me off guard. It was my own damn fault for not being more diligent. But let it serve as a warning,” he wrote.
On-Chain Trace Points to KuCoin
Blockchain investigator ZachXBT tracked the stolen Bitcoin, showing it moved to several deposit addresses tied to the KuCoin exchange across nine separate transactions shortly after the breach. KuCoin acknowledged the situation with a standard response, stating it “takes the prevention of illicit activity seriously” and the matter is under review, though it declined to comment further citing ongoing investigations.
Phishing Tactics Evolve Beyond App Stores
This is not the first time fake wallet apps have hit official stores. In 2023, a similar fraudulent Ledger Live app appeared on Microsoft's Store, causing nearly $600,000 in losses before Microsoft admitted the software had bypassed internal review. The FBI reports that crypto-related crimes are surging: total losses in the U.S. reached $11 billion in 2025, up from $9 billion the previous year.
Attackers are also turning to physical mail. Using contact details leaked from earlier data breaches, scammers send official-looking letters on forged letterheads to Trezor and Ledger users. The letters demand a “mandatory authentication check” with tight deadlines—such as February 15, 2026—to induce panic. Scanning the included QR codes leads to malicious sites that request a 12–24 word recovery phrase. Once entered, backend APIs grant attackers full wallet control.
Both Ledger and Trezor have faced scrutiny over customer database security, as these physical phishing campaigns rely heavily on personal information exposed in past breaches.

