Musician G. Love Loses 5.92 BTC After Downloading Fake Ledger App From Apple Store

Musician G. Love Loses 5.92 BTC After Downloading Fake Ledger App From Apple Store

N
News Editor 01
2026-07-08 16:14:13
Musician G. Love said he lost 5.92 BTC after entering his recovery phrase into a fake Ledger app found through Apple’s app marketplace, highlighting ongoing seed phrase phishing risks for self-custody users.
BitcoinLedgerSeed Phrase ScamApple App StoreOnchain Security

Musician Garrett Dutton, better known as G. Love, says he lost 5.92 BTC after downloading a fraudulent Ledger application while setting up his hardware wallet on a new Apple computer. At the time referenced in the report, the stolen bitcoin was valued at roughly $424,175, representing what he described as his retirement savings accumulated over about a decade.

A fake Ledger app triggered the theft

According to the report, the incident took place on April 11, 2026. Dutton said he was trying to install Ledger Live on a new Apple device and searched Apple’s app marketplace for the software. The listing he downloaded appeared legitimate, but it was not an official Ledger product.

After installation, the fake app prompted him to enter his 24-word recovery phrase. Once he did, the attackers gained control over the wallets associated with that seed phrase and quickly drained his bitcoin holdings. Dutton later posted publicly on X, saying he had suffered a major loss while transferring his Ledger setup to a new computer. He also shared a transaction hash and a bitcoin address, asking supporters who wanted to help him rebuild to send funds.

He subsequently clarified that only his bitcoin was affected and that no other crypto holdings were involved in the incident.

Onchain tracing linked the funds to Kucoin deposit addresses

Blockchain investigator ZachXBT said the stolen funds totaled approximately 5.92 BTC. He further stated that the assets were allegedly laundered through nine transactions into Kucoin deposit addresses. As with most bitcoin transfers, the movement of funds can be reviewed through public blockchain explorers, which makes post-incident tracing possible even if fund recovery remains uncertain.

Kucoin later responded by saying it follows a compliance-first approach and takes the prevention of illicit activity seriously. The exchange said it has established monitoring and review processes for potentially suspicious activity in line with regulatory expectations. At the same time, the company rejected the suggestion that it had “allowed” such activity and said it could not comment on specific details because of security, privacy, and ongoing investigative considerations.

Why a hardware wallet did not stop the loss

The case prompted debate on social media. Some users expressed sympathy, while others questioned how such a theft could happen given that Ledger hardware wallets require physical confirmation for transactions. Dutton’s explanation, however, aligns with a common and well-documented attack vector in crypto: seed phrase compromise through social engineering.

A hardware wallet can protect private keys only as long as the recovery phrase remains secret. Once a user voluntarily enters the phrase into a malicious application, website, or phishing page, the attacker can recreate the wallet elsewhere and access the funds without needing the original physical device. In other words, the security model collapses the moment the seed phrase is exposed.

This distinction is critical. Hardware wallets are designed to keep signing keys isolated from internet-connected devices. They are not designed to protect against users disclosing their recovery phrase to impostor software. That is why wallet providers repeatedly warn that seed phrases should never be typed into desktop apps, websites, browser prompts, email forms, or support chats.

Ledger’s long-standing warning about software downloads

The report emphasized that Ledger has for years instructed users to download its software only from ledger.com. The company has said it does not distribute its software through general consumer app stores in the way many users might assume. Any app appearing under another developer name and requesting a recovery phrase should be treated as fraudulent.

The mechanics of the scam are straightforward but effective. A user searches an app store, sees a convincing listing, installs the software, and is then prompted to enter a secret recovery phrase under the guise of setup, synchronization, migration, or account restoration. That single step gives the attacker full and permanent access to any wallet derived from the phrase.

The G. Love case is particularly notable because it illustrates how even a user with prior crypto experience can be caught off guard. Dutton said he had been involved in crypto since 2017 and acknowledged that the mistake was his own, describing the incident as a painful lesson and a warning to others about the volume of scams in the ecosystem.

A broader pattern affecting macOS users

The incident also fits into a broader pattern previously documented in the cybersecurity industry. The source article referenced earlier reporting from Moonlock in 2025 about malware targeting macOS users by replacing legitimate Ledger Live installations or prompting users to enter their recovery phrases. Searches for “Ledger” in Apple’s app marketplace have reportedly surfaced impostor apps from third-party publishers rather than Ledger SAS, increasing the risk that users may trust the wrong listing.

That context matters because many crypto users assume app marketplaces offer an additional layer of vetting. In practice, fraudulent wallet apps and phishing infrastructure have repeatedly found ways to imitate trusted brands, especially when users are rushing through setup or migrating devices. The danger is amplified when the fake interface closely resembles the legitimate product.

Self-custody comes with procedural risk

The case serves as a fresh reminder that self-custody is not just about owning a hardware wallet. It also requires disciplined operational security. The most important rule is simple: never enter a wallet’s seed phrase into any app or website unless the wallet provider explicitly requires on-device entry during initial setup. For Ledger products, the recovery phrase should only be handled in the secure context defined by the device maker, not typed into software downloaded from a third-party marketplace.

Users moving to a new computer, restoring access, or updating wallet software are often under time pressure and may be more vulnerable to phishing prompts. That makes migration moments especially dangerous. Before installing any wallet-related application, users should verify the official download source, check the developer identity, and cross-reference the guidance published by the hardware wallet manufacturer.

As of the report, no legal action had been announced. Dutton said he intended to move forward and expressed gratitude for his health, family, and music career despite the financial setback. The story had not yet been widely covered by mainstream media at the time it was first reported.

For the crypto industry, the lesson is familiar but still urgent: self-custody can remove counterparty risk, but it does not eliminate human error. In seed phrase scams, the attacker does not need to break the wallet. The victim is persuaded to hand over the keys.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.