Musician G. Love Loses 5.92 BTC After Downloading Fake Ledger App on Apple Store

Musician G. Love Loses 5.92 BTC After Downloading Fake Ledger App on Apple Store

N
News Editor 01
2026-07-08 16:16:13
Musician G. Love said he lost 5.92 BTC after installing a counterfeit Ledger app from Apple’s app marketplace and entering his recovery phrase, highlighting the ongoing risk of seed phrase theft and fake wallet software.
LedgerBitcoinWallet SecuritySeed Phrase ScamApple App Store

Musician Garrett Dutton, known as G. Love of G. Love & Special Sauce, said he lost 5.92 BTC—described as his retirement savings built up over roughly a decade—after downloading a counterfeit Ledger application while setting up a hardware wallet on a new Apple computer. At the time cited in the report, the stolen bitcoin was worth about $424,175.

A counterfeit app reportedly triggered the theft

According to the report, the incident took place on April 11, 2026. Dutton disclosed the loss the same day on X, explaining that he was trying to install what he believed to be the official Ledger Live software. Instead, he appears to have encountered a fraudulent app that mimicked Ledger’s branding closely enough to appear legitimate.

The fake app allegedly prompted him to type in his 24-word recovery phrase, also known as a seed phrase. Once that phrase was entered, the attackers gained full control over the wallets derived from it and quickly drained his bitcoin holdings. Dutton later clarified that, based on what he knew at the time, only his bitcoin was affected and no other assets were involved.

Onchain tracing points to KuCoin deposit addresses

Onchain investigator ZachXBT later traced the movement of the stolen funds and said that approximately 5.92 BTC had been taken. He further stated that the funds were reportedly laundered through nine transactions into deposit addresses associated with KuCoin. As with other bitcoin transfers, the movement of funds can be reviewed through public blockchain explorers.

KuCoin responded to media inquiries by saying it remains committed to a compliance-first approach and takes the prevention of illicit activity seriously. The exchange added that it does not agree with the characterization that it had “allowed” such activity, and said the matter was under review. Because of security, privacy, and ongoing investigative considerations, the company said it was not in a position to comment on specific details.

Why the hardware wallet did not prevent the loss

The case sparked debate on social media. Some users expressed sympathy, while others questioned whether the story made sense, noting that Ledger hardware wallets typically require physical confirmation on the device for transactions. But that line of defense does not apply once a user voluntarily reveals the recovery phrase.

That distinction is central to understanding the attack. In this case, the reported compromise did not depend on bypassing Ledger’s hardware security model. Instead, it relied on social engineering: convincing the victim to hand over the one secret that controls the wallet. Once the seed phrase is exposed, the attacker can restore the wallet elsewhere and move funds without needing the original device.

Dutton himself acknowledged that he had been caught off guard and described the incident as a scam. He also pushed back on accusations that he had fabricated the story, saying the experience should stand as a warning about the number of scams targeting crypto users.

Ledger’s long-standing warning: download only from ledger.com

The report emphasized that Ledger has repeatedly warned users to obtain its software only from ledger.com. The company has said for years that it is not present in consumer app stores for desktop software. If an application appears under another developer name rather than Ledger SAS, users should treat it as fraudulent.

The mechanics are straightforward but devastating. A user searches an app marketplace, finds a convincing imitation, installs it, and is then asked to enter the wallet’s seed phrase. At that point, the attacker has permanent access to every address derived from that phrase. The hardware wallet itself cannot protect funds after the recovery phrase has been disclosed.

This is one of the most important principles in self-custody: a seed phrase should never be typed into a website, computer app, or third-party interface unless the user is absolutely certain it is part of a legitimate and secure recovery process. In Ledger’s security model, the phrase is meant to remain offline and should only be entered directly on the hardware device when appropriate.

A broader pattern affecting macOS users

The incident also fits a broader pattern of attacks aimed at macOS users. The source report referenced earlier cybersecurity findings describing malware designed to replace legitimate Ledger Live installations on Apple computers and then prompt victims to enter their recovery phrases. It also noted that App Store searches for “Ledger” had at times surfaced impostor apps from third-party sellers rather than the real developer.

That pattern underscores a persistent weakness in crypto security: many successful thefts do not break cryptography or hardware protections. Instead, they exploit trust, urgency, and interface design. A fake app that looks polished and appears inside a trusted software marketplace can be enough to convince users they are interacting with an official product.

Public fallout and unresolved next steps

As of the article’s update, no legal action had been announced. Dutton said he intended to move forward and expressed gratitude for his health, family, and music career despite the loss. The story had not yet been widely covered by mainstream media at the time referenced in the report.

For the wider crypto industry, the case serves as another reminder that self-custody comes with both sovereignty and operational risk. Hardware wallets remain among the most trusted tools for holding digital assets, but they are not immune to scams built around human error. The strongest technical safeguards can fail the moment a recovery phrase is surrendered to an attacker.

The lesson for users is simple and severe: never enter a seed phrase into an app found through an app store search unless its authenticity is fully verified. In practice, that means going directly to the official source, confirming the publisher, and understanding that any request for a recovery phrase outside a verified recovery flow should be treated as a likely attempt to steal funds.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.