On April 11, 2026, musician Garrett Dutton, better known as G. Love of G. Love & Special Sauce, fell victim to a sophisticated crypto phishing attack that drained nearly all his bitcoin holdings. While setting up his new Mac computer, he searched for the official Ledger Live application in the Apple Mac App Store and downloaded a convincing counterfeit. The fake app prompted him to enter his 24-word recovery seed phrase, and within moments, his entire Bitcoin stash — 5.92 BTC, valued at approximately $424,175 at the time — was swept away.
How the Attack Unfolded
Dutton disclosed the incident on X (formerly Twitter) the same day, describing it as “the worst day” and revealing that the stolen funds represented his retirement savings held for nearly a decade. He posted the transaction hash and a Bitcoin address, asking followers to help “refill” it. He later clarified that only his Bitcoin was affected; no other crypto assets were involved.
The attack vector was straightforward: the user searches for Ledger in a legitimate app store, finds a convincingly designed app, installs it, and then is asked to input the seed phrase. Once the seed phrase is entered, the attacker gains full and permanent access to every wallet derived from that phrase. The hardware wallet provides zero protection once the seed is exposed.
On-Chain Tracking and Community Response
Renowned on-chain investigator ZachXBT quickly traced the stolen funds, confirming that approximately 5.92 BTC moved through nine transactions into deposit addresses linked to the KuCoin exchange. The transaction records are publicly visible on any Bitcoin blockchain explorer.
The community reaction on X was mixed. Many users expressed sympathy and some sent small donations to Dutton’s public address. However, others questioned the story’s plausibility, pointing out that Ledger hardware wallets require physical confirmation on the device, and that the public donation address was a potential red flag. Dutton responded that he was socially engineered into voluntarily entering his seed phrase, which is exactly the attack vector the scam was designed to exploit.
“I mean, I’m okay,” Dutton wrote. “It just sucks getting scammed. F*** all you haters who called me a liar. I’ve been in the crypto circus since 2017. Today they caught me off guard. It was my own damn fault for not being more careful. But let this be a warning. There are so many scams out there.”
Security Advisory: Legitimate Ledger Apps Are Never on App Stores
This incident follows a documented pattern targeting macOS users. In 2025, cybersecurity firm Moonlock reported on malware designed to replace legitimate Ledger Live installations on macOS and trick users into entering their seed phrase. Searching the Mac App Store for “Ledger” often returns fake apps listed by third-party sellers rather than the genuine developer, Ledger SAS.
Ledger has stated for years that its software is only available via ledger.com. The company does not maintain a presence in consumer-facing app stores. Any app appearing under a different developer name is fraudulent.
Self-custody requires that the seed phrase never leave the physical Ledger device. It should only be typed directly on the device during initial setup. Entering it into any app, website, or computer compromises the entire wallet.
As of April 12, 2026, mainstream media had not yet covered the story. Bitcoin.com News was the first to report the incident. G. Love indicated he would move forward, expressing gratitude for his health, family, and music career, including a recent performance at Tortuga Fest. No legal action has been announced.

