fake Ledger Live app
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3WoQVe…c2PqSummary
Fake Ledger Live apps are malicious wallet impersonation applications distributed through official app stores — including the Microsoft Store and Apple App Store — that harvest cryptocurrency seed phrases to drain victims' wallets. Two major documented incidents have resulted in confirmed losses of at least $10.3 million: approximately $768,000 via the Microsoft Store in November 2023, and approximately $9.5 million via the Apple App Store in April 2026. Parallel macOS malware campaigns distributing trojanized DMG installers have been active since at least August 2024, with four concurrent active campaigns identified by security researchers.
Connected Entities
13 entities · 60 linked investigations- Ethereum→mentioned with→Coinbase(60%)
- Ledger Live→mentioned with→Ethereum(65%)
- Ethereum→mentioned with→Bitcoin(60%)
- Ledger Live→mentioned with→KuCoin(70%)
- Ledger Live→mentioned with→AudiA6(60%)
- Ledger Live→mentioned with→Bitcoin(70%)
- Ledger Live→mentioned with→Solana(60%)
- Ledger Live→mentioned with→ZachXBT(65%)
- KuCoin→mentioned with→Bitcoin(70%)
- KuCoin→mentioned with→ZachXBT(70%)
- + 42 more
Community submissions
“May 22 ZachXBT report adds new on-chain attribution: all $9.5M from fake Ledger app laundered through 150+ KuCoin deposit addresses via AudiA6 service — new evidence beyond original April reports”
— avoid-scout
Timeline(16 events)
December 2022
Ledger's official support account issues warnings about counterfeit Ledger Live apps appearing on the Microsoft Store.
BleepingComputer (referenced in 2023 coverage)March 2023
Ledger support issues additional warnings about Microsoft Store counterfeits.
BleepingComputer (referenced in 2023 coverage)19 October 2023
'Ledger Live Web3' fraudulent app published to Microsoft Store under publisher 'Official Dev'.
BleepingComputer5 November 2023
ZachXBT publicly alerts community to fake Ledger Live app on Microsoft Store. Microsoft removes the app the same day. Confirmed on-chain losses total approximately $768,000 (16.8 BTC + ~$180K in ETH/BSC assets).
BleepingComputer / ZachXBTAugust 2024
Moonlock Lab begins tracking macOS-targeted fake Ledger Live clone campaigns distributing trojanized DMG installers through compromised websites. Early variants steal passwords and wallet metadata but not seed phrases.
Moonlock19 March 2025
Threat actor 'Rodrigo' deploys Odyssey stealer — a macOS malware that replaces the legitimate Ledger Live binary with a clone that phishes for seed phrases on next launch, enabling full wallet drain.
Moonlock17 April 2025
First sample from threat actor '@mentalpositive' advertising explicit 'anti-Ledger' functionality on dark web forums appears.
Moonlock21 April 2025
AMOS JandiInstaller campaign targeting Ledger Live users identified by Moonlock.
Moonlock4 May 2025
@mentalpositive releases updated anti-Ledger malware variant with enhanced seed phrase extraction.
MoonlockMarch 2026
Kaspersky researchers discover 26 FakeWallet apps in the Apple App Store impersonating Ledger and six other major wallets, attributed with moderate confidence to SparkKitty threat actors. Primarily targeting Chinese iOS users.
Kaspersky Securelist7 April 2026
Fake Ledger Live app published by 'Leva Heal Limited' / 'SAS Software Company' begins actively draining victim wallets via the Apple App Store.
BleepingComputer / The Block8 April 2026
Victim loses $1.95 million in BTC, ETH, and stETH — the third-largest single loss in the Apple App Store incident.
BleepingComputer / ZachXBT9 April 2026
Single victim loses $3.23 million in USDT — the largest individual loss in the incident. Musician G. Love loses 5.92 BTC (~$424,000-447,000).
Decrypt / BleepingComputer13 April 2026
Active theft campaign ends after six days with total losses exceeding $9.5 million across 50+ victims on Bitcoin, Ethereum, Tron, Solana, and XRP.
The Block / CoinDesk14 April 2026
ZachXBT publishes on-chain investigation findings. PhishFort analyst escalates case to Apple's anti-fraud team. Apple removes the fake app and terminates developer account.
CoinDesk / CoinTelegraph / PhishFortDecision Log
- hash: 8rpPLcHz5EjFCsMYrnr2gUVGseyXvdUgSv85UhqCgRHh
This investigation is cryptographically anchored to the Solana blockchain (1 event).
model: claude-sonnet-4-6
generated: 5/4/2026, 4:05:01 PM
last updated: 5/26/2026, 4:11:15 AM
13 viewsavoid.net — verified advice for a post-truth world