Skip to main content
Sign in
Ledger Live1 decision on this page

Audit log

Every state-changing event for Ledger Live: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.

  1. #1publishby system:backfill
    2026-07-22 02:11:36Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    4xp3zXwddBy7…mbMAWpB8sha256 → base58
    verifying row…
    canonical bytes (19169 B) ▸
    {"actor":"system:backfill","investigation_id":"35de6192-9b0a-4914-8df7-3dbc6b531713","kind":"publish","page_slug":"ledger-live","published_at":"2026-07-22T02:11:36.705Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Ledger Live","sections":[{"content":"AVOID.NET maintains a separate entity page for Ledger, the French hardware-wallet manufacturer, which covers company-level issues such as the 2020 customer database breach and general brand-impersonation phishing. This page is scoped specifically to Ledger Live, the companion desktop/mobile software application, and documents incidents that are distinct to the app-distribution layer: repeated counterfeit \"Ledger Live\" listings on third-party app stores and a supply-chain compromise of a genuine Ledger-published software library bundled with the Ledger Live ecosystem. Readers researching the company's 2020 data breach or general corporate history should consult the Ledger entity page; this page focuses on app-specific security incidents.","heading":"Scope note: relationship to the \"Ledger\" hardware company page","severity":"low","sources":[]},{"content":"Fraudulent applications impersonating Ledger Live have repeatedly appeared on official app marketplaces over several years, each time tricking users into entering their 24-word recovery phrase and thereby surrendering full control of their wallets to attackers. In November 2023, a fake app titled \"Ledger Live Web3\" was listed on the Microsoft Store; on-chain investigator ZachXBT identified roughly $588,000 in Bitcoin theft tied to the app, with total losses across Bitcoin, Ethereum, and BNB Smart Chain reportedly reaching approximately $768,000 before Microsoft removed the listing the same day it was flagged, on November 5, 2023. In April 2026, a counterfeit macOS \"Ledger Live\" application published under the shell-entity name \"Leva Heal Limited\" — which multiple outlets reported had no connection to Ledger SAS — remained live on Apple's App Store from approximately April 7 to April 14, 2026. Reporting indicates the app was pulled only after community and researcher reports rather than by Apple's automated review, and it was linked to at least $9.5 million stolen from more than 50 victims across Bitcoin, Ethereum, Solana, Tron, and XRP, with the three largest individual losses reported at roughly $3.23 million in USDT, $2.08 million in USDC, and $1.95 million combined in BTC, ETH, and stETH. Stolen funds were reportedly routed through more than 150 deposit addresses at the exchange KuCoin and an alleged laundering service referred to as \"AudiA6.\" Ledger's own support documentation separately warns that fraudulent \"Ledger Live\" apps have also appeared on Google Play and the Chrome Web Store, and the company's official support account has publicly warned users never to enter a recovery phrase into any app.","heading":"Recurring counterfeit \"Ledger Live\" apps on major app stores","severity":"critical","sources":[{"credibility":1,"name":"Microsoft Listing Fake Ledger App Leads to $590K of Bitcoin Stolen by Hackers - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2023/11/06/microsoft-listing-fake-ledger-app-leads-to-590k-of-bitcoin-stolen-by-hackers"},{"credibility":1,"name":"Fake Ledger Live app in Microsoft Store steals $768,000 in crypto - Bleeping Computer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/fake-ledger-live-app-in-microsoft-store-steals-768-000-in-crypto/"},{"credibility":1,"name":"Hackers Pinch Nearly $1 Million in Crypto Via Fake Ledger App on Microsoft App Store - Decrypt","type":"news_article","url":"https://decrypt.co/204506/fake-ledger-app-microsoft-app-store-zachxbt"},{"credibility":1,"name":"A fake Ledger app on the Apple App Store just drained $9.5 million in crypto - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/04/14/a-fake-ledger-app-on-the-apple-app-store-just-drained-usd9-5-million-in-crypto"},{"credibility":1,"name":"Fake Ledger Live app on Apple's App Store stole $9.5M in crypto - Bleeping Computer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto/"},{"credibility":2,"name":"Apple pulls fake Ledger app and Freecash in rough day for App Store review - 9to5Mac","type":"news_article","url":"https://9to5mac.com/2026/04/14/apple-pulls-fake-ledger-app-and-freecash-in-rough-day-for-app-store-review/"},{"credibility":2,"name":"Ledger Scam (April 17): $9.5M Stolen via Fake App — Flagged and Taken Down by PhishFort Analyst","type":"research","url":"https://phishfort.com/fake-crypto-apps-app-store-phishing-scam/"},{"credibility":1,"name":"Fraudulent Ledger Wallet (formerly Ledger Live) applications - Ledger official support","type":"official","url":"https://support.ledger.com/article/fraudulent-ledger-live-applications"},{"credibility":2,"name":"Ledger Support: phishing warning about fake Ledger Live apps in Google Play and Chrome Web Store","type":"official","url":"https://x.com/ledger_support/status/1290268863477821440?lang=en-GB"}]},{"content":"On December 14, 2023, Ledger disclosed that a genuine, Ledger-published npm software package — @ledgerhq/connect-kit, a library used by decentralized applications (dApps) such as SushiSwap and Revoke.Cash to let users connect Ledger hardware wallets to web front ends — was compromised in a supply-chain attack. According to Ledger and multiple security researchers, a former Ledger employee fell victim to a phishing attack that gave attackers access to Ledger's npm publishing account, allowing them to upload three malicious versions of the package (1.1.5, 1.1.6, and 1.1.7). The compromised code presented users with a fraudulent wallet-connection prompt that, once accepted, drained connected wallets to attacker-controlled addresses via a rogue WalletConnect project. Reported losses from the roughly two-hour exploitation window (the malicious code was live for about five hours in total) exceeded $600,000. Ledger stated it removed the malicious versions, published a fixed version (1.1.8), reported attacker wallet addresses to authorities, and coordinated with stablecoin issuer Tether to freeze some stolen funds; on December 20, 2023, Ledger announced a plan to reimburse affected users, targeting completion by February 2024. Attribution of the underlying attackers has not been definitively confirmed in public reporting, though some coverage has referenced links to the phishing group \"Angel Drainer.\"","heading":"December 2023 Ledger Connect Kit supply-chain attack","severity":"high","sources":[{"credibility":1,"name":"Crypto Hardware Wallet Ledger's Supply Chain Breach Results in $600,000 Theft - The Hacker News","type":"news_article","url":"https://thehackernews.com/2023/12/crypto-hardware-wallets-supply.html"},{"credibility":1,"name":"Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code"},{"credibility":1,"name":"Security Incident Report - Ledger official blog","type":"official","url":"https://www.ledger.com/blog/security-incident-report"},{"credibility":2,"name":"Supply Chain Attack on Ledger Connect Kit: Analyzing the Impact and Preventive Measures - SlowMist","type":"research","url":"https://slowmist.medium.com/supply-chain-attack-on-ledger-connect-kit-analyzing-the-impact-and-preventive-measures-1005e39422fd"},{"credibility":2,"name":"Ledger Connect-Kit Compromise: A Crypto Drainer Attack - Sonatype","type":"research","url":"https://www.sonatype.com/blog/decrypting-the-ledger-connect-kit-compromise-a-deep-dive-into-the-crypto-drainer-attack"},{"credibility":2,"name":"Ledger Unveils Plan to Reimburse Wallet Drainer Hack Victims - DailyCoin","type":"news_article","url":"https://dailycoin.com/ledger-unveils-plan-to-reimburse-wallet-drainer-hack-victims/"}]},{"content":"In September 2025, following the compromise of a widely-used npm publishing account (belonging to developer \"Qix\"), malicious code described as \"crypto-clipper\" malware was injected into JavaScript packages with a reported combined download count exceeding one billion. The malware was designed to intercept outgoing cryptocurrency transaction data in browsers and silently substitute attacker-controlled wallet addresses that visually resembled the legitimate destination. Ledger's Chief Technology Officer, Charles Guillemet, publicly warned crypto users about the incident and specifically advised hardware-wallet users, including those relying on Ledger Live, to carefully verify every transaction detail on their device screen before signing, and advised software-wallet users to avoid on-chain transactions until the incident was resolved. Later reporting from The Block indicated the attack was contained with reportedly minimal financial impact. This incident did not involve a compromise of Ledger's own code but illustrates the broader software supply-chain risk environment in which Ledger Live and similar wallet-connection tooling operate.","heading":"September 2025 NPM ecosystem warning","severity":"medium","sources":[{"credibility":1,"name":"Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads - CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2025/09/08/ledger-cto-warns-of-npm-supply-chain-attack-hitting-1b-downloads"},{"credibility":1,"name":"NPM supply chain attack on crypto contained with 'almost no victims,' Ledger CTO says - The Block","type":"news_article","url":"https://www.theblock.co/post/369984/npm-supply-chain-attack-on-crypto-contained-with-almost-no-victims-ledger-cto-says"},{"credibility":2,"name":"Ledger CTO raises alarm over NPM supply chain attack targeting crypto users - crypto.news","type":"news_article","url":"https://crypto.news/ledger-cto-raises-alarm-over-npm-supply-chain-attack-targeting-crypto-users/"}]},{"content":"Ledger maintains an official support article cataloging fraudulent \"Ledger Live\" applications and a dedicated \"ongoing phishing campaigns\" status page, and its official support social media account has issued public warnings about fake Ledger Live listings on app stores dating back to at least 2020. The company states unambiguously that it distributes Ledger Live for desktop platforms only through its own website and has never published a macOS listing on the Apple App Store, meaning any App Store listing claiming to be Ledger Live for Mac should be treated as counterfeit. Following the December 2023 Connect Kit incident, Ledger committed to and reportedly carried out a victim-reimbursement program. These measures indicate an active, ongoing effort by Ledger to combat impersonation, though the recurrence of successful counterfeit-app incidents in 2023 and again in 2026 suggests the underlying risk — rooted in third-party app store review processes rather than in Ledger's own software — has not been resolved.","heading":"Ledger's mitigation posture","severity":"low","sources":[{"credibility":1,"name":"Fraudulent Ledger Wallet (formerly Ledger Live) applications - Ledger official support","type":"official","url":"https://support.ledger.com/article/fraudulent-ledger-live-applications"},{"credibility":1,"name":"Ongoing phishing campaigns - Ledger official","type":"official","url":"https://www.ledger.com/phishing-campaigns-status"},{"credibility":2,"name":"Ledger Unveils Plan to Reimburse Wallet Drainer Hack Victims - DailyCoin","type":"news_article","url":"https://dailycoin.com/ledger-unveils-plan-to-reimburse-wallet-drainer-hack-victims/"}]}],"sources_used":[{"credibility":1,"name":"Microsoft Listing Fake Ledger App Leads to $590K of Bitcoin Stolen by Hackers - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2023/11/06/microsoft-listing-fake-ledger-app-leads-to-590k-of-bitcoin-stolen-by-hackers"},{"credibility":1,"name":"Fake Ledger Live app in Microsoft Store steals $768,000 in crypto - Bleeping Computer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/fake-ledger-live-app-in-microsoft-store-steals-768-000-in-crypto/"},{"credibility":1,"name":"Hackers Pinch Nearly $1 Million in Crypto Via Fake Ledger App on Microsoft App Store - Decrypt","type":"news_article","url":"https://decrypt.co/204506/fake-ledger-app-microsoft-app-store-zachxbt"},{"credibility":1,"name":"A fake Ledger app on the Apple App Store just drained $9.5 million in crypto - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/04/14/a-fake-ledger-app-on-the-apple-app-store-just-drained-usd9-5-million-in-crypto"},{"credibility":1,"name":"Fake Ledger Live app on Apple's App Store stole $9.5M in crypto - Bleeping Computer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto/"},{"credibility":2,"name":"Apple pulls fake Ledger app and Freecash in rough day for App Store review - 9to5Mac","type":"news_article","url":"https://9to5mac.com/2026/04/14/apple-pulls-fake-ledger-app-and-freecash-in-rough-day-for-app-store-review/"},{"credibility":2,"name":"Ledger Scam (April 17): $9.5M Stolen via Fake App — Flagged and Taken Down by PhishFort Analyst","type":"research","url":"https://phishfort.com/fake-crypto-apps-app-store-phishing-scam/"},{"credibility":1,"name":"Fraudulent Ledger Wallet (formerly Ledger Live) applications - Ledger official support","type":"official","url":"https://support.ledger.com/article/fraudulent-ledger-live-applications"},{"credibility":2,"name":"Ledger Support: phishing warning about fake Ledger Live apps in Google Play and Chrome Web Store","type":"official","url":"https://x.com/ledger_support/status/1290268863477821440?lang=en-GB"},{"credibility":1,"name":"Crypto Hardware Wallet Ledger's Supply Chain Breach Results in $600,000 Theft - The Hacker News","type":"news_article","url":"https://thehackernews.com/2023/12/crypto-hardware-wallet-ledgers-supply.html"},{"credibility":1,"name":"Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code"},{"credibility":1,"name":"Security Incident Report - Ledger official blog","type":"official","url":"https://www.ledger.com/blog/security-incident-report"},{"credibility":2,"name":"Supply Chain Attack on Ledger Connect Kit: Analyzing the Impact and Preventive Measures - SlowMist","type":"research","url":"https://slowmist.medium.com/supply-chain-attack-on-ledger-connect-kit-analyzing-the-impact-and-preventive-measures-1005e39422fd"},{"credibility":2,"name":"Ledger Connect-Kit Compromise: A Crypto Drainer Attack - Sonatype","type":"research","url":"https://www.sonatype.com/blog/decrypting-the-ledger-connect-kit-compromise-a-deep-dive-into-the-crypto-drainer-attack"},{"credibility":2,"name":"Ledger Unveils Plan to Reimburse Wallet Drainer Hack Victims - DailyCoin","type":"news_article","url":"https://dailycoin.com/ledger-unveils-plan-to-reimburse-wallet-drainer-hack-victims/"},{"credibility":1,"name":"Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads - CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2025/09/08/ledger-cto-warns-of-npm-supply-chain-attack-hitting-1b-downloads"},{"credibility":1,"name":"NPM supply chain attack on crypto contained with 'almost no victims,' Ledger CTO says - The Block","type":"news_article","url":"https://www.theblock.co/post/369984/npm-supply-chain-attack-on-crypto-contained-with-almost-no-victims-ledger-cto-says"},{"credibility":2,"name":"Ledger CTO raises alarm over NPM supply chain attack targeting crypto users - crypto.news","type":"news_article","url":"https://crypto.news/ledger-cto-raises-alarm-over-npm-supply-chain-attack-targeting-crypto-users/"},{"credibility":1,"name":"Ongoing phishing campaigns - Ledger official","type":"official","url":"https://www.ledger.com/phishing-campaigns-status"}],"summary":"Ledger Live is the official companion application published by Ledger SAS for managing Ledger hardware wallets. The genuine application itself has no documented vulnerabilities that have led to direct fund loss, but the \"Ledger Live\" name and branding have been repeatedly and successfully counterfeited on major app marketplaces (Apple App Store, Microsoft Store, Google Play, Chrome Web Store), resulting in tens of millions of dollars in alleged theft from users who mistook fake listings for the real app. Separately, a genuine Ledger-published software component in the same ecosystem (the Ledger Connect Kit library) was compromised in a December 2023 supply-chain attack that briefly redirected funds from users of dApps integrating with Ledger hardware wallets.","timeline":[{"date":"2023-11-05","event":"On-chain investigator ZachXBT flags a fraudulent \"Ledger Live Web3\" app on the Microsoft Store; Microsoft removes it the same day. Reported losses of approximately $588,000-$768,000 in crypto across multiple chains.","source":"CoinDesk / Bleeping Computer","source_url":"https://www.coindesk.com/business/2023/11/06/microsoft-listing-fake-ledger-app-leads-to-590k-of-bitcoin-stolen-by-hackers"},{"date":"2023-12-14","event":"Ledger's genuine Connect Kit npm library is compromised via a phished former employee's account; malicious versions 1.1.5-1.1.7 drain over $600,000 from users connecting wallets through affected dApp front ends.","source":"The Hacker News","source_url":"https://thehackernews.com/2023/12/crypto-hardware-wallet-ledgers-supply.html"},{"date":"2023-12-20","event":"Ledger announces a plan to reimburse victims of the Connect Kit exploit, targeting completion by February 2024.","source":"DailyCoin","source_url":"https://dailycoin.com/ledger-unveils-plan-to-reimburse-wallet-drainer-hack-victims/"},{"date":"2025-09-08","event":"Ledger CTO Charles Guillemet publicly warns of a large-scale npm supply-chain attack (crypto-clipper malware) affecting the broader JavaScript ecosystem used by many crypto wallets and dApps.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2025/09/08/ledger-cto-warns-of-npm-supply-chain-attack-hitting-1b-downloads"},{"date":"2026-04-07","event":"A counterfeit macOS \"Ledger Live\" app published under the name \"Leva Heal Limited\" appears on Apple's App Store; the theft campaign is reported to run through April 13.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/04/14/a-fake-ledger-app-on-the-apple-app-store-just-drained-usd9-5-million-in-crypto"},{"date":"2026-04-14","event":"Apple removes the fake Ledger Live app after community/researcher reports; cumulative reported losses reach at least $9.5 million from more than 50 victims.","source":"Bleeping Computer","source_url":"https://www.bleepingcomputer.com/news/security/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 30a619ea-adfc-4cbd-8687-6b29dde5572e
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.