{"id":96167,"date":"2026-04-14T16:07:04","date_gmt":"2026-04-14T13:07:04","guid":{"rendered":"https:\/\/u1f987.com\/en\/?p=96167"},"modified":"2026-04-14T16:10:21","modified_gmt":"2026-04-14T13:10:21","slug":"fraudsters-steal-9-5-million-via-fake-ledger-app-in-app-store","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/fraudsters-steal-9-5-million-via-fake-ledger-app-in-app-store\/","title":{"rendered":"Fraudsters Steal $9.5 Million via Fake Ledger App in App Store"},"content":{"rendered":"<p>A counterfeit Ledger Live app in the App Store enabled hackers to steal cryptocurrency worth at least $9.5 million, according to on-chain detective ZachXBT.\u00a0<\/p>\n<p><script async src=\"https:\/\/telegram.org\/js\/telegram-widget.js?23\" data-telegram-post=\"investigations\/313\" data-width=\"100%\"><\/script><\/p>\n<p>On April 13, one victim, G. Love frontman Garrett Dutton, <a href=\"https:\/\/u1f987.com\/en\/news\/hacker-breaches-hyperbridge-mints-1-billion-polkadot-tokens\">revealed<\/a> that he lost all his savings of 5.9 BTC (about $420,000) accumulated over 10 years to this scheme. He explained that he downloaded the wallet on a new computer and entered the seed phrase, only to find the software was fraudulent.\u00a0<\/p>\n<p>ZachXBT traced the stolen assets, which were moved through a series of transactions to the KuCoin exchange. The expert later clarified that the perpetrators used this platform to launder the stolen cryptocurrency.\u00a0<\/p>\n<blockquote class=\"twitter-tweet\" data-conversation=\"none\">\n<p lang=\"en\" dir=\"ltr\">C) Want to explain to the community why Kucoin allowed a threat actor to launder $9.5M+ tied to a fake Ledger app via 150+ Kucoin deposit addresses over the past week?<\/p>\n<p>A few days before that another threat actor laundered $3.5M+ from the Bitcoin Depot incident via 25+ Kucoin\u2026 <a href=\"https:\/\/t.co\/vo7jb1rdwu\">pic.twitter.com\/vo7jb1rdwu<\/a><\/p>\n<p>\u2014 ZachXBT (@zachxbt) <a href=\"https:\/\/twitter.com\/zachxbt\/status\/2044009775546151180?ref_src=twsrc%5Etfw\">April 14, 2026<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>&#8220;Over the past week, $9.5 million stolen through a fake Ledger app was laundered via more than 150 KuCoin deposit addresses. A few days earlier, $3.5 million from <\/em><a href=\"https:\/\/u1f987.com\/en\/news\/bitcoin-depot-atm-operator-reports-3-7-million-theft\"><em>the Bitcoin Depot hack<\/em><\/a><em> was moved through 25+ wallets on the platform,&#8221; he wrote.\u00a0<\/em><\/p>\n<\/blockquote>\n<p>The incident affected more than just the musician. Over 50 users across various networks, including Bitcoin, <a href=\"https:\/\/u1f987.com\/en\/news\/what-is-tron-trx\">TRON<\/a>, <a href=\"https:\/\/u1f987.com\/en\/news\/what-is-solana-sol\">Solana<\/a>, and XRP Ledger, were also victimized.\u00a0<\/p>\n<p>The phishing campaign ran from April 7 to 13. Among the largest losses were:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>$3.23 million in <a href=\"https:\/\/u1f987.com\/en\/news\/what-is-tether-usdt\">USDT<\/a>;<\/li>\n<li>$2.08 million in <a href=\"https:\/\/u1f987.com\/en\/news\/what-is-the-usdc-stablecoin\">USDC<\/a>;<\/li>\n<li>$1.95 million in BTC, ETH, and stETH.<\/li>\n<\/ul>\n<p>In all cases, victims entered their seed phrase into the fake app, giving perpetrators full control over their wallets.<\/p>\n<p>ZachXBT also discovered that all deposit addresses on KuCoin, through which the stolen assets were moved, are linked to the AudiA6 service. This is a centralized crypto mixer that charges high fees for concealing illicit flows.\u00a0<\/p>\n<p>At the time of writing, Apple has removed the fake Ledger Live from the App Store. However, it remains unclear how this software passed moderation.\u00a0<\/p>\n<p>The on-chain detective suggested that the corporation might face legal consequences given the scale of the losses.\u00a0<\/p>\n<p>Ledger did not comment on the incident. However, the wallet team reminded users of basic phishing protection rules.\u00a0<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Protecting your digital life starts with staying alert to scams and phishing attempts.<\/p>\n<p>As digital ownership grows, fraud is becoming more sophisticated, and more frequent.<\/p>\n<p>Here are a few security reminders to keep top of mind \ud83e\uddf5 <a href=\"https:\/\/t.co\/az2Exj7cOu\">pic.twitter.com\/az2Exj7cOu<\/a><\/p>\n<p>\u2014 Ledger (@Ledger) <a href=\"https:\/\/twitter.com\/Ledger\/status\/2043703785449472174?ref_src=twsrc%5Etfw\">April 13, 2026<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<h2 class=\"wp-block-heading\">First Quarter Losses\u00a0<\/h2>\n<p>Experts at Hacken <a href=\"https:\/\/hacken.io\/insights\/q1-2026-security-report\/\">calculated<\/a> that in the first quarter, <a href=\"https:\/\/u1f987.com\/en\/news\/what-is-web3\">Web3<\/a> projects lost $482 million due to hacks and fraud.\u00a0<\/p>\n<p>During the reporting period, phishing and social engineering attacks dominated. As a result of 44 incidents, hackers stole $306 million.\u00a0<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/img-382d6bb57dc32d9f-1773248984109540.webp\" alt=\"Hacken: crypto industry losses from hacks and fraud in the first quarter of 2026\" class=\"wp-image-278440\"\/><figcaption class=\"wp-element-caption\">Source: Hacken.\u00a0<\/figcaption><\/figure>\n<p>According to experts, the largest incidents occur not in on-chain code but at the operational and infrastructure levels, which traditional audits almost never cover.<\/p>\n<p>Analysts cited examples such as:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>phishing, which cost the industry $306 million;<\/li>\n<li>a fake call from a &#8220;venture capitalist&#8221; (actually a North Korean hacker) to Step Finance, resulting in the project <a href=\"https:\/\/u1f987.com\/en\/news\/coinbase-confirms-data-leak-record-ransom-in-russia-and-other-cybersecurity-news\">losing $40 million<\/a>;<\/li>\n<li>the compromise of <span data-descr=\"Amazon Web Services\" class=\"old_tooltip\">AWS<\/span> key management service <a href=\"https:\/\/u1f987.com\/en\/news\/hacker-attack-on-resolv-crashes-usr-stablecoin\">at Resolv Labs \u2014 $25 million<\/a>.<\/li>\n<\/ul>\n<p>Even where smart contracts are to blame, the most costly mistakes often involved old deployments and known vulnerability classes:<\/p>\n<ul class=\"wp-block-list\">\n<li>Truebit <a href=\"https:\/\/u1f987.com\/en\/news\/truebit-token-plummets-after-26-million-hack\">lost<\/a> $26.4 million due to an error in a Solidity contract deployed about five years ago;<\/li>\n<li>Venus Protocol <a href=\"https:\/\/u1f987.com\/en\/news\/venus-protocol-loses-2-million-due-to-token-the-manipulation\">suffered<\/a> from a classic price <a href=\"https:\/\/u1f987.com\/en\/news\/what-is-a-blockchain-oracle\">oracle<\/a> manipulation scheme known since 2022.<\/li>\n<\/ul>\n<p>Audited projects (Resolv \u2014 18 audits, Venus \u2014 five) lost $37.7 million. On average, their losses are higher than those of projects without audits. Protocols with a large <span data-descr=\"total value locked\" class=\"old_tooltip\">TVL<\/span> become targets for the most experienced hackers, noted Hacken.\u00a0<\/p>\n<p>Earlier in April, Solana project Drift Protocol <a href=\"https:\/\/u1f987.com\/en\/news\/drift-protocol-on-solana-loses-280m\">lost<\/a> $280 million. Experts <a href=\"https:\/\/u1f987.com\/en\/news\/north-korean-hackers-linked-to-280-million-drift-defi-protocol-breach\">linked<\/a> the hack to the Lazarus group from North Korea.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A counterfeit Ledger Live app in the App Store enabled hackers to steal cryptocurrency worth at least $9.5 million, according to on-chain detective ZachXBT.<\/p>\n","protected":false},"author":1,"featured_media":96168,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"Fake Ledger app in App Store leads to $9.5M crypto theft, says ZachXBT.","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1112,44,1640,1246],"class_list":["post-96167","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-apple","tag-cybercrime","tag-ledger","tag-scammers"],"aioseo_notices":[],"amp_enabled":true,"views":"37","promo_type":"1","layout_type":"1","short_excerpt":"Fake Ledger app in App Store leads to $9.5M crypto theft, says ZachXBT.","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/96167","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=96167"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/96167\/revisions"}],"predecessor-version":[{"id":96169,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/96167\/revisions\/96169"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/96168"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=96167"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=96167"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=96167"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}