{"id":71935,"date":"2026-04-15T09:14:58","date_gmt":"2026-04-15T02:14:58","guid":{"rendered":"https:\/\/hbbgroup.net\/fake-ledger-live-app-on-apple-app-store-drained-9-5m-from-victims-zachxbt\/"},"modified":"2026-04-15T09:14:58","modified_gmt":"2026-04-15T02:14:58","slug":"fake-ledger-live-app-on-apple-app-store-drained-9-5m-from-victims-zachxbt","status":"publish","type":"post","link":"https:\/\/hbbgroup.net\/vi\/fake-ledger-live-app-on-apple-app-store-drained-9-5m-from-victims-zachxbt\/","title":{"rendered":"Fake Ledger Live app on Apple App Store drained $9.5M from victims: ZachXBT"},"content":{"rendered":"<div data-testid=\"html-renderer-container\">\n<p>Onchain investigator ZachXBT said a fake Ledger Live app listed on Apple\u2019s App Store was tied to about $9.5 million in crypto stolen from more than 50 suspected victims between April 7 and 13.<\/p>\n<p>In a Tuesday Telegram <a title=\"https:\/\/t.me\/investigations\/313\" href=\"https:\/\/t.me\/investigations\/313\" target=\"_blank\" rel=\"nofollow noopener\">post<\/a>, ZachXBT said the alleged thefts affected users across Bitcoin, Solana, Tron, XRP Ledger and Ethereum Virtual Machine (EVM)-compatible networks. He claimed the stolen funds were laundered through over 150 KuCoin deposit addresses allegedly tied to AudiA6, which he described as a centralized mixing service.\u00a0<\/p>\n<p>ZachXBT said the fake app was removed by Apple on April 13 and identified three seven-figure losses among the largest known cases. He said one victim lost about $1.95 million in Bitcoin (<a title=\"https:\/\/cointelegraph.com\/price-indexes\/bitcoin\" href=\"https:\/\/cointelegraph.com\/price-indexes\/bitcoin\">BTC<\/a>), staked Ether (stETH) and Ether (<a title=\"https:\/\/cointelegraph.com\/price-indexes\/ethereum\" href=\"https:\/\/cointelegraph.com\/price-indexes\/ethereum\">ETH<\/a>), another lost $3.23 million in USDt (<a title=\"https:\/\/cointelegraph.com\/price-indexes\/tether\" href=\"https:\/\/cointelegraph.com\/price-indexes\/tether\">USDT<\/a>) on April 9, and a third victim lost about $2 million in USDC (<a title=\"https:\/\/cointelegraph.com\/price-indexes\/usdc\" href=\"https:\/\/cointelegraph.com\/price-indexes\/usdc\">USDC<\/a>) on April 11.<\/p>\n<p>ZachXBT <a title=\"https:\/\/t.me\/investigations\/311\" href=\"https:\/\/t.me\/investigations\/311\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> Kucoin had seen an\u00a0increase in illicit activity\u00a0recently, and pointed out that the company had been <a title=\"https:\/\/cointelegraph.com\/news\/austria-regulator-slaps-new-business-ban-kucoin-eu\" href=\"https:\/\/cointelegraph.com\/news\/austria-regulator-slaps-new-business-ban-kucoin-eu\" target=\"_self\" rel>banned from onboarding new European Union users<\/a> in February, shortly after receiving its Markets in Crypto Assets Regulation (MiCA) license. He also questioned whether the incident presented grounds for a class action against Apple.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a title=\"https:\/\/cointelegraph.com\/news\/north-korea-it-worker-hacked-exposing-fraud-scam-operation\" href=\"https:\/\/cointelegraph.com\/news\/north-korea-it-worker-hacked-exposing-fraud-scam-operation\" target=\"_self\" rel><em><strong>Counterhacker exposes DPRK unit that made $1M a month working IT jobs<\/strong><\/em><\/a><\/p>\n<p>Key details, including the total losses, victim count and laundering route, remain based on ZachXBT\u2019s findings and had not been confirmed by Apple or KuCoin at publication. Cointelegraph asked both companies for comment but had not received a response by publication.<\/p>\n<h2>Ledger warns users never to enter seed phrase into apps<\/h2>\n<p>Ledger chief technology officer Charles Guillemet said in a statement to Cointelegraph that the company never asks users for their 24-word recovery phrase and warned that <a title=\"https:\/\/cointelegraph.com\/learn\/articles\/fake-coindcx-website-fraud-case-explained\" href=\"https:\/\/cointelegraph.com\/learn\/articles\/fake-coindcx-website-fraud-case-explained\">official-looking software environments<\/a> should not be treated as inherently safe.<\/p>\n<figure><img decoding=\"async\" alt=\"Security, Ledger, Cybersecurity, Scams, KuCoin\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2026-04\/019d8c2f-2798-7af9-a03c-347ab1531e74.png\"><figcaption><em>Fake Ledge Live app in the App Store. Source: <\/em><a title=\"https:\/\/archive.ph\/4RVLf\" href=\"https:\/\/archive.ph\/4RVLf\" target=\"_blank\" rel=\"nofollow noopener\"><em>Archive.ph<\/em><\/a><\/figcaption><\/figure>\n<p>\u201cYou cannot trust the software environment around you \u2013 not your browser, not your app store, not your desktop,\u201d Guillemet said, adding that attackers \u201coperate wherever the opportunity exists,\u201d including official distribution platforms.\u00a0<\/p>\n<p><em><strong>Related: <\/strong><\/em><a title=\"https:\/\/cointelegraph.com\/news\/web3-hacks-cost-464-million-in-q1-hacken\" href=\"https:\/\/cointelegraph.com\/news\/web3-hacks-cost-464-million-in-q1-hacken\"><em><strong>Web3 hacks cost $482M in Q1 as phishing drives majority of losses: Hacken<\/strong><\/em><\/a><\/p>\n<p>The latest incident follows a smaller but similar case reported on Monday. Musician Garrett Dutton, also known as \u201cG. Love,\u201d said he <a title=\"https:\/\/cointelegraph.com\/news\/musician-loses-420k-bitcoin-retirement-fund-after-installing-fake-ledger-app\" href=\"https:\/\/cointelegraph.com\/news\/musician-loses-420k-bitcoin-retirement-fund-after-installing-fake-ledger-app\">lost about $420,000 in BTC<\/a> after downloading a malicious app impersonating Ledger Live from Apple\u2019s App Store and entering his seed phrase.\u00a0ZachXBT said the stolen assets were sent to deposit addresses associated with KuCoin.\u00a0<\/p>\n<p><iframe width=\"100%\" height=\"315\" src=\"https:\/\/www.youtube.com\/embed\/_wUqq1Fm3nE?start=\" frameborder=\"0\" allow=\"accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen loading=\"lazy\"><\/iframe><\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a title=\"https:\/\/cointelegraph-magazine.com\/ai-dramatically-accelerated-quantum-threat-bitcoin-ai-eye\/\" href=\"https:\/\/cointelegraph-magazine.com\/ai-dramatically-accelerated-quantum-threat-bitcoin-ai-eye\/\" target=\"_blank\" rel=\"nofollow noopener\"><em><strong>How AI just dramatically sped up the quantum risk for Bitcoin<\/strong><\/em><\/a><\/p>\n<p><template data-type=\"defi_newsletter\" data-name=\"subscription_form\" data-label=\"Subscription Form: DeFi Newsletter\"><\/template><\/div>\n<p>Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph\u2019s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy <a href=\"http:\/\/cointelegraph.com\/editorial-policy\">https:\/\/cointelegraph.com\/editorial-policy<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Onchain investigator ZachXBT said a fake Ledger Live app listed on Apple\u2019s App Store was tied to about $9.5 million [&hellip;]<\/p>","protected":false},"author":5,"featured_media":71936,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[220],"tags":[],"class_list":["post-71935","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tien-dien-tu"],"acf":[],"_links":{"self":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/posts\/71935","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/comments?post=71935"}],"version-history":[{"count":0,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/posts\/71935\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/media\/71936"}],"wp:attachment":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/media?parent=71935"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/categories?post=71935"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/tags?post=71935"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}