logo

The $9.5 Million Blind Spot: How a Fake Ledger App Evaded Apple’s Vetting to Empty User Wallets

ID: f4cdc20b-9477-5e72-868e-eb1626a08c8f

STIX ID: report--f4cdc20b-9477-5e72-868e-eb1626a08c8f

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-23

Author: Ddos

...
...

A malicious macOS application impersonating Ledger Live bypassed Apple’s App Store vetting between April 7–13, 2026, coerced users into divulging recovery seed phrases, and enabled theft of roughly $9.5M from more than 50 victims; stolen funds were laundered via the Audi A6 mixer and moved through KuCoin. The report stresses Ledger Live is distributed only from Ledger’s official site and highlights the failure in App Store oversight that allowed the scam to reach users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.