A counterfeit Ledger Live application, discovered on Apple's official Mac App Store, has resulted in the theft of nearly 6 Bitcoin (BTC), valued at over $424,000, from musician Garrett Dutton, known professionally as G. Love.
图片:代表数字店面中的欺诈性应用程序的插图。
In an April 11 post on social media platform X, Dutton detailed the incident, which occurred while he was setting up his Ledger hardware wallet on a new Apple computer.他在应用商店中搜索“Ledger Live”,下载了看似合法的应用程序,然后按照其说明进行操作。然后,恶意软件提示他输入 24 个字的恢复助记词,这是正版硬件钱包软件从来不需要的关键安全元素。输入该短语后,攻击者立即耗尽了他钱包中的 5.92 BTC。
"I lost 5.9 BTC all I had for ten years I worked on this f#ck be careful out there," Dutton wrote, stating the stolen funds constituted part of his retirement savings.
图像:区块链上加密货币交易跟踪的表示。
链上调查员 ZachXBT 追踪了被盗的比特币,发现资金是通过被识别为加密货币交易所 KuCoin 存款地址的地址传送的。当被问及复苏的可能性时,ZachXBT 表示对交易所干预的希望不大。 The investigator criticized KuCoin's selective compliance and cited the exchange's loss of its Markets in Crypto-Assets (MiCA) license just three months after obtaining it in February 2026 as evidence of systemic issues.
“非法服务继续利用平台上的经纪人和个人账户,几乎没有明显的监管阻力,”ZachXBT 补充道,并指出涉及的大量存款地址表明窃贼可能使用了即时兑换服务。
该事件引发了安全专业人士的再次警告。 Pudgy Penguins 的安全主管 Beau 强调了一条基本规则:切勿将硬件钱包的种子短语输入任何联网设备,例如笔记本电脑或手机。
他解释说,诈骗者经常通过网络钓鱼电子邮件、欺骗性在线广告甚至实体邮件分发虚假钱包应用程序。 Beau advised users to treat any unsolicited message urging them to download or update wallet software as a potential scam until they can verify its authenticity through official, independent channels.
此次盗窃事件凸显了复杂的网络钓鱼活动和虚假应用程序带来的持续风险,即使是在苹果应用商店等精心策划的平台上,也凸显了用户在加密货币自我托管方面保持警惕的迫切需要。
