The important conclusion is this: we should always check the legitimacy of a site, ensure it is official and free of any malicious activity, and always check information from the relevant community about the site you are planning to visit.
-snip-
By the way, I am curious about the case you described. Could you provide a source? Maybe, it will become clearer, if we read it carefully, and we can understand how the phishing scam site works.
I don't know if this is the reddit thread OP is talking about, but the story seems almost the same --
How I lost over $1M after installed Ledger Wallet from App Store
The victim downloaded a fake Ledger Wallet app on his Mac from the official App Store. He wasn't aware that the desktop version is only available from the ledger.com website. In this case, the second user's argument would be right, because simply downloading a fake app shouldn't have been enough to drain his funds. He must've been tricked into entering his seed phrase, or maybe he signed a transaction on his device without verifying the details. Still, his actions were very careless for someone with a huge amount of money. As explained by one of the mods there:
It is also crucial to understand that a fake app cannot autonomously drain your wallet just by being installed. A hardware wallet's security model dictates that assets can only be moved if the 24-word recovery phrase was typed directly into the fake app, or if a malicious transaction was physically approved on the Ledger device screen.
So, opinion number two is correct in this case, right? but, it seems my previous explanation wasn't quite right.
There is an important lesson to be emphasized in this case: the victim mistake who easily downloading an app from an unofficial source (Ledger, in this case). He should have verified the source, checked with the relevant community, or at least checked the official website first, then looked at the download link provided there.
By the way, I just visited the Ledger website, and found that Ledger provides a download link for macOS, but why doesn't it go to the Mac App Store when I try to click it? Shouldn't it redirect to the Mac App Store? just like clicking the download link for Android, which redirects directly to the Google Play Store? or, has Ledger not yet registered their account as an Apple Developer there? Cmiiw.
Ledger company should realize how important it is to provide their application there, because they are a company that must also take care of its customers carefully, and because there are many people who depend on that company for their finances.