Hazink
Sr. Member
  

Activity: 1036
Merit: 457
Trêvoid █ No KYC-AML Crypto Swaps
|
 |
April 13, 2026, 09:28:57 PM |
|
It's interesting to see how non of this, as written, is fault of Bitcoin.. Additional security for funds, App store not allowing fake apps, and exchangers making things difficult for scammers would make future hack like that more difficult.
Stores where they download apps from can only try as much as they can to limit how many of such fake apps get listed in their stores, but they can't completely stop them. The more they are upgrading their system to detect them, the more the scammers will also put in more effort to bypass them. The real work is left with us to be very vigilant not to fall victim to such a scam. Anything that concerns our wallet and funds. I always take extra precautions to make sure I'm doing the right thing, because once they are gone, it's gone forever. There is no reverse button.
|
|
|
|
|
Churchillvv
|
In recent times I have come across things that made me understand the need for verification, I wanted to download a popular application which was everywhere little did I know that it can’t be found on AppStore nor play store it only gotten through direct download from the official website.
And if you have been in the forum you will find bout that list times people refer you to download it from the official website, a YouTube video guided through the times and I didn’t fall victim of this, but however, AppStore and Playstore care less of what happens after the installation but however it’s a personal duty to figure out if the application you downloaded are the right one.
This lesson is hard on him but not a new one either, just that he didn’t follow due diligence. But anyone could also be a victim.
|
|
|
|
coinlary (OP)
Sr. Member
  

Activity: 798
Merit: 298
Make decisions without looking back
|
 |
April 13, 2026, 09:48:12 PM |
|
Mennn... This sucks! Looks more like a beginner mistake.
It seems it was his first time of using a hardware device. If he had used one before, he would have known that one does not need to enter the seed phrase on an app but on the hardware device itself, and this would have been avoided.
No, he's not a beginner. I don’t know how true, but he mentioned that he's been into crypto stuff since 2017: https://x.com/i/status/2043135121516056723. That doesn't look like a beginner even though years don't guarantee the level of knowledge. That’s not my main point anyway. It can happen to anyone, don't think it only affects beginners. He said he was tricked, which means it must have been something well crafted to steal users coins even though such wallet shouldn't ask for a seed. Just me thinking what If he had ignored Ledger, maybe he would still have his BTCs.
|
|
|
|
RGBTC
Legendary

Activity: 2814
Merit: 1149
Vega.Bet
|
What makes me a bit surprised is how Ledger might let their desktop application only be available via direct download from the official Ledger website. This is actually the safest method to avoid getting an unofficial app. Listing the downloaded file in a company's private directory will allow for two-way scrutiny from both the specific team and the user, adding an extra layer of security and verification, such as a digital signature etc. But if it is laundered through KuCoin, the hacker's identity should be known because they enforce KYC. Hopefully KuCoin can help him to freeze that Bitcoin.
Let's hope for the best, as verified exchange accounts are also freely available on the black market.
|
|
|
|
taufik123
Legendary

Activity: 3402
Merit: 2547
Duelbits.com
|
 |
April 14, 2026, 01:26:12 AM |
|
5.96 BTC is a large amount that is worth the current $443,284 rate ($74,376), Why didn't he double-check before downloading the app, he should have downloaded it from his official website. Even though iPhone products in the App Store are usually safer than android, but they can still be infiltrated by phishing applications that make someone suffer more losses.
But it should have been detected by his Mac device, or maybe it was still completely undetected. But this is also the fault of the user not being very thorough.
Then who should be responsible for this incident, because this application is actually downloaded from the App Store and is not even detected by the security of the device. I think android is weaker, but iPhone also has a friendliness that needs to be fixed as soon as possible.
|
|
|
|
|
knowngunman
|
Perhaps, this will change the mindset of people that believe anything from Appstore is completely safe. I know cases like this are more common with Playstore but this incident just confirmed that all stores are the same.
The first mistake of the victim was downloading the wallet from the store using the search button. He could have visited the official website and click on the download link directly from the official website. I believe Playstore would have suggested multiple similar apps when you use their search engines for any app.
Another mistake was having all his eggs in one basket. Having that Bitcoin, he could have split it into different wallets. He might still have some Bitcoin left if he had store them in different wallets.
When you have a significant coins, security of your assets should be taken seriously.
|
| █▄ | R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | ▀█ | THE #1 SOLANA CASINO | ████████████▄ ▀▀██████▀▀███ ██▄▄▀▀▄▄█████ █████████████ █████████████ ███▀█████████ ▀▄▄██████████ █████████████ █████████████ █████████████ █████████████ █████████████ ████████████▀ | ████████████▄ ▀▀▀▀▀▀▀██████ █████████████ ▄████████████ ██▄██████████ ████▄████████ █████████████ █░▀▀█████████ ▀▀███████████ █████▄███████ ████▀▄▀██████ ▄▄▄▄▄▄▄██████ ████████████▀ | ........5,000+........ GAMES ......INSTANT...... WITHDRAWALS | ..........HUGE.......... REWARDS ............VIP............ PROGRAM | . PLAY NOW |
|
|
|
Cookdata
Legendary

Activity: 1820
Merit: 1499
Not Your Keys, Not Your Bitcoin
|
 |
April 14, 2026, 02:39:32 PM |
|
This report sound unbelievable at first when I saw the thread on X, I even said he was looking for attention because he wasn't providing the necessary details for one to verify. Probably he was still in shock after losing his entire savings to a scammer. With this kind of mistake, I doubt if people still knows the purpose of hardware wallet. He comfortably imported seed phrase from his hardware wallet to a suppose ledgerlive firmware, in this case a fake software wallet, this guy doesn't knows nothing aabout a hardware walle but this isn't the time to blame. According to ZachXBT, more than $9.5M has been drained through that fake ledgerlive wallet. Out of the many, he was one of the victims that spoke out.  I hope apple takes their security serious on Mac app store with apps deployed and perhaps kucoin might be able help in their investigations for the affected victims. I just hope this will not be another case of laundering through another identity, it's possible that kucoin may be able to map accounts that match the deposit address but the users behind are not even responsible for this act, this is why AML and Kyc is useless most often. There is no way the drainers will be that dumb to cash the coins that will traced back to them.
|
|
|
|
acroman08
Legendary
Online
Activity: 3206
Merit: 1305
|
 |
April 14, 2026, 06:12:05 PM |
|
This sucks for him, it's an expensive mistake for him, hopefuly next time he double check, tripple check or as you said, download the app through the official website(even then he should still double check the website). This is also why I'm always reluctant to download something especially if it is from the app store/playstore, there are just too many fake apps with malwares there and the app store/playstore are not doing anything about it.
|
|
|
|
|
aoluain
Legendary

Activity: 3136
Merit: 1774
|
 |
April 14, 2026, 06:24:14 PM |
|
That is not good at all. This sort of thing has been happening for many years and on google also where a fake website is served before the authentic one in a search result.
IMO this just goes to show that big tech want our money but they really dont care about us at all. The proper checks should have been carried out before that app was made available on the apple platform. This just serves as a reminder that we need to keep checking everything we do online.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
salad daging
Legendary

Activity: 2534
Merit: 1070
Bitcoin To The Moon 📈📈📈
|
 |
April 14, 2026, 06:32:07 PM |
|
In recent times I have come across things that made me understand the need for verification, I wanted to download a popular application which was everywhere little did I know that it can’t be found on AppStore nor play store it only gotten through direct download from the official website.
And if you have been in the forum you will find bout that list times people refer you to download it from the official website, a YouTube video guided through the times and I didn’t fall victim of this, but however, AppStore and Playstore care less of what happens after the installation but however it’s a personal duty to figure out if the application you downloaded are the right one.
This lesson is hard on him but not a new one either, just that he didn’t follow due diligence. But anyone could also be a victim.
There may be some people who make mistakes in their actions where they believe that by searching directly in the appstore / playstore it is a safe application, wrongly they often do not think there are many cloned applications scattered in the application store, even though the appstore has a strict review, there are always gaps. Yep if they ask on the forum then the best advice will be given, it's just that when it happens to be a victim then they immediately speak up with the case they experienced, if it's like this there is nothing that can help except making this a lesson. I always visit the official website first to download the Trezor suite and then I say it's safe.
|
|
|
|
|
coinlary (OP)
Sr. Member
  

Activity: 798
Merit: 298
Make decisions without looking back
|
 |
April 14, 2026, 06:54:11 PM |
|
Now, I think everyone should know that these companies aren’t really responsible for your loss even if they allow fake and malicious apps to be added to their stores, get used to it already.
I believe they should be held accountable for this apps they add to their store. And, of course, they should thoroughly check these apps before publishing them. Otherwise, what's the point of having a store at all? Malicious apps disguised as useful apps can be downloaded directly from the app store. If they want to preserve their store's user base, they should be held accountable (not publishing infected apps, and if they do and these actions result in user losses, they should compensate them). Yeah I know they should, that's a figure of speech. Take a look at this issue , you will understand what I meant better : In 2022 someone sued apple for exactly same thing that happend to Garrett Dutton, the musicia( i learnt his name from a post today). But this what what happened Apple was protected by Section 230 of the Communications Decency Act (“CDA”) from such liability. Beyond failing to convince the court that Apple’s actions fell outside CDA Section 230, Plaintiff was also unsuccessful in overcoming the argument that the limitation of liability clause in Apple’s terms was enforceable with respect to the various claims. This is what CDA Section 230[C1] says : (c)Protection for “Good Samaritan” blocking and screening of offensive material (1)Treatment of publisher or speaker No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider. Now, checkout Apple Licensed Application End User License Agreement : YOU EXPRESSLY ACKNOWLEDGE AND AGREE THAT USE OF THE LICENSED APPLICATION IS AT YOUR SOLE RISK. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE LICENSED APPLICATION AND ANY SERVICES PERFORMED OR PROVIDED BY THE LICENSED APPLICATION ARE PROVIDED "AS IS" AND “AS AVAILABLE,” WITH ALL FAULTS AND WITHOUT WARRANTY OF ANY KIND And Google TOS(although it's content but it's still pointing to almost same thing ): Content may be offered by Google or made available by third-parties not affiliated with Google. Google is not responsible for and does not endorse any Content made available through Google Play that originates from a source other than Google.
This shows that even if they are responsible for the damage caused , they will always hide behind the law unless they are willingly submit & taking full responsibility. So it's high time Users start taking caution and getting used to navigating or downloading through the official site, I didn't noticed earlier
|
|
|
|
The Cryptovator
Legendary

Activity: 3038
Merit: 2621
Protect your privacy 🔏 it's very important
|
 |
April 14, 2026, 07:24:59 PM |
|
I'm a little confused as to how his bitcoins was stolen? His case description only mentions installing a new app, not entering the seed phrase on the device. Malware couldn't have stolen his bitcoin without him pressing a button on hardware wallet.
Sadly, it was due to his own lack of diligence. According to the article shared by OP, he was prompted by the app to enter his seed phrase. After that, all of his bitcoins were immediately stolen. Though I can't remember fully, I think when I generated the seed on the device, it wasn't necessary to do it through the app. I might be wrong; I have to enter the seed on the device during recovery of my wallet when the device resets for the testing purposes. Because I have tried to reset my hardware wallet to make sure all the functions were working well. So I don't think a Ledger user needs to input their seed phrase on the software. It's related to the hardware wallet directly. I can remember when I tried to recover my wallet; it was quite hard to input the seed on the device since there is a limited button. However, sorry for the person who lost such a big amount. Don't take it negatively, but whoever has this kind of funds in their wallet must study more how to secure their funds. It's not an option; it's mandatory for big holders. Otherwise, they have to suffer this way. Before I buy each hardware like Ledger and Trezor, I first make sure how everything works. Because I am not an expert, it means I have to learn from the authentic resources.
|
| | Sportsbet.io | │ |
| │ |
| │ | ████████████████████████ ██ ██████
██ ████████████████
MORE THAN A BET!
██ ████████████████
██ █████████████████████ ██ ████████ |
|
|
|
|
Churchillvv
|
 |
April 14, 2026, 09:09:27 PM |
|
Snip
There may be some people who make mistakes in their actions where they believe that by searching directly in the appstore / playstore it is a safe application, wrongly they often do not think there are many cloned applications scattered in the application store, even though the appstore has a strict review, there are always gaps. Yep if they ask on the forum then the best advice will be given, it's just that when it happens to be a victim then they immediately speak up with the case they experienced, if it's like this there is nothing that can help except making this a lesson. I always visit the official website first to download the Trezor suite and then I say it's safe. Perhaps there is still no guarantee that because you downloaded from the official site that you’re safe or there could be no threat in the download but however the fact that it does not exist in the AppStore nor playstore makes it more likely to be a good one. Apps can be cloned on either store but however the store is only charged with the obligation to verify the company which the application is created or registered with but however what the application does to you, good or bad can not be verified by the store, it’s from users rating that they usually know which is bad or good. So this is more reason you can find scammers application on both store.
|
|
|
|
|
Rgram
|
 |
April 14, 2026, 09:22:05 PM |
|
The easy way out always gets the best of us and once again, it has made an example out of this fellow. It’s a very sad sad thing to experience how, all your life’s work can be swept away in an instant. Possibly a down side to crypto, not having to give you a prompt that ensures you’re the one operating the wallet at the time but even then, it’s still the advantage we seek, having all liberty ti do as we please once we’ve imported our wallets without any prompt. The issue here is, not having to verify the authentic source for downloads as AppStore and Playstore doesn’t guarantee authenticity. GitHub has being a good reference point in most cases.
|
|
|
|
|
sokani
|
 |
April 14, 2026, 09:43:16 PM |
|
This is actually the safest method to avoid getting an unofficial app. Listing the downloaded file in a company's private directory will allow for two-way scrutiny from both the specific team and the user, adding an extra layer of security and verification, such as a digital signature etc.
Not everyone knows how important it is to verify the digital signature of applications before running them on their devices and that's why I support the idea of having these apps only on their official websites. If hardware manufacturers really care about their users, companion apps like Ledger Live, Trezor Suite, Tagem app, SafePal app, etc, should be removed from the App Store and Play Store. As long as these apps remain on these websites, scammers will continue to deploy fake apps, and ignorant people will keep making the mistake of downloading them and losing money.
|
|
|
|
|
Hamza2424
Legendary

Activity: 1792
Merit: 1163
|
 |
April 14, 2026, 09:59:32 PM |
|
That's really disturbing, because if someone loses their retirement funds, it means they have to start again. But he does not seem too disturbed from the look of his posts, though that is just my observation anyway. Bro, I think Apple has made itself such a big brand that people have always trusted it from a security point of view. They think it cannot be hacked, and that they will not lose anything if they use Apple products.
Because their security checks are better than anyone else's.
So that trust blinded them, and they did not think about checking all this. They downloaded the Ledger wallet on his new device, while probably on the old one he had the original app. I am sure people make such mistakes because other factors also influence them, and in this case it was Apple.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
taufik123
Legendary

Activity: 3402
Merit: 2547
Duelbits.com
|
 |
April 15, 2026, 04:03:34 AM |
|
The easy way out always gets the best of us and once again, it has made an example out of this fellow. It’s a very sad sad thing to experience how, all your life’s work can be swept away in an instant. Possibly a down side to crypto, not having to give you a prompt that ensures you’re the one operating the wallet at the time but even then, it’s still the advantage we seek, having all liberty ti do as we please once we’ve imported our wallets without any prompt.
The issue here is, not having to verify the authentic source for downloads as AppStore and Playstore doesn’t guarantee authenticity. GitHub has being a good reference point in most cases.
When he believes too much in the security of the device he owns and the AppStore which is known to be very meticulous and always makes a strict selection for the applications to be registered, in the end he falls into the trap of scammers who make Fake Live Applications that manage to exist on the official Appstore. This is a warning to all of us, Nothing is really safe, vigilance is always the main thing to do, being skeptical may be better, Will not trust any application even if it is in an official place, there should always be a check in advance to enter the Passphrase anywhere. When an incident like this happens to someone who loses all his hard work for a lifetime, then who should be responsible? He has bought an official device and downloaded it in an official place, but is stuck with a fake application, does Apple not take this case seriously?
|
|
|
|
ThemePen
Legendary

Activity: 1568
Merit: 1027
I stand with Palestine.
|
 |
April 15, 2026, 04:33:48 AM |
|
Not everyone knows how important it is to verify the digital signature of applications before running them on their devices and that's why I support the idea of having these apps only on their official websites. If hardware manufacturers really care about their users, companion apps like Ledger Live, Trezor Suite, Tagem app, SafePal app, etc, should be removed from the App Store and Play Store. As long as these apps remain on these websites, scammers will continue to deploy fake apps, and ignorant people will keep making the mistake of downloading them and losing money.
Having crypto apps in normal app stores leads to trouble between being easy to use and high security methods since stores are easy to use, which lets scammers make fake apps and smart search rules and rob unaware users. People have habit to trust any app they can find in real store and are unaware of fact that cheats can skip store reviews and make secret entries through which they steal password phrases. I think it is dangerous move to just get rid of them since it may force users to go even further down bad path and download apps in even more unwise ways. They need to use deep linking where users can only get actual app via safe link on official site. This would remove easy path that people use when trying to find name of brand, and will also work to remove fact that easy mistake can lead to much of lost money.
|
| █▄ | R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | ▀█ | THE #1 SOLANA CASINO | ████████████▄ ▀▀██████▀▀███ ██▄▄▀▀▄▄█████ █████████████ █████████████ ███▀█████████ ▀▄▄██████████ █████████████ █████████████ █████████████ █████████████ █████████████ ████████████▀ | ████████████▄ ▀▀▀▀▀▀▀██████ █████████████ ▄████████████ ██▄██████████ ████▄████████ █████████████ █░▀▀█████████ ▀▀███████████ █████▄███████ ████▀▄▀██████ ▄▄▄▄▄▄▄██████ ████████████▀ | ........5,000+........ GAMES ......INSTANT...... WITHDRAWALS | ..........HUGE.......... REWARDS ............VIP............ PROGRAM | . PLAY NOW |
|
|
|
Luzin
Legendary

Activity: 2324
Merit: 1028
|
 |
April 15, 2026, 04:51:26 AM |
|
This is not the first person who has fallen for this type of scam, and he won't be the last, so don't make a mistake of thinking Electrum has an official wallet for iOS devices, Sparrow has an official mobile wallet, and so many more.
Thieves take advantage of the carelessness and ignorance of users. This is bad, and I am quite lucky to have joined this forum. I have special validation through this forum regarding anything related to Bitcoin and storage wallets. My local forum discusses several wallets and original sources, so I always use these original sources to obtain applications. So it seems that the topic of original sources could be a good and useful topic. A topic containing original links to go to the official sites. It might be limited to forum users, but at least it is useful and reduces losses.
|
|
|
|
|
The Cryptovator
Legendary

Activity: 3038
Merit: 2621
Protect your privacy 🔏 it's very important
|
Update: Just right now, noticed from Cointelegraph, Apple removed a fake Ledger app that stole $9.5M from crypto investors. That means, due to the fake apps, holders lost $9.5M. But the question is who should take the responsibility? Apple couldn't ignore their responsibility since they approved those apps. But I think Apple will be freed from the trap of terms, and holders will lose it forever. According to the news, almost 50 users lost the funds, and three users lost big funds. We have to learn the Apple Store doesn't mean all software there is trusted. Shouldn't trust anything related to funds blindly; we have to verify if they are fake or real. The scammer 'SAS Software Company' used a 'bait-and-switch strategy' to place their apps/software on the Apple Store. I will write more details about it on a new thread from where everyone should learn.
|
| | Sportsbet.io | │ |
| │ |
| │ | ████████████████████████ ██ ██████
██ ████████████████
MORE THAN A BET!
██ ████████████████
██ █████████████████████ ██ ████████ |
|
|
|
|