Close Menu
  • Home
  • Daily
  • AI
  • Crypto
  • Bitcoin
  • Stock Market
  • E-game
  • Casino
  • World
  • Affiliate News
  • English
    • Português
    • English
    • Español

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Extra Materials Guide (Appliques and Stickers) In Fantasy Life i

May 25, 2025

Crypto investor charged with kidnapping, torturing an Italian for passwords

May 25, 2025

Pokemon GO Player Finally Catches Super Rare Pokemon Variant After Nearly 9 Years of Playing

May 25, 2025
Facebook X (Twitter) Instagram
MetaDaily – Breaking News in Crypto, Markets & Digital Trends
  • Home
  • Daily
  • AI
  • Crypto
  • Bitcoin
  • Stock Market
  • E-game
  • Casino
  • World
  • Affiliate News
  • English
    • Português
    • English
    • Español
MetaDaily – Breaking News in Crypto, Markets & Digital Trends
Home » Fake Ledger Live App | MacOS
Bitcoin

Fake Ledger Live App | MacOS

adminBy adminMay 24, 2025No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
Share
Facebook Twitter LinkedIn Pinterest Email


Mac users who use Ledger hardware wallets to manage their digital assets are being warned about a new scam that uses fake apps to steal funds.

Cybercriminals have launched multiple phishing campaigns using malware that targets macOS systems, replacing the real Ledger Live app with a fake version that asks users to enter their recovery phrase.

These fake apps look almost identical to the real Ledger Live, but instead of helping users manage their bitcoin, they steal the 24-word recovery phrase—the master key to the user’s digital assets.

According to a detailed analysis by Moonlock, the attacks start when users’ computers get infected with Atomic macOS Stealer malware from one of over 2,800 hacked websites. Once installed, the malware removes the legitimate Ledger Live app and installs a malicious version in its place.

The fake app then shows a pop-up message saying it has detected “suspicious activity”, and asks the user to enter their recovery phrase to fix the issue. Once entered, the seed phrase is sent to a server controlled by the attacker.

moonlock atomic stealer macosmoonlock atomic stealer macos
2,800 websites discovered infected with Atomic Stealer — Moonlock

“Once entered, the seed phrase is sent to an attacker-controlled server, exposing the user’s assets in seconds,” Moonlock said in their May 22 report.

With the recovery phrase, the scammers can drain the user’s wallet of all digital assets—bitcoin and other tokens.

This isn’t an isolated incident. Moonlock has been tracking this malware since August 2024 and has found at least four active campaigns targeting Mac users. They believe the attackers are getting more sophisticated and are refining their methods.

“This isn’t just a theft. It’s a high-stakes effort to outsmart one of the most trusted tools in the crypto world. And the thieves are not backing down,” Moonlock researchers said.

Initially, the fake Ledger Live apps could only steal passwords and view wallet details. This gave attackers some insight into victims’ assets but no way to steal funds directly.

However, over time, hackers have improved their tactics and are now harvesting recovery phrases, so they can take full control of wallets and move funds freely.

One strain of malware, called Odyssey, was spotted in March and was linked to a hacker using the alias “Rodrigo”.

Odyssey replaces Ledger Live with a trojanized app and displays a phishing page asking users to enter their recovery phrases after showing a fake “critical error” message. Another copycat campaign using AMOS (Atomic macOS Stealer) followed soon after.

fake ledger live macosfake ledger live macos
The fake Ledger Live app asks for user’s seed phrase — Moonlock

In one case, a fake app even displayed an “App corrupted” error after stealing the seed phrase to lower the victim’s suspicion and buy time to transfer the funds.

For years, computers running MacOS were considered safer than their Windows counterparts, because the operating system is less prone to malware. This advanced malware shows that users can never be too careful.

Attackers aren’t just relying on infected apps to steal from users. Other scam tactics include:

Discord attacks: In May, a moderator account in Ledger’s official Discord server was compromised. Attackers used it to post fake verification links.

Reddit phishing: In January, a user reported losing $15,000 after unknowingly entering their recovery phrase into a fake app.

Physical mail scams: In April, some Ledger users received letters claiming to be from the company. These letters included QR codes leading to phishing sites that asked for seed phrases under the guise of a “critical security update”.

Attackers are increasingly targeting users holding hardware wallets, because they might be holding larger amounts.

Earlier this month, a Trezor One user reported being contacted by Coinbase impersonators, who tricked him into entering his seed phrase into a fake website, resulting in loss of 17.5 BTC.

The final goal for all these attacks is similar: the attackers are looking for users’ seed phrases, and they are getting creative in finding new ways to acquire them.

One sure way of staying safe is to learn more. The golden standard rule is to NEVER enter your seed phrase into a computer or a website, no matter how urgent or convincing it looks.

If you are a hardware wallet user, make sure you purchase the wallet from official sources. And the ONLY electronic place you can enter your seed phrases is on the hardware wallet itself.

If a process requires you to enter your seed phrase anywhere on a computer itself, it is definitely a scam.

Related: Bitcoin Hardware Wallet Hacks | What You Need to Know



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleSummer air travel could be a ‘recipe for frustration’
Next Article Redefining the Hurdle Rate in Modern Investing
admin
  • Website

Related Posts

Redefining the Hurdle Rate in Modern Investing

May 24, 2025

Move to Fully Custodied, Bitcoin-Only Loan Model

May 23, 2025

Adam O’Brien | Bitcoin Well and Bypassing Traditional Banks

May 23, 2025

Sangha Renewables | 20MW Solar Mining Farm in Texas

May 23, 2025
Leave A Reply Cancel Reply

Our Picks

Voluptatem aliquam adipisci dolor eaque

April 24, 2025

Funeral of Pope Francis Coincides with King’s Day Celebrations in the Netherlands and Curaçao

April 24, 2025

Curaçao’s Waste-to-Energy Plant Remains Unfeasible Due to High Costs

April 23, 2025

Dutch Ministers: No Immediate Threat from Venezuela to ABC Islands

April 23, 2025
Don't Miss
Affiliate Network News

The Sunday Times List of Best Places to Work in 2025

By adminMay 23, 20250

We’re incredibly proud to share that Awin has once again secured a spot on The…

Awin Claims Best Affiliate Network or SaaS of the Year at 2025 Performance Marketing Awards

May 15, 2025

Global ThinkTank 2025: Who, What, Where

May 9, 2025

Introducing Awin’s 2024 Power 100

April 25, 2025
About Us
About Us

Welcome to MetaDaily.io — Your Daily Pulse on the Digital Frontier.

At MetaDaily.io, we bring you the latest, most relevant, and most exciting news from the world of affiliate networks, cryptocurrency, Bitcoin, egaming, and global markets. Whether you’re an investor, gamer, tech enthusiast, or digital entrepreneur, we provide the insights you need to stay ahead of the curve in this fast-moving digital era.

Our Picks

Wyoming Gaming Commission Issues Warning on Illegal iGaming

May 23, 2025

Playtech Eyes Growth After Snaitech Sale, B2B Shift

May 22, 2025

España lanza programa de subvenciones de 1,05M€ para investigar daños del juego

May 21, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • DMCA
© 2025 metadaily. Designed by metadaily.

Type above and press Enter to search. Press Esc to cancel.