Hackers using fake Ledger Live app to steal seed phrases and drain crypto
Cybercriminals are using fake Ledger Live apps to drain macOS users’ crypto through malware that steals seed phrases, a cybersecurity firm warns. The malware replaces the legitimate Ledger Live app on victims’ devices an...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Cybercriminals are using fake Ledger Live apps to drain macOS users’ crypto through malware that steals seed phrases, a cybersecurity firm warns.
The malware replaces the legitimate Ledger Live app on victims’ devices and then prompts the user to input their seed phrase through a phony pop-up message, a team from Moonlock said in a May 22 report.
“Initially, attackers could use the clone to steal passwords, notes, and wallet details to get a glimpse of the wallet’s assets, but they had no way to extract the funds,” the Moonlock team said.
“Now, within a year, they have learned to steal seed phrases and empty the wallets of their victims,” it added.
One way the scammers replace the real Ledger Live app with a clone is through the Atomic macOS Stealer, designed to steal sensitive data, which Moonlock said it has found lurking on at least 2,800 hacked websites.
Source: MoonlockAfter infecting a device, Atomic macOS steals personal data, passwords, notes and wallet details and replaces the real Ledger Live app with a phony.
“The fake app then displays a convincing alert about suspicious activity, prompting the user to enter their seed phrase,” the Moonlock team said.
“Once entered, the seed phrase is sent to an attacker-controlled server, exposing the user’s assets in seconds.”
Malware campaign active since AugustMoonlock has been tracking malware that's distributing a malicious clone of Ledger Live since August, with at least four active campaigns, and they think hackers are “only getting smarter.”
Threat actors on the dark web are offering malware with “anti-Ledger” features. However, one of the examples examined by Moonlock did not feature the full anti-Ledger phishing functionality advertised. The firm speculates those features could “still be in development or is forthcoming in future updates.”
Moonlock says hackers are offering malware for would-be thieves to steal from Ledger users. Source: Moonlock“This isn’t just a theft. It’s a high-stakes effort to outsmart one of the most trusted tools in the crypto world. And the thieves are not backing down,” Moonlock said.
“On dark web forums, chatter around anti-Ledger schemes is growing. The next wave is already taking shape. Hackers will continue to exploit the trust crypto owners place in Ledger Live.”
Related: Ledger secures Discord after hacker bot tried to steal seed phrases
To avoid falling prey to similar malware scams, the cybersecurity firm recommends being wary of any page that warns of a critical error and asks for a 24-word recovery phrase.
At the same time, never share a seed phrase with anyone or input it on any website, no matter how legitimate it looks, and only download Ledger Live from its official source.
Ledger didn’t immediately respond to Cointelegraph’s request for comment.
Magazine: ChatGPT a ‘schizophrenia-seeking missile,’ AI scientists prep for 50% deaths
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CointelegraphRelated market context
AI may be keeping Bitcoin’s biggest macro headwind alive after the Fed stops hiking
Bitcoin faces a new macro headwind from the artificial-intelligence boom as massive infrastructure spending competes for long-term...
Bitcoin holder loses 80 BTC worth $5.2 million after moving funds to reseller-bought Ledger
The incident underscores the critical importance of purchasing hardware wallets from official sources to ensure asset security. Th...
Tether freezes USDT linked to Ledger user thefts near $90 million
The freeze highlights the need for robust supply chain security and raises concerns about the limitations of centralized control i...
Ledger Probes Potential Theft of $87M in User Funds Tied to Crypto Wallet Reseller
Ledger asked reseller CryptoBilis to pause sales and urged recent buyers not to set up their devices, as an onchain investigator t...
Tether Freezes USDT Linked to Ledger User Thefts, MistTrack Says
MistTrack puts reported losses near $90 million as Ledger asks reseller CryptoBilis to halt device sales and shipments.... Read th...
Ledger investigates potential wallet tampering after reports of $86 million in crypto stolen
The hardware wallet maker said it is investigating devices sold by a Southeast Asian reseller as social posts swirl about crypto a...