Fake Ledger Apps on Mac: How Seed Phrase Theft Works and How to Protect Your Wallet

Hackers are targeting Mac users with fake Ledger apps designed to steal 24-word seed phrases and access cryptocurrency wallets. Learn how malware like Odyssey and AMOS bypass Apple security and how to stay protected.

May 26, 2025 - 13:48
Updated: 8 days ago
106k
Fake Ledger Apps on Mac: How Seed Phrase Theft Works and How to Protect Your Wallet

Quick answer: Fake Ledger Live apps on macOS show a false error and ask for your 24-word recovery phrase, which gives an attacker full control of your funds. Genuine Ledger software never asks you to type the phrase into a computer. Download only from the official site, never bypass macOS warnings, and move funds to a new wallet at once if you entered it.

Key takeaways

  • Genuine Ledger software never asks for your recovery phrase on a computer or phone.
  • Download wallet apps only from the official site, not from adverts or links.
  • Do not bypass macOS warnings for software you did not expect.
  • If you typed the phrase, move funds to a new wallet immediately.

What was reported

Security researchers have reported campaigns that target people who hold crypto on a Ledger hardware wallet and use macOS. The attackers distribute a fake version of the Ledger Live app, usually through a download page or disk image (DMG) that looks genuine. When opened, the app shows an alarming message, such as an error or a need to "restore" the wallet, and asks for the 24-word recovery phrase. Anyone who types it in gives the attacker full control of the funds.

Names such as Odyssey and Atomic macOS Stealer (AMOS) were attached to this activity in reports from the security team at Moonlock Lab. The specific malware names, dates and the reported actor handles come from that research and from news coverage that followed. They have not been independently verified for this article, so confirm them in the primary reports before you quote them.

Why the seed phrase is the target

A hardware wallet keeps private keys on the device. The recovery phrase can rebuild those keys on any device. Whoever has the phrase owns the funds, and blockchain transactions cannot be reversed. That is why genuine Ledger software never asks you to type the phrase into a computer or phone app, and why any prompt that does is a scam.

How the trick usually works

  1. You find a fake download through a search advert, a social post or a messaging link.
  2. You install the fake app, sometimes after being told to bypass macOS warnings.
  3. The app, or a stealer running behind it, may collect browser data and passwords.
  4. A fake error screen pushes you to enter the recovery phrase.
  5. The attacker moves your funds, often within minutes.

How to protect yourself

  • Never enter your recovery phrase on a computer or phone. It is only used to restore a wallet on a new hardware device.
  • Download wallet software only from the vendor's official site, typed in or from a bookmark, not from adverts. The official site is ledger.com.
  • Do not bypass macOS security warnings for software you did not expect. Apple explains how Gatekeeper treats unidentified developers.
  • Keep macOS and your browser updated and use endpoint protection.
  • Store the recovery phrase offline, never as a photo or in cloud notes.
  • Use a separate device or profile for large holdings, and consider a passphrase feature that your wallet supports.

If you entered your recovery phrase

  1. Assume it is compromised. Do not wait.
  2. From a clean device, create a new wallet with a fresh recovery phrase and move any remaining funds immediately.
  3. Remove the fake app, scan the Mac with trusted tools and change passwords from a clean device.
  4. Report the fraud to the national cybercrime portal and to your exchange if funds moved there.

Related reading: Celestial Stealer, crypto-stealing Firefox extensions and Google Forms crypto scams.

Next steps

To learn how stealers are analysed and blocked, see the Cyber Security course.

Frequently Asked Questions

Attackers distribute a fake Ledger Live app for macOS that shows a false error and asks for your 24-word recovery phrase. If you enter it, they can rebuild your wallet and move funds. Genuine software never asks for it.

It is the 12 or 24 words that can recreate your wallet's private keys on any device. Whoever has it controls the funds, and blockchain transactions are irreversible, so it must stay offline and private.

No. The phrase is entered only on a hardware wallet device when restoring. Any computer or phone app, pop-up or support chat asking for it is a scam, however professional it looks.

Treat it as compromised. From a clean device create a new wallet with a fresh phrase, move remaining funds at once, remove the fake app, change passwords and report the fraud to the cybercrime portal.

Go directly to the vendor's official website by typing the address or using a bookmark, not from search adverts or social links. Do not bypass macOS security warnings for software you did not expect.

No. macOS has built-in protections such as Gatekeeper, but stealers and fake apps do target Mac users, mainly through social engineering. Keep the system updated, use endpoint protection and be sceptical of downloads.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.