Fake Ledger Apps on Mac: How Seed Phrase Theft Works and How to Protect Your Wallet
Hackers are targeting Mac users with fake Ledger apps designed to steal 24-word seed phrases and access cryptocurrency wallets. Learn how malware like Odyssey and AMOS bypass Apple security and how to stay protected.
Quick answer: Fake Ledger Live apps on macOS show a false error and ask for your 24-word recovery phrase, which gives an attacker full control of your funds. Genuine Ledger software never asks you to type the phrase into a computer. Download only from the official site, never bypass macOS warnings, and move funds to a new wallet at once if you entered it.
Key takeaways
- Genuine Ledger software never asks for your recovery phrase on a computer or phone.
- Download wallet apps only from the official site, not from adverts or links.
- Do not bypass macOS warnings for software you did not expect.
- If you typed the phrase, move funds to a new wallet immediately.
What was reported
Security researchers have reported campaigns that target people who hold crypto on a Ledger hardware wallet and use macOS. The attackers distribute a fake version of the Ledger Live app, usually through a download page or disk image (DMG) that looks genuine. When opened, the app shows an alarming message, such as an error or a need to "restore" the wallet, and asks for the 24-word recovery phrase. Anyone who types it in gives the attacker full control of the funds.
Names such as Odyssey and Atomic macOS Stealer (AMOS) were attached to this activity in reports from the security team at Moonlock Lab. The specific malware names, dates and the reported actor handles come from that research and from news coverage that followed. They have not been independently verified for this article, so confirm them in the primary reports before you quote them.
Why the seed phrase is the target
A hardware wallet keeps private keys on the device. The recovery phrase can rebuild those keys on any device. Whoever has the phrase owns the funds, and blockchain transactions cannot be reversed. That is why genuine Ledger software never asks you to type the phrase into a computer or phone app, and why any prompt that does is a scam.
How the trick usually works
- You find a fake download through a search advert, a social post or a messaging link.
- You install the fake app, sometimes after being told to bypass macOS warnings.
- The app, or a stealer running behind it, may collect browser data and passwords.
- A fake error screen pushes you to enter the recovery phrase.
- The attacker moves your funds, often within minutes.
How to protect yourself
- Never enter your recovery phrase on a computer or phone. It is only used to restore a wallet on a new hardware device.
- Download wallet software only from the vendor's official site, typed in or from a bookmark, not from adverts. The official site is ledger.com.
- Do not bypass macOS security warnings for software you did not expect. Apple explains how Gatekeeper treats unidentified developers.
- Keep macOS and your browser updated and use endpoint protection.
- Store the recovery phrase offline, never as a photo or in cloud notes.
- Use a separate device or profile for large holdings, and consider a passphrase feature that your wallet supports.
If you entered your recovery phrase
- Assume it is compromised. Do not wait.
- From a clean device, create a new wallet with a fresh recovery phrase and move any remaining funds immediately.
- Remove the fake app, scan the Mac with trusted tools and change passwords from a clean device.
- Report the fraud to the national cybercrime portal and to your exchange if funds moved there.
Related reading: Celestial Stealer, crypto-stealing Firefox extensions and Google Forms crypto scams.
Next steps
To learn how stealers are analysed and blocked, see the Cyber Security course.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0