Replace April 15, 2026, 6:43 am UTC: This text has been up to date to add feedback from a KuCoin spokesperson.
Onchain investigator ZachXBT mentioned a faux Ledger Reside app listed on Apple’s App Store was tied to about $9.5 million in crypto stolen from greater than 50 suspected victims between April 7 and 13.
In a Tuesday Telegram post, ZachXBT mentioned the alleged thefts affected customers throughout Bitcoin, Solana, Tron, XRP Ledger and Ethereum Digital Machine (EVM)-compatible networks. He claimed the stolen funds had been laundered by means of over 150 KuCoin deposit addresses allegedly tied to AudiA6, which he described as a centralized mixing service.
ZachXBT mentioned the faux app was eliminated by Apple on April 13 and recognized three seven-figure losses among the many largest recognized instances. He mentioned one sufferer misplaced about $1.95 million in Bitcoin (BTC), staked Ether (stETH) and Ether (ETH), one other misplaced $3.23 million in USDt (USDT) on April 9, and a 3rd sufferer misplaced about $2 million in USDC (USDC) on April 11.
ZachXBT said Kucoin had seen a rise in illicit exercise just lately, and identified that the corporate had been banned from onboarding new European Union users in February, shortly after receiving its Markets in Crypto Belongings Regulation (MiCA) license. He additionally questioned whether or not the incident introduced grounds for a category motion in opposition to Apple.
Associated: Counterhacker exposes DPRK unit that made $1M a month working IT jobs
In response, KuCoin mentioned it displays for suspicious exercise in keeping with regulatory expectations and disputed claims it had “allowed” illicit flows. A spokesperson advised Cointelegraph the matter is beneath assessment however declined to remark additional due to safety and privateness concerns.
Key particulars, together with the whole losses, sufferer depend and laundering route, stay based mostly on ZachXBT’s findings and had not been confirmed by Apple or KuCoin at publication.
Ledger warns customers by no means to enter seed phrase into apps
Ledger chief expertise officer Charles Guillemet mentioned in a press release to Cointelegraph that the corporate by no means asks customers for his or her 24-word restoration phrase and warned that official-looking software environments shouldn’t be handled as inherently protected.

Fake Ledge Reside app within the App Store. Supply: Archive.ph
“You can’t belief the software program atmosphere round you – not your browser, not your app retailer, not your desktop,” Guillemet mentioned, including that attackers “function wherever the chance exists,” together with official distribution platforms.
Associated: Web3 hacks cost $482M in Q1 as phishing drives majority of losses: Hacken
The most recent incident follows a smaller however comparable case reported on Monday. Musician Garrett Dutton, often known as “G. Love,” mentioned he lost about $420,000 in BTC after downloading a malicious app impersonating Ledger Reside from Apple’s App Store and getting into his seed phrase. ZachXBT mentioned the stolen belongings had been despatched to deposit addresses related to KuCoin.
Journal: How AI just dramatically sped up the quantum risk for Bitcoin
Ezra Reguerra Fake Ledger App on Apple Store Linked to $9.5M Theft cointelegraph.com 2026-04-14 15:22:57
Source link












