Fake Crypto Wallets in Apple’s App Store Stole $9.5M—And Apple Knew
Kaspersky found 26 phishing apps posing as crypto wallets in Apple's App Store, exploiting enterprise provisioning profiles to steal seed phrases.
- Twenty-six phishing apps posing as crypto wallets were found in Apple’s App Store in March, with one fake Ledger Live app alone stealing $9.5 million from 50+ victims.
- The malware hijacks seed phrases through malicious library injection and Apple’s own enterprise provisioning profiles — a technique first seen in 2022.
- Musician G. Love lost 5.9 BTC ($430,000) after downloading the counterfeit app, which passed Apple’s review process and appeared in search results for “Ledger Wallet.”
Twenty-six fake cryptocurrency wallet apps were hiding in plain sight inside Apple’s App Store in March 2026, masquerading as Ledger, MetaMask, Coinbase, Trust Wallet, and other popular wallets, according to research from Kaspersky. The finding echoes a broader pattern of iOS security vulnerabilities that have plagued Apple’s closed ecosystem. One of them — a counterfeit Ledger Live app — went on to steal $9.5 million from more than 50 users across Bitcoin, Ethereum, Tron, Solana, and XRP before Apple removed it in early April.
The three largest individual losses tracked between April 8 and 11 were $3.23 million, $2.08 million, and $1.95 million. Musician G. Love said on X he lost 5.9 BTC — roughly $430,000 and, as he put it, “all I had for ten years I worked on this.” He shared the transaction hash to prove it. The stolen funds were laundered through more than 150 KuCoin deposit addresses via a centralized mixing service investigators flagged as “AudiA6.”
Apple removed the app after receiving multiple reports, but the damage had already spread across multiple blockchains. The campaign had been running undetected since fall 2025, with malware metadata pointing to months of silent operation before anyone noticed.
How Fake Crypto Wallet Malware Steals Your Seed Phrase
The attack chain starts with a phishing app in the App Store — one that copies a legitimate wallet’s icon and uses a slightly misspelled name to slip past Apple’s filters. Once installed, the app redirects users to a browser page designed to look like the App Store, where they’re prompted to install a trojanized version of the real wallet. That second installation happens through Apple’s enterprise provisioning profiles — the same system designed for companies to distribute internal apps to employees, now repurposed as a malware delivery mechanism.
The trojanized wallets use malicious library injection (dylib) to hijack the apps from the inside. Kaspersky’s team described the technique as injecting malicious load commands into the wallet’s main executable, then hijacking key view controller methods like viewDidLoad in the recovery phrase screen. When a user opens or restores a wallet, the malware scans UI subviews for mnemonic words, extracts them, encrypts the data, and fires it off to hardcoded command-and-control servers via POST requests. It’s the digital equivalent of someone taping a camera behind your screen while you type in your password. Kaspersky classified the malware under HEUR:Trojan-PSW.IphoneOS.FakeWallet.* detection signatures.
The Trust Wallet variant uses a slightly different approach — a custom __hook executable section injected before the __text section in the program header, which trampolines to dlsym and a mnemonic validation method to hijack both wallet restore and creation flows. The Ledger variant, meanwhile, takes a more old-school route: since Ledger keys stay on an offline device, the malware simply presents a fake UI to capture the seed phrase when users manually enter it. Some of the 26 apps Kaspersky found had no phishing features active yet but showed signs of being linked to the same threat actors — malicious features likely waiting to flip on in a future update.
How Fake Crypto Wallets Slipped Past Apple’s App Store Review
This isn’t new ground. ESET found a similar campaign in 2022 using the same enterprise provisioning profile trick to steal recovery phrases from MetaMask, Coinbase, Trust Wallet, TokenPocket, Bitpie, imToken, and OneKey. And in 2023, a fake Ledger Live app on Microsoft Store stole $768,000. The playbook hasn’t changed much — Apple’s review process just hadn’t caught up.
Several factors compound the problem. The campaign specifically targets the Chinese App Store, where official crypto wallet apps are restricted, creating a vacuum that scammers fill with fakes. Meanwhile, Ledger distributes its Mac app on its own website but only offers the iOS version through the App Store — creating a single point of trust that attackers exploit. Despite reports surfacing almost immediately after the fake Ledger app was published, Apple didn’t take prompt action, and the $9.5 million figure comes from blockchain analysis by investigators, not from any official Apple or Ledger disclosure.
Apple’s enterprise provisioning profiles remain a favorite tool for malware distributors, online casinos, and pirated app mods — a systemic vulnerability the company has known about for years. Kaspersky classified the malware under HEUR:Trojan-PSW.IphoneOS.FakeWallet.* and HEUR:Trojan.IphoneOS.FakeWallet.*, but the real detection failure happened at Apple’s front door, where a fake app named close enough to “Ledger Live” passed review and appeared in search results for anyone looking for their wallet.