惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
V
Visual Studio Blog
雷峰网
雷峰网
J
Java Code Geeks
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog RSS Feed
C
Check Point Blog
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
V
V2EX
D
Docker
IT之家
IT之家
博客园 - 聂微东
腾讯CDC
U
Unit 42
Microsoft Security Blog
Microsoft Security Blog
The Cloudflare Blog

GRAHAM CLULEY

US Coast Guard and FBI board oil tanker to investigate cyber attack Smashing Security podcast #485: These researchers got drunk to hack an LG TV Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man 'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Singer loses life savings to fake wallet downloaded from ...
Graham CLULEY · 2026-04-17 · via GRAHAM CLULEY

If you hold cryptocurrency, there's a very simple golden rule that you should always follow. Never hand over your seed phrase.

Garrett Dutton, better known as G. Love - the front man of blues-hip-hop outfit G. Love & Special Sauce - has learnt that lesson the hard way.

In what must have been a painful admission earlier this month, G. Love described how while setting up a new computer, he downloaded what he believed was the legitimate Ledger Live app from Apple's official App Store.

The bogus app tricked the singer into entering his seed phrase - the master key to his cryptocurrency holdings. With that vital information in their hands, the thieves were able to steal 5.9 Bitcoin (approximately US $440,000), which G. Love had been holding for ten years and considered to be his retirement fund.

A seed phrase (also known as a recovery phrase) is the sequence of 12 or 24 words that are generated when you set up a cryptocurrency wallet. Anyone who has the seed phrase has full, irrevocable access to your funds - making it impossible to reverse any fraudulent transfers made into someone else's account without your permission.

The real Ledger Live app will never ask you for your seed phrase. In fact, no legitimate wallet software ever will ask for it. If any app requests your seed phrase, it is a scam.

It won't be much consolation for G. Love, but he's not the only one to suffer.

Renowned cryptocurrency investigator ZackXBT revealed on Telegram that the same fake Ledger Live app had been linked to the theft of some US $9.5 million from more than 50 victims between April 7-13, with the three victims hardest hit each lost seven-figure sums.

Apple removed the app from its online store on April 12, but not before the damage had been done.

It remains to be seen whether victims will launch a class action against Apple due to their heavy losses, but serious questions must be asked about the thoroughness of the company's App Store vetting due to the fact that the app remained available long enough to defraud dozens of people.

G. Love, who says he is not a naive newcomer to cryptocurrency, has publicly reached out to Apple - but does not appear to have had any response.

If you hold cryptocurrency, here is what you can do to better protect yourself.

  • Never enter your seed phrase into any app, website, or form — for any reason whatsoever.
  • Be especially careful when setting up a new device. That is precisely when you are most likely to search for and reinstall familiar apps, and exactly when scammers are counting on you to drop your guard.
  • Check developer names and ratings carefully. Fake apps often attempt to mimic a real product's branding.

In the past Apple has presented its App Store as a more secure and safer place to find and download apps than other operating systems. G. Love's loss of a ten-year retirement fund serves as a timely lesson that trust in platforms can easily be misplaced.