Nearly $600,000 worth of Bitcoin (BTC) was stolen after many individuals downloaded a fraudulent Ledger Live application via the Microsoft App Store, as discovered by cryptocurrency investigator ZachXBT. In a subsequent update, ZachXBT mentioned that while Microsoft had successfully removed the app, the damage had been done.
What went down
The fake app, named Ledger Live Web3, was successfully identified on November 5th, however it was too late as countless users had already used the application since they believed they were obtaining Ledger Live, an authentic graphical interface for Ledger hardware wallets for offline cryptocurrency storage.
The scammer received the aforementioned sum through 38 transactions via the wallet address bc1qg05gw43elzqxqnll8vs8x47ukkhudwyncxy64q, according to Blockchain.com. Approximately $115,200 has been withdrawn through the wallet of the scammer through two transactions, leaving them with $473,800 or 13.5 BTC.
The first payment directed to the wallet address was made on October 24th, totaling $5,210. Prior to this, the wallet remained inactive. The majority of these transactions also occurred after November 2nd, with the largest transfer amounting to $81,200 on November 4th.
Another day, another scam
Alarmingly, it was revealed that the deceptive application had already appeared on the store as early as October 19th, at which point Microsoft users could download and use it. ZachXBT stated that they received two messages by victims on November 4th and argued that Microsoft should be held accountable for not conducting due diligence and allowing the fake application to be featured in its app store to begin with.
To make matters worse, this is not the first instance of a bogus Ledger Live application infiltrating Microsoft. In fact, Ledger has a support account on X (formerly Twitter) which alerted its users about a fake app bearing the Ledger name on no less than two separate occasions in both December 2022 and March 2023. As of this time, Ledger has not commented on the scam specifically but has consistently advised users that the only secure source for downloading Ledger Live is their website, ledger.com.