Three things happened in the last two weeks that matter if you keep cryptocurrency on or near a Mac. Apple patched a CoreGraphics flaw it says may have been exploited against targeted individuals. Kaspersky published a new version of the MacSync stealer that can swap your Ledger app for a fake one. And the same family of malware goes looking for files with names like seed and wallet.
None of that means your coins are in danger today. It means this is a good week to spend fifteen minutes on three checks, in this order.
Step 1: Install the right macOS update
Choose Apple menu > About This Mac to see your version, then install the matching update from System Settings > General > Software Update:
| You run | Install |
|---|---|
| macOS 27 Golden Gate | 27.0.1 |
| macOS 26 Tahoe | 26.7.1, which fixes the CoreGraphics flaw |
| macOS 15 Sequoia | 15.8.1, which fixes the same flaw |
If you’re staying on Tahoe or Sequoia, install the update from Other updates, not the Upgrade Now button, which installs Golden Gate. Our security PSA has the details. The CoreGraphics flaw is triggered by processing a malicious file, which is exactly the kind of thing that arrives as a “whitepaper”, an “airdrop PDF” or an image in a crypto group chat.
Macs on Sonoma or older don’t get this fix. If you hold meaningful amounts, don’t manage them from a Mac that no longer receives security updates.
Step 2: Verify your Ledger and Trezor apps are genuine
A hardware wallet keeps your keys on the device, but the companion app on your Mac is what you look at and click. MacSync and earlier stealers have replaced Ledger’s and Trezor’s apps with modified copies that look the same and then ask for your recovery phrase.
A genuine app is signed by its developer and notarized by Apple. A swapped copy usually carries an ad-hoc signature that names no developer. Check in Terminal; use whichever app name you have installed:
codesign -dvv "/Applications/Ledger Wallet.app" 2>&1 | grep -E "Authority|TeamIdentifier|Signature"
spctl -a -vv "/Applications/Ledger Wallet.app"
- Genuine: the first command shows
Authority=Developer ID Application:followed by the developer’s name, and aTeamIdentifier. The second showsacceptedandsource=Notarized Developer ID. - Suspicious:
Signature=adhoc,TeamIdentifier=not set, orrejected.
Repeat with "/Applications/Ledger Live.app" if you have the older app, and "/Applications/Trezor Suite.app". If anything looks wrong, don’t open the app. Read our MacSync guide first.
And one rule that beats every command: no genuine wallet app ever asks you to type your recovery phrase into the computer. Not to “sync”, “verify”, “repair” or “restore access”. If a window asks, it’s theft.
Step 3: Get seed and wallet files out of iCloud Desktop
If Desktop & Documents Folders is turned on in iCloud Drive, everything on your Desktop and in Documents is copied to iCloud and to every Mac signed in to your Apple Account. A screenshot of your seed phrase on the Desktop is then on several machines and in the cloud, and any one of them can be infected.
Stealers don’t guess, either. Recent campaigns search the disk for file names containing words like seed, wallet, mnemonic and keys. Find yours first:
mdfind -onlyin ~ 'kMDItemFSName == "*seed*"c || kMDItemFSName == "*wallet*"c || kMDItemFSName == "*mnemonic*"c'
For each result:
- A recovery phrase in any digital form, including a note, text file, screenshot or photo, should not exist. Copy it onto paper or metal, confirm it’s correct, then delete the file and empty the Trash. If it was ever synced to iCloud or another device, treat that phrase as exposed: set up a new wallet and move the funds.
- Wallet files, such as an Electrum wallet or a Bitcoin Core
wallet.dat, should live in the app’s own folder, protected with a strong password, and never on the Desktop or in Documents while iCloud syncs them.
If you use iCloud for everything else, turn on Advanced Data Protection in System Settings > [your name] > iCloud, so your iCloud data is end-to-end encrypted. It helps with iCloud, but it doesn’t help if malware on one of your Macs reads the files directly.
While you’re here
- Don’t install “wallets” you found through an ad, a DM or a new X account. MacSync spread as a fake wallet app called Toria, promoted with its own website and social accounts.
- Never paste Terminal commands from a website that says it will “fix” or “install” something.
- If an app you just opened asks for your Mac password and then says it’s damaged and should be moved to the Trash, disconnect from the internet. That sequence matches MacSync’s behaviour.
The short version
Install 27.0.1, 26.7.1 or 15.8.1 depending on your macOS. Check that your Ledger or Trezor app is signed by its developer and notarized, not ad-hoc signed. Find any files named seed, wallet or mnemonic, and get recovery phrases off your Mac and out of iCloud entirely.