Cryptocurrency software is a high-value target for impersonation because a single successful installation can be worth a great deal, and because the people looking for it are often in a hurry. The result is an ecosystem of look-alike domains, paid advertisement placements and "download portals" that exist to hand you a file the developer never published.
None of that is defeated by being careful in a vague sense. It is defeated by four checks that take about two minutes in total.
The four checks, in order of usefulness
| Check | What it proves | How to do it |
|---|---|---|
| Checksum match | The file on your disk is byte-for-byte the file the developer published | Compute a SHA-512 hash of the download and compare it with the developer's signature page |
| Publisher / signing identity | Who built the file you are about to run | Windows: publisher name in the permission prompt and file properties. macOS: codesign output compared with the published Developer ID |
| Domain | Which company is serving the page | Read the address bar right to left, character by character; type the domain yourself rather than clicking |
| Package name and version | Whether the file is the current release or an old, repackaged build | Compare the file name, size, version and date with the current release on the developer's signatures page |
Verify a download on Windows
Open PowerShell
Press the Start button, type PowerShell, and open it. You do not need administrator rights for this check.
Compute the SHA-512 hash of the downloaded file
Right-click the downloaded file, choose Properties, and copy its full path from the Location field. Then run the hash command shown immediately after this list, substituting that path.
Compare the hash with the published value
Open the developer's official download-signatures page, use the browser's find function (Ctrl + F), and search for the hash you just produced. A match is a hit; SHA-512 hashes are not case-sensitive, so case differences are irrelevant.
Check the publisher in the file's properties
Right-click the file, open Properties → Digital Signatures, and read the signer name. Compare it with the publisher the developer documents for its builds. An unsigned file, or one signed by an unrelated company, should be deleted rather than run.
Check the version and date
On the Details tab of the same properties window, compare Product version and the file date with the current release listed on the signatures page. A version that is years old, or a date that predates the release, means you are holding something redistributed rather than published.
Only then run the installer
If the hash, the publisher and the version all agree, you are holding the published file, and any reputation warning Windows shows is an artefact of a new release rather than evidence of tampering. If any of the three disagrees, delete the file and start again from the official source.
Get-FileHash "$HOME\Downloads\your-downloaded-installer.exe" -Algorithm SHA512 | Format-ListVerify a download on macOS
Open Terminal
Press Command + Space, type Terminal, and press Enter.
Compute the SHA-512 checksum
Type the first command shown after this list, then drag the downloaded file from Finder into the Terminal window so the path is inserted for you, and press Enter.
Compare with the published checksum
Open the developer's official download-signatures page and compare the value there with the one in Terminal. Any difference at all — including a single character — means the file is not the published file.
Verify the signing identity after installation
Ledger's official documentation states that the only official Ledger Wallet Developer ID for macOS is X6LFS5BQKN, that this identifier has been consistent for years, and that an application signed with any other identifier is not genuine. Read the identity macOS sees with the second command below, looking for TeamIdentifier or Developer ID Application, and confirm the current official value on the developer's documentation page before relying on it.
Verify the published checksum file itself, if you want maximum assurance
The developer's signatures page also publishes a .sha512sum file together with a signature file and a public key, so the checksum list itself can be verified cryptographically with the third command below. A successful result reads Verified: OK; anything else means you should stop and contact the developer's official support channel.
shasum -a 512 ~/Downloads/your-downloaded-package.dmgcodesign -dv --verbose=4 /Applications/YourApplication.appopenssl dgst -sha256 -verify ledgerlive.pem -signature ledger-live-desktop-x.xx.x.sha512sum.sig ledger-live-desktop-x.xx.x.sha512sumHTTPS proves that the page you are reading arrived unmodified from the server that served it. It says nothing about whether that server belongs to the developer. A well-built phishing domain has a valid certificate too. The checksum is the check that connects the file on your disk to the developer's published release.
Signs that a download page is not the developer's
- The address is a near-miss: a different top-level domain, an extra word, a hyphen, or a character swapped for a similar-looking one.
- The page opens from an advertisement, a search-engine promotion, a video description or a reply in a forum thread.
- You were redirected there from somewhere you did not intend to go, or through an intermediate "portal" page.
- The page offers a "downloader", "installer helper", "accelerator" or "driver" as a first step.
- The download is a compressed archive or an executable inside an archive, when the developer publishes a signed installer.
- The site invites you to "verify your wallet", "sync your accounts" or "restore your phrase" as part of the download.
- The page displays countdown timers, fake reviews or security badges that are not linked to anything.
- The file is offered as a "cracked", "unlocked", "pro" or "mod" version of paid software.
- Comments or a support chat exist but every reply is generic praise posted within minutes of each other.
Using third-party software download platforms
Third-party software repositories exist for every category of software, and some are genuinely useful. The question that matters is not whether such a platform is well known, but whether the developer itself distributes through it.
- A listing on a third-party platform does not mean the developer endorses, authorises or even knows about that distribution.
- Some platforms repackage installers to add their own downloader or to strip bundled components. A repackaged installer will not match the developer's published checksum, even when nothing malicious was added.
- Some platforms carry outdated versions for years. An old wallet application can be missing security fixes, and it is exactly the kind of file that a phishing page also offers.
- The only reliable comparison is against the developer's own current distribution information: the domain, the package name, the version and the published checksum.
For maximum safety, use the developer's own distribution channel. If you choose to use a third-party platform anyway, download the file and then run the checksum check before installing. If it does not match the published value, the platform has modified the file, whatever its reputation.
This site does not host, mirror, repackage or distribute any installer, and it publishes no download buttons. We do not provide modified or "compatible" builds, and we do not link to third-party mirrors as an alternative to the developer's own source. Any page claiming to be an "official" download centre for wallet software while operating from a domain that is not the developer's own is precisely the thing this guide exists to help you avoid.
If you already installed something you now doubt
Disconnect the computer from the internet
If you suspect the software was malicious, stop network access first, so that anything already running cannot report back or receive instructions.
Do not enter or "check" any recovery phrase
The most common follow-up mistake is entering the phrase to see whether it is still valid. Never type a Secret Recovery Phrase anywhere except the device itself: doing so converts a suspicion into a confirmed loss.
Check for signs of compromise
Unfamiliar browser extensions, remote-access tools you did not install, new startup items, unexpected processes, or a modified hosts file. Record what you find before removing anything.
Remove the application through the normal uninstall process
Use the operating system's own removal tools — see the uninstall guide — and then run a full scan with your existing security software.
Assume any phrase typed into that machine is exposed
If a recovery phrase was ever typed into the suspect computer, create a new account on the hardware device following the developer's official guidance, and move holdings there.
Report it through official channels
Use the developer's official support and phishing-reporting pages, reached by typing the domain yourself. Include the domain, the file name and, if you have it, the checksum.
Review your accounts for unauthorised activity
Look for transactions you did not authorise, and for approvals you do not recognise. Act on what you find before adding new funds to the affected accounts.
Verification checklist
Download verification
Related reading
- Security basics — phishing, fake support and recovery-phrase theft
- Windows installation guide — including what to do about SmartScreen prompts
- macOS installation guide — Gatekeeper prompts and signing checks
- Troubleshooting library — when an installation still fails