This page explains how to install the Ledger Wallet desktop application on a Mac — Intel or Apple Silicon — and how to read the security prompts macOS shows when you open an application it has not seen before. It is written on the assumption that you would rather verify a file than switch a protection off, because that is the only approach that actually protects a wallet.
No step on this page asks for a recovery phrase, a PIN or a private key. Nothing on this site ever will.

Before you begin: four quick checks
The product shipped for years as Ledger Live and is now called Ledger Wallet; Ledger's support documentation records the rename reaching the desktop and mobile apps by 3 November 2025. Tutorials written before that date use the old name and still describe the same application. What matters is that you install the current package rather than an old build redistributed by a third party.
1. Check your macOS version
The developer's official system-requirements article states that the desktop application requires macOS 12.0 (Monterey) or later, including Ventura and Sonoma, and it recommends staying on a macOS release that Apple still supports with security updates.
To check: open the Apple menu → About This Mac. The window shows the macOS name and version, the chip or processor, and the amount of memory. Write the version number down.
2. Determine whether your Mac is Intel or Apple Silicon
In the same About This Mac window, the Chip line names an Apple chip (M1, M2, M3 and later families) or the Processor line names an Intel processor. Apple Silicon Macs run the desktop application natively; Intel Macs use the same download. There is no separate "Intel build" to hunt for, and no need to install a compatibility layer for a modern release.
3. Check free space
Open System Settings → General → Storage. The developer does not publish a fixed disk figure for the desktop application, so no honest guide can quote one — what matters is that macOS has room for the download, the installed application and its local data. A Mac with less than a few gigabytes free behaves unpredictably during installations, so clear space first.
4. Decide the download source before you open a browser
Use the developer's own website, typed by hand. Not an advertisement, not a "download portal", not a link from a video description, a forum reply or a message. macOS protects you from a damaged application but it cannot protect you from a correctly signed application that someone else built — and that is precisely what a convincing fake download is.
A fake download page can look perfect and still hand you a package that Gatekeeper accepts because it is properly signed by somebody. Signature checks prove who built the file, not that the file is the software you intended to install. Verifying the published checksum is the step that closes the gap.
How to install Ledger Wallet on macOS
The sequence below follows the vendor's published instructions and adds the verification detail a vendor page reasonably omits.
Confirm the macOS version
Compare the version from About This Mac with the official minimum — macOS 12.0 or later. If your Mac is older than that, do not install an unofficial older build from a third-party archive; the supported alternative is the mobile application, or a newer macOS release if your Mac supports it.
Install pending macOS updates
Open System Settings → General → Software Update. Installing pending updates first means the security features that will evaluate the installer — including Gatekeeper and XProtect — are current, and it removes a common cause of installation failures.
Confirm free storage
Check System Settings → General → Storage and clear space if the drive is nearly full. Empty the Downloads folder of unrelated large files; the installer needs room to unpack as well as to install.
Open the developer's own website
Type the domain yourself in the address bar. Check the address character by character, confirm the padlock, and confirm that the certificate belongs to the developer. If anything redirects you to a different domain, or offers you an "accelerated mirror", close the tab and start again.
Download the macOS package
Choose the macOS build on the developer's download page. Safari saves the file to your Downloads folder; depending on your browser settings it may open automatically. A downloaded disk image or package is not an application yet — it is a container that you will install from.
Verify the file before installing it
Open Terminal and compute the SHA-512 checksum of the downloaded file, then compare it with the value published on the developer's official download-signatures page. This is the single most useful step on this page.
:::cmd macOS Terminal — SHA-512 checksum shasum -a 512 ~/Downloads/your-downloaded-package.dmg
If the value does not match the published one, do not open the file: delete it, empty the Trash, and download again from the official source.
@@ Open the disk image or package
Double-click the downloaded file. If macOS mounts a disk image, a window opens showing the application and an alias for the Applications folder. Read the mounted volume's name and the publisher information in the window before dragging anything.
@@ Install the application
Drag the application icon into the Applications folder, then eject the disk image by dragging its volume to the Trash or pressing the eject button in Finder. If the package is a .pkg installer instead, run it and follow the wizard, reading the publisher name it displays.
@@ Launch the application from Applications
Open Applications in Finder (or use Spotlight) and start the application from there rather than from the mounted disk image. Running an application directly from a mounted image is a frequent cause of confusing permission and update errors. The first launch prepares the local data directory.
@@ Read the macOS security prompt carefully
Depending on your macOS version and how the application was distributed, macOS may show a dialog explaining that the application was downloaded from the internet, or that it cannot be opened because the developer cannot be verified. The next section explains exactly how to evaluate that dialog without weakening your security settings.
@@ Connect the Ledger hardware wallet
Plug the device into the Mac with the supplied cable — directly into a port on the computer rather than into a hub, dock or display. Unlock the device with its PIN and leave it on its home screen. If the device asks whether to allow the connection, confirm on the device itself.
@@ Complete the application setup
The application detects the device and walks you through the remaining decisions: which accounts to add, whether to send optional diagnostics, and how the portfolio should be displayed. Keep the device connected. Screen wording changes between releases, which is why this guide describes decisions rather than reproducing screenshots.
@@ Install the device applications you need, then check for updates
Install blockchain applications onto the hardware device through the application's device area, keeping in mind that device storage is limited. Finish by checking for updates through the application's own update mechanism — never through a link that arrived by email or message.
:::
macOS prompts and concepts, in plain language
The disk image (DMG) and installation packages
A disk image is a virtual volume: macOS mounts it as if you had inserted a disk, which is why the application appears next to a shortcut to your Applications folder. Copying the application into Applications is what installs it. A .pkg file behaves differently — it runs an installer with its own wizard. Both formats can be verified the same way, by checksum.
Gatekeeper
Gatekeeper is the part of macOS that decides whether an application may launch, based on where it came from and whether it carries a valid signature. It is a gate, not a virus scanner, and it is designed to be informed rather than circumvented. When Gatekeeper objects to an application, the useful response is to verify what you are holding, not to remove the objection.
"Unidentified developer" and "cannot be verified"
This message means macOS could not confirm the developer's identity for the file. It appears for genuinely unsigned software, and it also appears in some configurations for software distributed outside the App Store. Two legitimate responses exist:
- Verify the checksum against the developer's published signatures page. If it matches, you are holding the published file, and the prompt is a distribution artefact rather than evidence of tampering.
- Verify the signing identity for the installed application, as described in the next section, and compare it with the developer's published Developer ID.
What you should not do is disable Gatekeeper globally, or run terminal commands to strip a quarantine attribute from a file you have not verified. Those habits remove the protection for every future download, not just this one.
Permissions and privacy prompts
macOS asks for permission when an application wants to access removable volumes, the local network, notifications or files in specific folders. Grant only what the application needs to function, and read each prompt rather than approving by reflex. A wallet application does not need your contacts, your photos or your calendar.
USB connectivity
Desktop hardware wallets connect over USB. The common causes of "device not detected" on macOS are the cable itself, an unpowered hub or dock, a monitor's USB port, and a device that has gone to sleep. Try a direct port, unlock the device, and re-seat the cable before assuming a software problem.
Intel and Apple Silicon
Both architectures are supported by the current release. Apple Silicon Macs run the application natively; if you ever see a prompt offering to install a compatibility layer for an application, that is a strong signal you are running an old or unofficial build, because a current release does not require one.
If macOS shows a security warning: verify, do not bypass
Work through these steps in order. They take two minutes and they answer the only question that matters: is this the file the developer published?
- Confirm the source. Look at the address bar, not the page design. If the file did not come from the developer's own domain, stop and re-download.
- Compare the checksum. Run the
shasum -a 512command shown above and compare the output with the developer's published signature page. Ignore case; hexadecimal comparison is not case-sensitive. - Confirm the signature of the installed application. The developer's documentation publishes a single official Developer ID for macOS. You can read the identity that macOS sees:
codesign -dv --verbose=4 /Applications/YourApplication.appLook for TeamIdentifier or Developer ID Application in the output. Ledger's official documentation states that the only official Ledger Wallet Developer ID for macOS is X6LFS5BQKN, that this identifier has been stable for years, and that an application signed with any other identifier is not genuine. Verify the current value in the official documentation before relying on it.
4. Re-download if anything disagrees. A mismatch is not something to work around. Delete the file, empty the Trash, and start from the official page again.
5. Only then decide about the prompt itself. If the checksum and the signing identity both match, the file is the published file; you can acknowledge the prompt through the dialog's own options. Keep Gatekeeper enabled either way.
Do not disable Gatekeeper, do not turn off "Allow applications from" restrictions, and do not run commands to strip quarantine attributes from an unverified download. If a guide's solution to a security prompt is to remove the security, the guide is optimising for convenience rather than for the safety of your assets.
Once you have verified a file, keep the checksum and the download date in a note. When a future release arrives, compare the new file's checksum with the developer's signature page before installing. Verification becomes a ten-second habit rather than a research project.
Setups that are not supported
| Setup | Status | Practical consequence |
|---|---|---|
| Virtual machines (Parallels, VMware Fusion, UTM, VirtualBox) | Not supported | The application is documented as unsupported on virtual machines. USB pass-through is unreliable and device detection frequently fails. |
| iPad and tablet models | Not supported | Even where a build starts, these devices are outside the supported set. |
| macOS older than 12.0 | Not supported | Use the mobile application, or update macOS if your Mac supports it. Do not install unofficial older builds from third-party archives. |
| Hardware wallets connected through unpowered hubs | Works inconsistently | Connect directly to the Mac where possible. |
After installation: verify the shape of a healthy install
macOS installation checklist
If something goes wrong
| Symptom | Where to look |
|---|---|
| macOS refuses to open the application | The application cannot be opened |
| An "unidentified developer" message appears | Unidentified developer warning |
| macOS says the application is damaged | The application is described as damaged |
| The device is not detected after connecting | The hardware wallet is not detected on macOS |
| The download appears incomplete | The DMG file appears corrupted |
| A permissions prompt blocks the application | A permissions problem blocks the application |
For the same process on Windows, read the Windows installation guide. For the checksum and publisher checks in more depth, see recognising fake downloads.