Two of Proton’s desktop apps briefly stopped opening on Macs this week, and the operating system told some users they were malicious. The warnings were false, and the cause sat with a trust decision made far from the software itself.
Proton said Apple revoked one of its developer accounts on Friday, October 2, without explaining why. The change rippled through macOS: builds that had opened normally for years were suddenly treated as untrusted, and in some cases the system branded them malware. Proton Mail for Mac and Proton Meet for Mac were both caught up in it.
The trigger is the certificate chain Apple uses to vouch for software. Pull a developer account and every app signed with it loses that stamp, so macOS falls back to treating the program as suspicious. Nothing inside the apps had changed; the trust behind them had.
Proton told users their accounts and data were untouched and stressed the malware alert was a false positive, not an infection. While it worked with Apple on a remedy, it shipped fresh builds and pointed people at its web apps. The company closed the incident the same evening, once the desktop apps were updated, and told anyone still seeing a prompt to install the newest version.
The episode shows how much of a Mac’s safety model rests on credentials Apple controls, and how quickly a routine account action can turn trusted software into something the system warns about.