SlowMist has yet to confirm crypto theft from iPhone Safari attack
The analyzed Safari sample targets iOS 18.4–18.6.2 using previously patched flaws, while its effectiveness on iOS 26.5 remains unverified.
SlowMist disclosed a Safari attack targeting iOS 18.4 to 18.6.2, though its effectiveness on iOS 26.5 remains unconfirmed. The attack, linked to a malicious webpage in iPhone Safari, aimed to steal crypto private keys and seed phrases. SlowMist has not independently confirmed any crypto theft from a victim compromised by this specific attack.
The attack reuses techniques from the DarkSword exploit chain, disclosed by Google Threat Intelligence Group in March. SlowMist's chief information security officer, 23pds, identified the malicious activity in early May, and they published their analysis on September 4. The attack code could access Apple's Keychain and app files, potentially exposing crypto wallet information.
SlowMist advised iPhone users to update their devices immediately and avoid suspicious links, also mentioning that Apple's Lockdown Mode could provide additional defense.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.