{
  "id": 9765258,
  "title": "SlowMist has yet to confirm crypto theft from iPhone Safari attack",
  "url": "https://urgent.news/2026/09/25/slowmist-has-yet-to-confirm-crypto-theft-from-iphone-safari-attack",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-25T12:19:34.000Z",
  "source": {
    "name": "Cointelegraph",
    "slug": "cointelegraph",
    "url": "https://cointelegraph.com/news/no-confirmed-crypto-theft-iphone-safari-attack-slowmist"
  },
  "original_language": "en",
  "account": "SlowMist disclosed a Safari attack targeting iOS 18.4 to 18.6.2, though its effectiveness on iOS 26.5 remains unconfirmed. The attack, linked to a malicious webpage in iPhone Safari, aimed to steal crypto private keys and seed phrases. SlowMist has not independently confirmed any crypto theft from a victim compromised by this specific attack. The attack reuses techniques from the DarkSword exploit chain, disclosed by Google Threat Intelligence Group in March. SlowMist's chief information security officer, 23pds, identified the malicious activity in early May, and they published their analysis on September 4. The attack code could access Apple's Keychain and app files, potentially exposing crypto wallet information. SlowMist advised iPhone users to update their devices immediately and avoid suspicious links, also mentioning that Apple's Lockdown Mode could provide additional defense.",
  "summary": "The analyzed Safari sample targets iOS 18.4–18.6.2 using previously patched flaws, while its effectiveness on iOS 26.5 remains unverified.",
  "key_points": [
    "SlowMist disclosed Safari attack targeting iOS 18.4 to 18.6.2",
    "Attack aimed to steal crypto private keys and seed phrases",
    "SlowMist has not confirmed crypto theft from victims"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}