SlowMist Warns DarkSword Attack Targets iPhone Users’ Crypto Wallets

2 Min Read
  • SlowMist said attackers are using the DarkSword exploit to target iPhone owners’ crypto wallets through malicious links opened in Safari.
  • Successful exploitation could allow attackers to escape the browser sandbox, gain elevated privileges and access wallet data and private keys, according to SlowMist.
  • SlowMist claimed DarkSword has been adapted for newer iOS versions, including iOS 26.5, but that claim has not been independently confirmed.

SlowMist has warned that attackers are using the DarkSword exploit to target crypto wallet owners on iPhones through Safari. The attack matters because successful exploitation could give attackers elevated access to a device and expose crypto wallet information and private keys, according to the firm.

SlowMist Chief Information Security Officer 23pds, who is known by that pseudonym, reported that attackers are distributing malicious links and prompting victims to open them in Safari.

According to 23pds, successful exploitation of the vulnerabilities can allow attackers to escape Safari’s browser sandbox, gain elevated privileges and access data stored on the device, including crypto wallet information and private keys.

Google Threat Intelligence Group previously investigated DarkSword and identified a chain of six vulnerabilities used in attacks against users in Saudi Arabia, Turkey, Malaysia and Ukraine. Google said the exploit supported iOS versions 18.4 through 18.7 and that the known vulnerabilities had been fixed with the release of iOS 26.3.

SlowMist now claims that attackers have adapted DarkSword to support newer versions of Apple’s operating system, including iOS 26.5. That information has not been independently confirmed.

Experts recommend that iPhone users install the latest available iOS version and avoid suspicious links received through social networks and messaging services.

In a separate case reported earlier, a crypto trader lost about $600,000 after encountering a fake Cloudflare verification.

Source: Incrypted

SlowMist Warns DarkSword Attack Targets iPhone Users’ Crypto Wallets

SlowMist said attackers are using DarkSword through malicious Safari links to target iPhone crypto wallets and claimed, without independent confirmation, that it supports iOS 26.5.

2 Min Read
Cronos Seeks 228M-Plus CRO Burn, All Product Profits for Buybacks

Voting is underway on two Cronos network proposals to burn 228 million CRO, direct all Ult and Cronos Launch revenue to buybacks and burns, and fund staking rewards from the…

4 Min Read
Bitcoin Rises to $85,000 Amid Negative Coinbase Premium

CryptoQuant said bitcoin crossed its $80,061 one-year moving average, potentially starting a recovery, but the negative Coinbase Premium indicated weak U.S. spot demand ahead of $88,761 resistance.

3 Min Read
Ethereum Rises; Binance Withdrawals Hit Three-Year High, Wallets Reach Record 207 Million

Ethereum topped $2,630 on Sept. 18, its highest since January, while Santiment reported rising large transactions and a record 207.17 million non-zero-balance wallets, and Darkfost said monthly Binance withdrawal transactions…

3 Min Read
AFTER 2049 Names Claptone, Crusy to Headline Singapore Event

Claptone and Crusy will headline AFTER 2049, TOKEN2049 Singapore’s official closing party, at Marina Bay Sands SkyPark on Oct. 9, 2026, featuring Polygon Live’s spatial audio system.

3 Min Read