SlowMist Has Yet to Confirm Crypto Theft from iPhone Safari Attack

Following recent security warnings regarding a vulnerability in the Safari browser on iPhones, SlowMist conducted an investigation and has yet to confirm any actual cryptocurrency theft. Though reports cited affected iOS versions ranging from 13 to 26.5, SlowMist’s strongest technical evidence pertains only to versions 18.4 through 18.6.2, urging caution against premature conclusions about the breadth of the attack.
Investigation and DarkSword Exploit Reuse
SlowMist identified that the Safari exploit reuses techniques from the DarkSword iOS exploit chain, which Google Threat Intelligence Group disclosed in March. DarkSword has been exploited by various threat actors since at least November 2025. SlowMist’s threat intelligence team MistEye, led by their CISO known as 23pds, first detected relevant malicious activity in early May. On September 4, SlowMist published their analysis of the WYINCC Safari campaign, which involved a malicious website promoting a free virtual private server service. When accessed from an iPhone using Safari, the exploit code loads automatically without requiring further user interaction.
Attack Objectives and Potential Impact
The examined malicious Safari sample included capabilities to access Apple’s Keychain—Apple’s secure credential storage system—and decrypt stored information. Additionally, it could access app files and shared data, potentially exposing sensitive information held by cryptocurrency wallet apps. SlowMist clarified that the sample demonstrates what the attack is capable of targeting but does not constitute proof of successful theft from every targeted wallet. They also noted that the full exploit chain was not run on real victim devices, and therefore no specific cases of confirmed compromise using this exact sample have been identified.
User Guidance from SlowMist
Given the limited evidence but elevated risks, SlowMist strongly advises iPhone users to promptly install the latest iOS security updates and to avoid clicking on suspicious links. For users unable to update immediately or considered at higher risk, SlowMist recommends enabling Apple’s Lockdown Mode as an additional protective measure, although it does not confirm that this feature fully mitigates the specific Safari attack. Furthermore, users concerned that their wallet keys or seed phrases might have been exposed should transfer assets to a newly generated wallet on a clean device rather than continue using possibly compromised credentials.
Why it matters
This news is significant for iPhone users, particularly those managing cryptocurrencies. Despite sensational reports about widespread vulnerabilities in the Safari browser, SlowMist’s technical investigation has so far found only preliminary evidence of exploit attempts without confirmed cases of actual crypto theft stemming from this attack. This clarifies the real threat level and helps prevent premature alarm. Nonetheless, the incident highlights the critical importance of promptly updating iOS devices and employing additional safeguards such as Apple’s Lockdown Mode. Moreover, it stresses the need for users to migrate assets to new wallets if they suspect exposure of keys or seed phrases. The story also illustrates the complexity of modern mobile threats and the vital role of continuous vulnerability monitoring in mobile operating systems to safeguard digital assets.
Prepared from the source material with AI-assisted editing and checked against the supplied facts.
Open original source ↗