SlowMist, a cybersecurity firm, has identified an iPhone Safari exploit that could expose cryptocurrency wallet private keys and seed phrases, though it has not yet confirmed any successful thefts linked to the attack. The threat involves malicious pages designed to compromise devices running iOS versions from 13 through 26.5, with the most recent evidence pointing to versions 18.4 to 18.6.2. The company cautioned that the broader range of affected versions—spanning from iOS 13 to 26.5—remains preliminary and based on technical analysis rather than confirmed victim compromises. ‘We prefer to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence,’ SlowMist stated, emphasizing the need for caution in its findings.
The attack reuses techniques from the previously disclosed DarkSword exploit chain, first disclosed by Google Threat Intelligence Group in March 2025. DarkSword had been exploited by multiple threat actors since November 2025, with SlowMist’s MistEye team identifying relevant activity as early as May 2025. The most recent campaign, dubbed WYINCC, involved a malicious webpage advertising a free virtual private server (VPS) service. Opening the page through Safari triggered the exploit without requiring further user interaction, despite Apple having already patched the underlying vulnerabilities.
SlowMist’s analysis revealed that the malicious sample targeted Apple’s Keychain to retrieve and decrypt stored information, including data from crypto wallet applications. While the exploit demonstrated the capability to access such data, the firm noted that it did not execute the full chain on a real device to confirm successful extraction in every case. ‘We did not execute the full chain on a real victim device, so we cannot identify a specific victim whose device we independently confirmed was successfully compromised by this exact sample,’ the company said.
In the absence of confirmed thefts, SlowMist advised iPhone users to install the latest iOS security updates and avoid engaging with suspicious links. For those unable to update immediately or facing heightened risks, the firm recommended enabling Apple’s Lockdown Mode, though it cautioned that this feature had not been tested against this specific attack. Users who suspect their wallet keys or seed phrases may have been exposed are advised to transfer their assets to a newly generated wallet on a clean device, rather than continuing to use potentially compromised credentials.
The exploit leverages techniques from DarkSword, a previously known iOS exploit chain, but operates independently of another SlowMist investigation involving malicious components embedded in an App Store app called FomoPeek. While Apple had previously patched the vulnerabilities in DarkSword, the Safari campaign’s persistence underscores the ongoing need for vigilance among crypto users.











