Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Safari Zero-Day Exploit Targets iPhone Crypto Wallets Through WebKit Vulnerability

Security researchers have confirmed an active exploit chain affecting iPhones running iOS 13 through 26.5 that uses malicious Safari webpages to steal cryptocurrency private keys and seed phrases from wallet storage.
59 minutes ago 8 views
Safari Zero-Day Exploit Targets iPhone Crypto Wallets Through WebKit Vulnerability

Blockchain security firm SlowMist confirmed on September 19 that a critical vulnerability is being actively exploited against iPhones, with attackers targeting private keys and mnemonic seed phrases stored in crypto wallets. The exploit affects devices running iOS 13 through 26.5 and operates through malicious webpages accessed via Safari.

How the Attack Works

The exploit chain begins when a user visits a compromised Safari webpage. The attack exploits a memory corruption flaw in WebKit, Apple's browser engine, and its JavaScript runtime environment, JavaScriptCore, to establish an initial foothold.

From this entry point, the exploit escalates through several stages. It bypasses Pointer Authentication Codes, Apple's mechanism for verifying software instructions have not been altered, then breaks out of the browser's sandbox—the isolated environment designed to prevent web content from accessing the broader operating system. The attack ultimately achieves kernel-level access, the highest control level possible on a device.

With kernel access, attackers can reach the iOS Keychain, where sensitive credentials including crypto wallet keys are stored. Private keys and seed phrases can be copied without the device owner's knowledge.

Implications for Crypto Users

Unlike compromised email passwords that can be reset, stolen private keys cannot be recovered. Whoever possesses a private key has permanent access to associated funds.

Software wallets stored on iPhones face direct risk from this exploit. Hardware wallets, which store private keys on dedicated physical devices that never connect to the internet, are not vulnerable to Safari-based attacks.

Pattern of iOS Targeting

This is not an isolated incident. In March 2026, security researchers identified an exploit kit called DarkSword that chained six separate vulnerabilities to harvest data from iPhones running iOS 18.x variants. That kit specifically targeted crypto applications including Coinbase and MetaMask.

Apple patched several vulnerabilities in the exploit chain through iOS 26.3, but the window between discovery, patching, and user adoption creates ongoing risk.

Recommended Actions

Security researchers recommend immediate steps for affected users: update iOS to the latest available version and avoid clicking links from unknown sources. Users concerned about potential exposure should treat their device as compromised and regenerate keys entirely on clean hardware, which also requires moving funds to a new wallet address.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $85,789.78+5.70% EthereumETH $2,748.49+4.72% Tether USDUSDT $1.00+0.11% BNBBNB $800.19+5.35% XRPXRP $1.50+7.12% USDCUSDC $1.00+0.02% SolanaSOL $117.83+8.20% TRONTRX $0.3453+0.18% HyperliquidHYPE $93.01+0.63% ZcashZEC $1,494.02+2.62%
Prices by Coinranking. Informational only.