Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

SlowMist Finds No Confirmed Crypto Theft from iPhone Safari Attack

Security firm SlowMist has not independently verified any cryptocurrency theft from a recent iPhone Safari exploit, though it confirmed the attack can access wallet data on certain iOS versions.
1 hour ago 8 views
SlowMist Finds No Confirmed Crypto Theft from iPhone Safari Attack

A malicious iPhone Safari attack that triggered security warnings this week has not been linked to confirmed cryptocurrency theft, according to an investigation by security firm SlowMist.

Multiple reports circulated urging iPhone users to update their devices, warning that malicious Safari pages could expose crypto private keys and seed phrases. Initial reports cited a vulnerability range spanning iOS 13 through iOS 26.5, though SlowMist cautioned this should be treated as preliminary.

SlowMist told Cointelegraph it has not independently confirmed a victim compromised by the specific Safari attack sample it analyzed. The firm's strongest technical evidence covers iOS 18.4 through 18.6.2.

Attack Mechanics and Scope

The Safari attack reuses techniques from the previously disclosed DarkSword exploit chain. Google Threat Intelligence Group disclosed DarkSword in March as an iOS exploit chain used by multiple threat actors since at least November 2025.

SlowMist published its analysis of the WYINCC Safari campaign on September 4, identifying a malicious webpage advertising free virtual private server services. When opened on an iPhone using Safari, the page loaded exploit code without requiring additional user interaction. The vulnerabilities in the chain had already been disclosed and patched by Apple.

What the Attack Could Access

SlowMist found that the malicious sample included a component designed to access Apple's Keychain and retrieve encrypted information stored there. The code could also access app files and shared app data, potentially exposing information from crypto wallet applications.

However, SlowMist emphasized that the sample demonstrates collection capability and intended targets, but does not prove successful extraction from every targeted wallet. "We did not execute the full chain on a real victim device, so we cannot identify a specific victim whose device we independently confirmed was successfully compromised by this exact sample," the firm said.

Recommended Protective Steps

Despite the absence of confirmed thefts, SlowMist advised iPhone users to install the latest iOS security updates and avoid suspicious links. For users unable to update immediately or facing elevated risks, the firm recommended considering Apple's Lockdown Mode as additional defense, while noting it has not confirmed the feature completely blocks this specific attack.

SlowMist urged users who believe a wallet key or seed phrase may have been exposed to move their assets to a newly generated wallet on a clean device rather than continue using potentially compromised credentials.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $84,038.10-0.16% EthereumETH $2,698.32+1.02% Tether USDUSDT $0.9999+0.06% BNBBNB $774.93-0.18% XRPXRP $1.59+5.61% USDCUSDC $0.9999-0.02% SolanaSOL $119.85+4.07% TRONTRX $0.3374-0.79% HyperliquidHYPE $92.74-0.11% ZcashZEC $1,605.07+5.64%
Prices by Coinranking. Informational only.