• CONTACT
  • MARKETCAP
Coin  Deskk
  • BOOKMARKS
  • What’s New
  • Cryptocurrency
  • Pages
    • Contact Us
    • Search Page
    • Customize Interests
    • My Bookmarks
  • Home Coin
  • Home Coin
Reading: SlowMist warns Darksword may target wallets on iOS 26.5
Share
Coin  DeskkCoin  Deskk
Font ResizerAa
  • Home
  • Crypto
  • Market
  • Blockchain
  • Contact
Search
© 2026 Coindeskk News Network. All Rights Reserved.
What's New

SlowMist warns Darksword may target wallets on iOS 26.5

Crypto
Last updated: September 22, 2026 12:08 am
Crypto
Published: September 22, 2026
Share
SlowMist warns Darksword may target wallets on iOS 26.5

SlowMist has warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5 and extract private keys from self-custody crypto wallets. Summary Darksword attacks can begin when an iPhone user opens a malicious link in Safari. SlowMist says attackers may have adapted the exploit chain to iOS 26.5. Google previously confirmed Darksword activity against iOS 18.4 through iOS 18.7. Three U.S. investors separately allege fake wallet apps caused $1.835 million in Bitcoin losses. SlowMist Chief Information Security Officer 23pds said attackers are using Darksword to bypass Apple’s security controls, gain extensive access to affected iPhones, and collect data from locally installed cryptocurrency wallets. The reported iOS 26.5 exposure has not been independently confirmed by Apple or Google. Google Threat Intelligence Group’s published research documented support for iOS versions 18.4 through 18.7, while 23pds said attackers have since modified the tool to work against the newer operating system. Darksword may reach iOS 26.5 devices Google’s Threat Intelligence Group identified Darksword as a full iOS exploit chain that combines six vulnerabilities to compromise devices and deliver separate malicious payloads. The company tracked related activity from at least December 2025 through March 2026. According to Google, the original framework supported iOS 18.4 through iOS 18.7. One flaw used against iOS 18.6 to 18.7 devices, tracked as CVE-2025-43529, affected JavaScriptCore, the engine that processes JavaScript in Safari. Apple patched the flaw in iOS 18.7.3 and iOS 26.2 after Google reported it. SlowMist’s latest assessment extends the potential exposure to iOS 26.5, although the security company’s claim has not received official confirmation. No technical analysis cited in the warning established which vulnerability or replacement exploit could let Darksword compromise the newer release. Attackers generally initiate the compromise through social engineering, according to 23pds. A target receives a link through a social network, messaging app, or another communication channel and opens the page in Safari. Malicious web content then attempts to exploit the browser and other iOS components without requiring the user to install a conventional application. Once the chain succeeds, the attacker may obtain root-level control, 23pds said. Such access can remove the isolation that normally prevents one application from reading files and credentials belonging to another, placing private keys and other wallet records stored on the device at risk. Malicious Safari links can expose wallet data Google found several groups using Darksword with different final-stage payloads, rather than one fixed piece of malware. Depending on the campaign, the payloads could collect account details, messages, browser records, files, location history, saved Wi-Fi data and information linked to cryptocurrency wallets. The security company connected separate operations to victims in Saudi Arabia, Turkey, Malaysia and Ukraine. Google associated some activity with commercial surveillance providers and suspected state-linked groups, while researchers also found signs that financially motivated actors had gained access to advanced iPhone exploitation tools. No victim total or confirmed amount of cryptocurrency stolen through Darksword was included in the material supplied by SlowMist. The warning instead focused on the framework’s ability to reach wallet information after compromising the device that stores it. A similar delivery method appeared in an earlier mobile threat. In March, crypto.news covered Google’s findings on Coruna, an exploit kit containing 23 vulnerabilities across five attack chains. Coruna targeted iPhones running versions from iOS 13 through iOS 17.2.1 and could search files and images for terms such as “backup phrase” and “bank account.” Google researchers said Coruna fingerprinted a visitor’s device before selecting an exploit suited to the iPhone model and software version. Some operators placed the kit on fake gambling and cryptocurrency sites, allowing the compromise to begin when a target loaded the page. Recent iOS threats have targeted private keys Darksword is not the only recent security threat involving cryptocurrency data on Apple devices. Binance warned iPhone and iPad users on Sep. 19 about malicious code found in FomoPeek versions 1.1 and 1.2. Researchers examining the app found a kernel exploitation framework with eight attack methods and declared support covering iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1. The malicious modules could escape the iOS sandbox, decrypt Keychain data, and access private keys, wallet recovery phrases, account credentials, and files held by other applications, according to a report on FomoPeek. Binance advised anyone who had installed the affected versions to remove the app, update iOS, and avoid reinstalling it. Self-custody users were also told to create a new wallet on a clean device and transfer their assets, since deleting a malicious app would not protect a wallet if its private key or recovery phrase had already been copied. Darksword uses a different route because its documented campaigns rely on malicious or compromised websites. Both cases, however, involve attempts to defeat the controls that ordinarily prevent software from obtaining sensitive records held elsewhere on an iPhone. SlowMist advised users to install mobile operating-system updates promptly and avoid opening unsolicited links sent by strangers. Google and Apple have also treated current software as a central defense because Apple has patched the six vulnerabilities documented in the original Darksword chain. U.S. investors have also sued Apple over fake wallets For U.S. crypto holders, the Darksword warning follows a separate dispute over malicious wallet software distributed through Apple’s official marketplace. Three investors filed a federal lawsuit alleging that fake applications impersonating Sparrow Wallet appeared in the App Store and caused about $1.835 million in Bitcoin losses, according to earlier court coverage. The plaintiffs’ allegations concern fraudulent applications rather than a browser-based exploit. Their case nevertheless centers on the security of Apple’s mobile distribution system and the financial damage that can occur when users trust software presented as a legitimate cryptocurrency wallet. Another counterfeit application posing as Ledger Live allegedly stole at least $9.5 million from more than 50 victims between April 7 and April 13. Blockchain investigator ZachXBT traced funds from Bitcoin, Ethereum, Solana, Tron, and XRP users to more than 150 KuCoin deposit addresses and a mixing service. The fake Ledger application asked users to enter their 24-word recovery phrases during what appeared to be a standard wallet setup. Apple later removed the listing, while one victim said he downloaded it while configuring a Ledger device on a new MacBook. Unlike the Darksword chain, the fraudulent Ledger app did not need to break the operating system’s security controls. Users exposed their wallets by entering recovery phrases into the impersonating software, giving its operators control of every address derived from those phrases.

Discover Altcoins’ Rocket-Powered Rally: M, IP, PUMP Soar Unstoppably!
Connecticut DeFi warning follows resident’s $200K loss
Deregulation Sparks Cyber Chaos: Unleash Hidden Hacks Before It’s Too Late
Will Solana’s Whale-Powered $200 Surge Endure? Discover Now!
President Trump crypto profits called inappropriate by 63%: poll

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Bank of Russia sets 1% crypto risk limit under draft rules Bank of Russia sets 1% crypto risk limit under draft rules
Next Article Tokenized stocks may see limited U.S. demand: TD Cowen Tokenized stocks may see limited U.S. demand: TD Cowen

Follow US

Find US on Socials
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
Shiba Inu Plunges: Will It Survive This Critical Test?
Shiba Inu Plunges: Will It Survive This Critical Test?
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin  Deskk

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

© Coindeskk News Network. All Rights Reserved.