
SlowMist Investigates iPhone Safari Exploit Amidst Crypto Theft Concerns
Vexoda Newsroom
Security firm SlowMist is investigating a potential iPhone Safari exploit that could compromise crypto private keys. While evidence points to certain iOS versions, confirmed theft remains unverified.
A recent security alert has warned iPhone users about a sophisticated attack leveraging the Safari browser, potentially leading to the theft of cryptocurrency private keys and seed phrases. Reports circulating this week urged immediate updates for affected iOS versions, citing a broad range from iOS 13 up to iOS 26.5. This alert has caused concern within the crypto community regarding the safety of digital assets stored on mobile devices.
The security firm SlowMist, which has been actively investigating the alleged exploit, stated that while they have analyzed a specific Safari attack sample, they have not yet independently confirmed any instances of cryptocurrency theft directly resulting from it. Their strongest technical findings currently align with iOS versions 18.4 through 18.6.2, and they have cautioned that the wider range mentioned in earlier reports should be considered preliminary until further reproducible evidence emerges.
The investigated Safari attack appears to reuse techniques previously disclosed in the DarkSword exploit chain, which has been active since late 2025, according to Google Threat Intelligence. SlowMist's threat intelligence team first identified related activity in early May. The attack reportedly involves a malicious webpage, advertised as a free virtual private server service, that injects exploit code into an iPhone's Safari browser upon opening, potentially without requiring an additional user click. Notably, the vulnerabilities exploited were ones that Apple had already patched.
The core functionality of the analyzed malicious Safari sample was designed to access Apple's Keychain, a secure storage system for sensitive data, to retrieve and decrypt information. Furthermore, the exploit code showed capabilities to access app files and shared data, which could include sensitive information stored by cryptocurrency wallet applications. While the sample demonstrates the potential to access such data, SlowMist emphasizes that it does not definitively prove successful extraction from every targeted wallet.
Despite the lack of confirmed theft linked to this specific sample, SlowMist strongly advises all iPhone users to promptly install the latest available iOS security updates to mitigate potential risks. For users who cannot update immediately or are in high-risk situations, the firm suggests enabling Apple's Lockdown Mode as an additional protective measure, though its complete effectiveness against this particular attack remains unverified. These recommendations aim to bolster user defenses against evolving mobile security threats.
Looking ahead, traders and cryptocurrency holders should remain vigilant and continue to monitor official security advisories from firms like SlowMist and Apple. Users who suspect their wallet keys or seed phrases may have been compromised are urged to immediately transfer their digital assets to a newly generated wallet on a secure, clean device. This proactive measure is crucial to prevent further potential losses from any confirmed or future exploits targeting mobile platforms.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.