Skip to content

Coins

New Cryptocurrency Attack Discovered on iPhone: Steps to Protect Your Assets

Key Highlights Google Threat Intelligence Group (GTIG) revealed the “DarkSword” attack chain exploiting six iOS vulnerabilities to achieve kernel-level access via Safari, with all flaws patched in iOS 26.3 or...

Key Highlights

  • Google Threat Intelligence Group (GTIG) revealed the “DarkSword” attack chain exploiting six iOS vulnerabilities to achieve kernel-level access via Safari, with all flaws patched in iOS 26.3 or earlier.
  • The campaign targeted cryptocurrency users in Turkey, Saudi Arabia, Malaysia, and Ukraine starting November 2025, enabling extraction of private keys and seed phrases from compromised devices.
  • Unverified claims that DarkSword affects all iOS versions from 13 through 26.5 remain unconfirmed; Apple released iOS 26.7 on September 14, 2026, and researchers urge immediate updates plus Lockdown Mode for high-risk users.

Multi-Stage Safari Exploit Chain Grants Kernel Access on iPhone

Security researchers have detailed a sophisticated attack chain dubbed DarkSword that targets iPhone users through Safari, ultimately delivering full device control and posing acute risk to cryptocurrency holders. According to research published in March by the Google Threat Intelligence Group (GTIG), the exploit chain begins with memory corruption vulnerabilities in Safari’s JavaScriptCore engine. When a target visits a malicious or compromised website, the initial foothold allows attackers to bypass Pointer Authentication Codes (PAC) protections, escape the WebContent sandbox, and escalate privileges to the kernel level. GTIG confirmed that six distinct vulnerabilities were chained together in the operation, all of which Apple addressed no later than the release of iOS 26.3.

Confirmed Targeting of Cryptocurrency Users Across Four Nations

Lookout’s complementary research indicates that once DarkSword achieves kernel access, threat actors can rapidly extract user credentials and sensitive data associated with cryptocurrency wallets, including private keys and mnemonic seed phrases stored on the device. The first confirmed iterations of the campaign targeted devices running iOS 18.4 through iOS 18.7. GTIG attributed active exploitation to a campaign that began in November 2025 against targets located in Turkey, Saudi Arabia, Malaysia, and Ukraine. The geographic spread and focus on crypto asset extraction suggest a financially motivated operation with selective targeting rather than indiscriminate mass compromise.

Unverified Claims of Broader Version Impact Require Caution

Recent public claims asserting that DarkSword remains effective across a vastly wider range — from iOS 13 through iOS 26.5 — have not been independently verified by GTIG, Lookout, or other recognized research entities. Security professionals emphasize that this extended version span should not be treated as a confirmed finding. Apple continues to harden the platform; the company released iOS 26.7 on September 14, 2026, and recent updates have included patches for numerous vulnerabilities affecting WebKit, the kernel, and other core system components. Researchers stress that the verified attack surface covers the iOS 18.x series addressed in the March disclosure.

Mitigation Guidance: Update, Lockdown Mode, and Operational Hygiene

GTIG and Lookout recommend that all users, particularly those managing cryptocurrency wallets on mobile devices, immediately update to the latest available iOS version. For devices that cannot be updated or for individuals assessed to be at elevated risk, enabling Apple’s Lockdown Mode provides an additional layer of protection by severely restricting attack surface vectors such as just-in-time JavaScript compilation and complex web technologies. Beyond patching, researchers advise strict operational hygiene: avoid opening untrusted links received via messages, email, or social media in Safari, and never store critical secrets — private keys, seed phrases, or recovery phrases — in plaintext or accessible locations on the phone.

Why This Matters

The DarkSword disclosure underscores the persistent threat of watering-hole and drive-by exploitation targeting mobile browsers, especially when high-value assets like cryptocurrency wallets are involved. The chain’s ability to defeat PAC and sandbox protections — mitigations Apple has invested heavily in — demonstrates that determined adversaries can still string together multiple zero-day or n-day flaws to achieve full compromise. For the cryptocurrency ecosystem, the incident reinforces that mobile devices should not be treated as secure cold storage; hardware wallets and air-gapped signing remain best practice. The November 2025 campaign start date also indicates that threat actors held and operationalized the chain for months before public disclosure, a reminder that patch lag creates a dangerous exposure window. Going forward, Apple’s rapid response with iOS 26.3 and subsequent releases, combined with Lockdown Mode adoption, represents the primary defense for at-risk users until the next vulnerability cycle emerges.

Frequently Asked Questions

Which iOS versions are confirmed vulnerable to the DarkSword attack chain?
GTIG confirmed that the first observed DarkSword variants targeted devices running iOS 18.4 through iOS 18.7. All six vulnerabilities used in the chain were patched by Apple in iOS 26.3 or earlier.
Is it true that DarkSword works on every iOS version from 13 to 26.5?
No. Claims that the exploit chain affects all versions from iOS 13 through iOS 26.5 have not been independently verified by Google Threat Intelligence Group, Lookout, or other recognized researchers. The verified scope remains the iOS 18.x series documented in the March disclosure.
What immediate steps should cryptocurrency users take to protect themselves?
Update to the latest iOS version (iOS 26.7 as of September 14, 2026), enable Lockdown Mode if the device supports it and the user is at high risk, avoid opening untrusted links in Safari, and never store private keys, seed phrases, or recovery phrases on the phone in accessible form.
Evan Mercer

Penulis

Evan Mercer covers coins, digital assets and the market stories shaping everyday conversations about money. His work focuses on accessible explanations, useful context and the signals behind sudden moves.