Crypto news report · source clearly identified

SlowMist has not confirmed crypto theft from iPhone Safari attack

The analyzed Safari sample targets iOS 18.4–18.6.2 using previously patched flaws, while its effectiveness on iOS 26.5 remains unverified.

Security firm SlowMist says it has not independently verified any cryptocurrency theft linked to a recently publicized iPhone Safari exploit. The company’s analysis focuses on a malicious webpage that loads exploit code on Safari browsers running specific iOS versions.

Technical scope of the Safari sample

SlowMist’s investigation identifies the sample as targeting iOS versions 18.4 through 18.6.2. These versions contain vulnerabilities that were previously disclosed and patched by Apple. The firm cautions that reports suggesting a broader range from iOS 13 to iOS 26.5 are preliminary and lack reproducible evidence.

Relation to known exploit chains

The malicious page reuses techniques from the DarkSword exploit chain, which was first disclosed by Google Threat Intelligence Group in March 2026 and has been observed in the wild since at least November 2025. The Safari attack is separate from the FomoPeek campaign, another SlowMist‑investigated threat involving a compromised App Store application.

Intended capabilities

Analysis shows the code attempts to access Apple’s Keychain, decrypt stored data, and read files from installed applications. This includes data that could be used by cryptocurrency wallet apps, such as private keys or seed phrases. SlowMist notes that while the sample demonstrates these collection capabilities, it does not prove successful extraction from every targeted wallet.

Evidence limitations

SlowMist did not execute the full exploit chain on a live victim device, and therefore cannot confirm a specific compromised user or successful theft of crypto assets linked to this sample.

Recommendations for iPhone users

  • Install the latest iOS security updates immediately.
  • Avoid clicking suspicious links, especially those that claim free services.
  • Consider enabling Apple’s Lockdown Mode for additional protection, though its effectiveness against this specific Safari exploit has not been fully verified.
  • If a wallet’s private key or seed phrase may have been exposed, move assets to a new wallet on a clean device.

Source & attribution

News Source

Publisher
Cointelegraph
Original date
September 25, 2026, 12:19 PM
Original headline
SlowMist has yet to confirm crypto theft from iPhone Safari attack
View original report ↗