Crypto news report · source clearly identified

SlowMist warns Darksword exploit may target iOS 26.5 wallets

Security firm SlowMist says the Darksword exploit chain could have been adapted to compromise iPhones running iOS 26.5, allowing attackers to extract private keys from self‑custody crypto wallets.

SlowMist has issued a warning that the Darksword exploit chain may now work against devices running iOS 26.5. The group says the attack can be triggered when a user opens a malicious link in Safari, potentially giving attackers root‑level control of the iPhone and access to private keys stored in self‑custody wallets.

How the attack works

The Darksword chain combines multiple iOS vulnerabilities to bypass Apple’s security controls. Attackers typically deliver a malicious URL via social media, messaging apps, or other channels. When the link is opened in Safari, the exploit attempts to compromise the browser and other system components without requiring the installation of a traditional app. If successful, the attacker can read files and credentials across applications, including cryptocurrency wallet data.

Known capabilities and targets

  • Root‑level access to the device, removing app isolation.
  • Extraction of private keys, recovery phrases, and other wallet credentials.
  • Collection of browser history, messages, location data, Wi‑Fi settings, and files.
  • Activity linked to victims in Saudi Arabia, Turkey, Malaysia and Ukraine.

Historical context

Google’s Threat Intelligence Group previously documented Darksword supporting iOS 18.4‑18.7. The chain uses six vulnerabilities, one of which (CVE‑2025‑43529) affected JavaScriptCore and was patched in iOS 18.7.3 and iOS 26.2 after Google reported it. SlowMist’s latest assessment extends the potential exposure to iOS 26.5, though Apple and Google have not independently confirmed this claim.

Related iOS threats

Other recent iOS exploits have also targeted cryptocurrency data. Google’s Coruna kit targeted iOS 13‑17.2.1, while Binance warned of malicious code in FomoPeek apps that could decrypt Keychain data and access wallet credentials on iOS 12‑18.7.2 and iOS 26.0‑26.1.

Recommendations

  • Install iOS updates promptly to receive security patches.
  • Avoid opening unsolicited links from unknown senders.
  • Consider creating a new wallet on a clean device if you suspect compromise.

Source & attribution

News Source

Publisher
crypto.news
Original date
September 21, 2026, 8:47 PM
Original headline
SlowMist warns Darksword may target wallets on iOS 26.5
View original report ↗