SlowMist Chief Information Security Officer 23pds said attackers are exploiting the Darksword vulnerability through Safari to bypass iOS security protections, take control of devices, and extract private keys and other data from self-custodied crypto wallets. The flaw had previously been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group had earlier disclosed that Darksword originally affected iOS 18.4 through 18.7. According to 23pds, attackers have now adapted the exploit to iOS 26.5, though that claim has not been officially verified. The attack chain typically starts with social engineering: once a user clicks a malicious link sent through social media or messaging apps, the device may be rooted and wallet data extracted. SlowMist urged users to update their phones promptly and avoid visiting links sent by strangers. Separately, Bitcoin.com News reported that three investors who downloaded fake wallet apps from Apple’s official App Store lost nearly $1.8 million in Bitcoin and have sued Apple.
SlowMist Chief Information Security Officer 23pds said attackers are using the Darksword vulnerability through Safari to bypass iOS security mechanisms, gain control of devices, and extract private keys and other data from self-custodied crypto wallets.
The vulnerability had previously been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group earlier disclosed that Darksword originally affected only iOS 18.4 to 18.7.
23pds said the exploit has now been adapted to iOS 26.5, although that assessment has not been officially verified.
According to the warning, these attacks usually begin with social engineering. After users click malicious links sent through social media or messaging applications, their devices may be rooted and wallet data may then be extracted.
SlowMist advised users to update their phone systems promptly and avoid visiting website links sent by strangers. Separately, Bitcoin.com News reported that three investors lost nearly $1.8 million in Bitcoin after downloading fake wallet applications from Apple’s official App Store, and they have filed a lawsuit against Apple.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.