SlowMist Chief Information Security Officer 23pds said attackers are exploiting the Darksword vulnerability to bypass iOS security protections through Safari, seize control of devices, and extract private keys and other data from self-custodied crypto wallets. He said the exploit has been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group had previously disclosed that Darksword originally affected only iOS 18.4 through 18.7. 23pds also said attackers have adapted the exploit to iOS 26.5, though that claim has not been officially verified. According to him, the attack chain usually starts with social engineering: users click malicious links sent through social media or messaging apps, after which a device may be rooted and wallet data extracted. He urged users to update their phones promptly and avoid opening website links sent by strangers. Separately, three investors who lost nearly $1.8 million in Bitcoin after downloading a fake wallet app from Apple’s official App Store have filed a lawsuit against Apple.
According to ChainCatcher, SlowMist Chief Information Security Officer 23pds said attackers are using the Darksword vulnerability to bypass iOS security protections through Safari, take control of devices, and extract private keys and other data from self-custodied crypto wallets.
The vulnerability was previously used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group had disclosed earlier that Darksword originally affected only iOS 18.4 to 18.7. 23pds said attackers have already adapted it to iOS 26.5, although that assessment has not been officially verified.
23pds said the attacks usually begin with social engineering. After users click malicious links delivered through social media or messaging apps, their devices may obtain root access and wallet data may then be extracted.
He advised users to update their phone systems promptly and avoid visiting website links sent by strangers. In a separate case, three investors who lost nearly $1.8 million in Bitcoin after downloading fake wallet apps from Apple’s official App Store have sued Apple.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.