SlowMist Uncovers DarkSword Wallet Theft Campaign Targeting iOS Safari

SlowMist Uncovers DarkSword Wallet Theft Campaign Targeting iOS Safari

N
News Editor
2026-09-04 11:05:07
SlowMist security team has identified a malicious campaign disguised as a free VPS service. The landing page event[.]polarnode[.]vip silently loads the lk[.]js script, which checks for iPhones running iOS 18.4 to 18.6.2 on Safari, aiming to steal assets from DarkSword wallet users. SlowMist urges users to stay vigilant.

The SlowMist security team says it found a malicious campaign aimed at iOS users. The trick is simple. Attackers pose as a free VPS service and use a landing page at event[.]polarnode[.]vip to quietly load the lk[.]js script.

That script looks for iPhones using Safari and running iOS 18.4 through 18.6.2. The target: assets held by DarkSword wallet users. And SlowMist has warned affected users to take precautions.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.