SlowMist said the iPhone Safari attack that triggered recent security alerts has not yet been tied to a confirmed cryptocurrency theft in its own investigation.
Several reports circulated this week urging iPhone users to update their devices immediately, warning that malicious Safari pages could expose crypto private keys and seed phrases. Some of those reports cited a possible affected range stretching from iOS 13 to iOS 26.5.
In comments to Cointelegraph, SlowMist said it has not independently confirmed a victim whose device was compromised by the specific Safari sample it analyzed. The strongest technical evidence it currently has covers iOS 18.4 through 18.6.2.
The security firm said the "iOS 13 to 26.5" range should be treated as preliminary. "We therefore prefer to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence," the company said.
SlowMist says the campaign reused DarkSword techniques
SlowMist said the Safari attack reused techniques from the previously disclosed DarkSword exploit chain. It also said the case is separate from FomoPeek, another SlowMist investigation involving malicious components embedded in an App Store app.
Google Threat Intelligence Group, or GTIG, disclosed DarkSword in March and described it as an iOS exploit chain used by multiple threat actors since at least November 2025.
According to SlowMist, MistEye, the threat intelligence team led by its chief information security officer 23pds, first identified the relevant activity in early May.
On Sept. 4, SlowMist published its analysis of the WYINCC Safari campaign, identifying a malicious webpage that advertised a free virtual private server service.
The company said the page loaded exploit code when opened on an iPhone with Safari and did not necessarily require another click from the user.
SlowMist added that the vulnerabilities used in the chain had already been disclosed and patched by Apple.
What the Safari sample was built to access
SlowMist said the malicious Safari sample it analyzed included a component designed to access Apple Keychain and retrieve and decrypt information stored there.
The code could also access app files and shared app data, which means information stored by crypto wallet applications could be exposed.
"The sample demonstrates the collection capability and the intended targets; it does not by itself prove successful extraction from every targeted wallet," SlowMist said.
The firm added: "We did not execute the full chain on a real victim device, so we cannot identify a specific victim whose device we independently confirmed was successfully compromised by this exact sample."
SlowMist still urges users to update iOS
Despite those limits, SlowMist advised iPhone users to install the latest iOS security updates available for their devices and avoid suspicious links.
For users who cannot update right away or face elevated risks, the firm said Apple’s Lockdown Mode could be considered as an added defensive measure. It also cautioned that it has not confirmed the feature fully blocks this specific Safari attack.
SlowMist said users who believe a wallet key or seed phrase may have been exposed should move their assets to a newly generated wallet on a clean device instead of continuing to use credentials that may already be compromised.

