SlowMist says no confirmed crypto theft tied to investigated iPhone Safari attack

SlowMist says no confirmed crypto theft tied to investigated iPhone Safari attack

N
News Editor
2026-09-25 12:19:34
SlowMist said it has not independently confirmed any cryptocurrency theft caused by the specific iPhone Safari attack sample behind recent security warnings, even as reports urged users to update their devices and warned that malicious webpages could expose private keys and seed phrases. According to the blockchain security firm, the strongest technical evidence it has so far applies to iOS 18.4 through 18.6.2, while broader claims that the issue affects devices from iOS 13 to iOS 26.5 should still be treated as preliminary. SlowMist said it does not want to state that iOS 26.5 is affected without reproducible technical evidence. The company added that the Safari attack reuses methods from the previously disclosed DarkSword exploit chain and is separate from FomoPeek, another SlowMist investigation involving malicious components hidden in an App Store app. Its analysis found that the malicious sample was built to access Apple Keychain, retrieve and decrypt stored data, and read app files and shared app data that could include information from crypto wallet apps. Even so, SlowMist said the sample shows collection capability and intended targets, not proof of successful extraction from every targeted wallet. The firm still advised users to install the latest iOS security updates, avoid suspicious links, consider Lockdown Mode if they face higher risk, and move assets to a newly generated wallet on a clean device if they suspect their keys or seed phrases may have been exposed.

SlowMist said the iPhone Safari attack that triggered recent security alerts has not yet been tied to a confirmed cryptocurrency theft in its own investigation.

Several reports circulated this week urging iPhone users to update their devices immediately, warning that malicious Safari pages could expose crypto private keys and seed phrases. Some of those reports cited a possible affected range stretching from iOS 13 to iOS 26.5.

In comments to Cointelegraph, SlowMist said it has not independently confirmed a victim whose device was compromised by the specific Safari sample it analyzed. The strongest technical evidence it currently has covers iOS 18.4 through 18.6.2.

The security firm said the "iOS 13 to 26.5" range should be treated as preliminary. "We therefore prefer to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence," the company said.

SlowMist says the campaign reused DarkSword techniques

SlowMist said the Safari attack reused techniques from the previously disclosed DarkSword exploit chain. It also said the case is separate from FomoPeek, another SlowMist investigation involving malicious components embedded in an App Store app.

Google Threat Intelligence Group, or GTIG, disclosed DarkSword in March and described it as an iOS exploit chain used by multiple threat actors since at least November 2025.

According to SlowMist, MistEye, the threat intelligence team led by its chief information security officer 23pds, first identified the relevant activity in early May.

On Sept. 4, SlowMist published its analysis of the WYINCC Safari campaign, identifying a malicious webpage that advertised a free virtual private server service.

The company said the page loaded exploit code when opened on an iPhone with Safari and did not necessarily require another click from the user.

SlowMist added that the vulnerabilities used in the chain had already been disclosed and patched by Apple.

What the Safari sample was built to access

SlowMist said the malicious Safari sample it analyzed included a component designed to access Apple Keychain and retrieve and decrypt information stored there.

The code could also access app files and shared app data, which means information stored by crypto wallet applications could be exposed.

"The sample demonstrates the collection capability and the intended targets; it does not by itself prove successful extraction from every targeted wallet," SlowMist said.

The firm added: "We did not execute the full chain on a real victim device, so we cannot identify a specific victim whose device we independently confirmed was successfully compromised by this exact sample."

SlowMist still urges users to update iOS

Despite those limits, SlowMist advised iPhone users to install the latest iOS security updates available for their devices and avoid suspicious links.

For users who cannot update right away or face elevated risks, the firm said Apple’s Lockdown Mode could be considered as an added defensive measure. It also cautioned that it has not confirmed the feature fully blocks this specific Safari attack.

SlowMist said users who believe a wallet key or seed phrase may have been exposed should move their assets to a newly generated wallet on a clean device instead of continuing to use credentials that may already be compromised.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
2800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.