23pds

SlowMist
2026-09-21 19:20:46

SlowMist warns Darksword exploit may now target iOS 26.5 and steal wallet private keys

SlowMist Chief Information Security Officer 23pds said attackers are exploiting the Darksword vulnerability through Safari to bypass iOS security protections, take control of devices, and extract private keys and other data from self-custodied crypto wallets. The flaw had previously been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group had earlier disclosed that Darksword originally affected iOS 18.4 through 18.7. According to 23pds, attackers have now adapted the exploit to iOS 26.5, though that claim has not been officially verified. The attack chain typically starts with social engineering: once a user clicks a malicious link sent through social media or messaging apps, the device may be rooted and wallet data extracted. SlowMist urged users to update their phones promptly and avoid visiting links sent by strangers. Separately, Bitcoin.com News reported that three investors who downloaded fake wallet apps from Apple’s official App Store lost nearly $1.8 million in Bitcoin and have sued Apple.

60
SlowMist warns Darksword exploit may now target iOS 26.5 and steal wallet private keys
SlowMist
2026-09-21 19:21:50

SlowMist warns Darksword exploit can bypass iOS protections and extract wallet private keys

SlowMist Chief Information Security Officer 23pds said attackers are exploiting the Darksword vulnerability to bypass iOS security protections through Safari, seize control of devices, and extract private keys and other data from self-custodied crypto wallets. He said the exploit has been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group had previously disclosed that Darksword originally affected only iOS 18.4 through 18.7. 23pds also said attackers have adapted the exploit to iOS 26.5, though that claim has not been officially verified. According to him, the attack chain usually starts with social engineering: users click malicious links sent through social media or messaging apps, after which a device may be rooted and wallet data extracted. He urged users to update their phones promptly and avoid opening website links sent by strangers. Separately, three investors who lost nearly $1.8 million in Bitcoin after downloading a fake wallet app from Apple’s official App Store have filed a lawsuit against Apple.

60
SlowMist warns Darksword exploit can bypass iOS protections and extract wallet private keys
Whale Movemen
2026-09-20 09:30:00

PA Daily: Strategy jumps 48% in a month as PlanB says Bitcoin bear market is over

PANews’ latest daily roundup spans market calls, security incidents, project updates, regulation and whale activity across crypto. Among the headline items, analyst PlanB said Bitcoin has moved above its 50-week moving average at about $79,000 and is now targeting the 100-week moving average near $89,000, arguing that the bear market has ended. On the equities side, Cointelegraph reported that MicroStrategy, trading as MSTR, was the best-performing Nasdaq-100 component over the past month with a 48% gain. The report also covered a major fraud case in Istanbul involving more than $3 billion, where authorities arrested 191 suspects in a cross-agency operation. In the U.S., Kalshi and Kraken parent Payward filed applications tied to perpetual contracts linked to individual stocks. Project-side developments included Universal’s planned wind-down over 60 days, MultiversX pausing its mainnet after confirming an attack attempt, and a dispute between Chengming Technology and Zhipu over alleged unauthorized data uploads by the ZCode client. Security and on-chain data featured heavily as well. Forbes reported that North Korea-linked hackers infected more than 30,000 devices through fake job offers and stole data from over 7,000 crypto wallets, with at least $10.71 million flowing to attacker-controlled wallets. PANews also highlighted losses at Fetch.ai and NuNet, several large leveraged positions, and comments from Michael Saylor, Vitalik Buterin, Peter Schiff, Jiang Zhuoer and ZachXBT.

320
PA Daily: Strategy jumps 48% in a month as PlanB says Bitcoin bear market is over
SlowMist
2026-09-19 11:07:07

SlowMist warns DarkSword iOS exploit is now being used in real attacks

SlowMist Chief Information Security Officer 23pds warned iOS users on Sept. 19 to update to the latest system version after saying the DarkSword iOS attack tool, which was leaked in March, is now being used by black-market operators in real-world attacks. According to the alert, attackers can trick users into opening a malicious webpage in Safari, then gradually break out of the browser sandbox and escalate privileges. The attack chain could eventually access keychain data and wallet information, allowing the theft of private keys and seed phrases. 23pds said the suspected affected range is iOS 13 to 26.5, though that scope has not been confirmed.

90
SlowMist warns DarkSword iOS exploit is now being used in real attacks
SlowMist
2026-09-19 10:45:55

SlowMist CSO 23pds warns of full iOS attack chain targeting wallet users

SlowMist Chief Information Security Officer 23pds said in a post on X that cybercriminal groups have built a complete attack chain against iOS users. According to his description, the process can start when a user clicks a link, leading to the extraction of private keys and seed phrases. When a victim opens a webpage in Safari, the attackers can exploit WebKit/JSC memory corruption to gain JavaScript-layer read and write access, bypass Pointer Authentication Code (PAC) protections to obtain native call capability, break out of the WebContent sandbox, and then escalate privileges in the kernel to gain root access. From there, they can pull data from Keychain and wallet storage. 23pds said affected versions range from iOS 13 to 26.5 and urged iOS users to update as soon as possible.

100
SlowMist CSO 23pds warns of full iOS attack chain targeting wallet users
Web3 Security
2026-07-27 10:02:00

Nearly 90% of stolen crypto funds were unrecoverable in H1 2026 as Web3 attacks shifted from code to people

Web3 recorded 182 publicly disclosed security incidents in the first half of 2026, with total losses reaching about $956 million, according to reports released by OKX Web3’s security team, SlowMist and OtterSec. The headline loss figure was down nearly 60% from a year earlier, but the decline mostly reflected the absence of a repeat of Bybit’s roughly $1.5 billion 2025 outlier. Incident count actually rose to 182 from 121, up about 50% year over year. The reports point to a structural shift in how attacks are carried out. The largest losses increasingly came from outside audited smart contracts and instead hit signing flows, cloud keys, validation paths, developer devices and users themselves. Examples cited in the reports include the roughly $285 million Drift Protocol attack, a months-long social engineering campaign centered on pre-signed transactions, and a Singapore case in which AI-generated officials appeared in a fake video conference, leading to losses of about S$4.9 million. Recovery remains rare. SlowMist said only 18 incidents in H1 resulted in stolen funds being recovered or frozen, totaling about $118 million, or 12.3% of overall losses. The rest, nearly 90%, was effectively gone. The reports also describe supply-chain poisoning, AI-assisted phishing, malicious browser extensions, recruiter scams and increasingly industrialized laundering routes involving privacy tools, cross-chain channels and OTC off-ramps.

2080
Nearly 90% of stolen crypto funds were unrecoverable in H1 2026 as Web3 attacks shifted from code to people