SlowMist warns Darksword exploit may now target iOS 26.5 and steal wallet private keys
SlowMist Chief Information Security Officer 23pds said attackers are exploiting the Darksword vulnerability through Safari to bypass iOS security protections, take control of devices, and extract private keys and other data from self-custodied crypto wallets. The flaw had previously been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group had earlier disclosed that Darksword originally affected iOS 18.4 through 18.7. According to 23pds, attackers have now adapted the exploit to iOS 26.5, though that claim has not been officially verified. The attack chain typically starts with social engineering: once a user clicks a malicious link sent through social media or messaging apps, the device may be rooted and wallet data extracted. SlowMist urged users to update their phones promptly and avoid visiting links sent by strangers. Separately, Bitcoin.com News reported that three investors who downloaded fake wallet apps from Apple’s official App Store lost nearly $1.8 million in Bitcoin and have sued Apple.








