‹ BackNewsCrypto Wallets

Crypto Wallets

SlowMist CISO says Apple update may have fixed zero-day used to steal crypto wallets
SlowMist’s Cos warns older iOS versions are being used to steal crypto wallets
U.S. Senate report says 84% of sanctioned Iran-linked wallets transacted in USDT
SlowMist
2026-09-25 12:19:34

SlowMist says no confirmed crypto theft tied to investigated iPhone Safari attack

SlowMist said it has not independently confirmed any cryptocurrency theft caused by the specific iPhone Safari attack sample behind recent security warnings, even as reports urged users to update their devices and warned that malicious webpages could expose private keys and seed phrases. According to the blockchain security firm, the strongest technical evidence it has so far applies to iOS 18.4 through 18.6.2, while broader claims that the issue affects devices from iOS 13 to iOS 26.5 should still be treated as preliminary. SlowMist said it does not want to state that iOS 26.5 is affected without reproducible technical evidence. The company added that the Safari attack reuses methods from the previously disclosed DarkSword exploit chain and is separate from FomoPeek, another SlowMist investigation involving malicious components hidden in an App Store app. Its analysis found that the malicious sample was built to access Apple Keychain, retrieve and decrypt stored data, and read app files and shared app data that could include information from crypto wallet apps. Even so, SlowMist said the sample shows collection capability and intended targets, not proof of successful extraction from every targeted wallet. The firm still advised users to install the latest iOS security updates, avoid suspicious links, consider Lockdown Mode if they face higher risk, and move assets to a newly generated wallet on a clean device if they suspect their keys or seed phrases may have been exposed.

310
SlowMist says no confirmed crypto theft tied to investigated iPhone Safari attack
FBI, Japanese police tie $10.7 million crypto theft campaign to North Korean group WaterPlum
North Korean hacking group WaterPlum posed as recruiters and stole $10.7 million in crypto
North Korean group WaterPlum posed as recruiters to deliver malware
Multinational warning says North Korea-linked hackers used fake crypto and AI job offers to target developers