SlowMist Still Has Not Confirmed Crypto Theft From iPhone Safari Attack

BTCC
Ledger


Security warnings circulating this week about a malicious iPhone Safari attack have prompted renewed calls for iOS updates—particularly over fears that the exploit could be used to steal crypto wallet secrets. However, SlowMist says it has not yet confirmed a real victim whose device was compromised by the specific Safari sample it analyzed, and it cautions that the initially reported iOS versions affected may be wider than what is technically proven.

In an investigation shared with Cointelegraph, SlowMist said the strongest evidence it has supports impact on iOS 18.4 through iOS 18.6.2, while an oft-cited “iOS 13 to 26.5” range should be treated as preliminary until reproducible proof is available. The firm also highlighted that the Safari campaign reuses techniques from the previously disclosed DarkSword iOS exploit chain, and that it is separate from another SlowMist case involving a malicious component embedded in an App Store application tied to the FomoPeek investigation.

Key takeaways

  • SlowMist has not independently confirmed a crypto theft or a specific confirmed victim tied to the exact Safari sample it examined.
  • The firm’s strongest technical evidence points to iOS versions 18.4 through 18.6.2; broader iOS coverage reported elsewhere is not yet proven.
  • The malicious webpage was designed to trigger an exploit via Safari and, once accessed, target Apple Keychain data and other app storage.
  • SlowMist links the Safari techniques to DarkSword reuse, while emphasizing this Safari campaign is distinct from its earlier FomoPeek App Store-related investigation.
  • SlowMist continues to recommend installing the latest iOS security updates and taking additional precautions such as Apple’s Lockdown Mode and rotating wallet credentials on suspected exposure.

Why the Safari warning is still urgent

The core claim behind the current wave of warnings is that a malicious Safari page could expose crypto private keys and seed phrases. While SlowMist’s analysis supports that the sample includes functionality aimed at collecting sensitive information, it draws a clear line between “capability” and “confirmed success against a particular wallet on a real device.”

SlowMist told Cointelegraph that it has not independently confirmed a victim compromise tied specifically to the Safari attack sample it studied. The company further noted that its investigation did not execute the full exploit chain on a real victim device, limiting the ability to identify an actual endpoint where secrets were successfully extracted.

itrust

That distinction matters for both users and defenders: even without confirmed theft, the presence of a plausible collection mechanism is enough to justify immediate defensive steps—especially because seed phrases and private keys are once-off secrets that can’t be safely “partially” exposed.

DarkSword techniques reused in a WYINCC Safari campaign

SlowMist’s write-up ties the Safari attack’s underlying approach to DarkSword, an iOS exploit chain that was disclosed earlier by Google Threat Intelligence Group (GTIG) in March. According to GTIG, DarkSword had been used by multiple threat actors since at least November 2025.

Google’s disclosure described DarkSword as an iOS exploit chain, and SlowMist said its own threat intelligence team—led by its chief information security officer, 23pds—first identified relevant activity in early May. SlowMist then published its analysis of the WYINCC Safari campaign on Sept. 4.

In this campaign, SlowMist said the malicious webpage appeared to advertise a free virtual private server service. When opened on an iPhone using Safari, the page loaded exploit code. SlowMist’s description indicates that the page could trigger the malicious code without requiring an additional click beyond visiting the page.

Importantly for risk assessment, SlowMist said the vulnerabilities employed in the chain had already been disclosed and patched by Apple. That aligns with the practical takeaway for users: applying the latest iOS updates is the most reliable way to reduce exposure to known, patched weaknesses.

What the sample was built to target

Beyond the delivery mechanism, SlowMist focused on what the malicious Safari sample attempted to access. The firm said the sample included a component designed to interact with Apple’s Keychain and retrieve and decrypt information stored there.

SlowMist also said the code could access app files and shared app data—capabilities that may overlap with information stored by cryptocurrency wallet applications. At the same time, SlowMist stressed that this demonstrates collection capability and intended targets, but does not itself prove successful extraction from every targeted wallet.

In other words, the technical evidence suggests a route to sensitive data. But it doesn’t automatically establish that the exploit would work on every device running the affected versions, nor does it prove that any specific wallet compromise occurred in the wild for this exact sample.

SlowMist also cautioned that it did not run the complete chain on a real victim device, which prevented it from independently identifying a specific confirmed victim whose device was compromised by the exact Safari sample.

How SlowMist frames iOS version risk and what to do next

The most sensitive aspect of the reporting has been the breadth of iOS versions claimed to be affected. Some warnings circulating this week cited a wide range from iOS 13 through iOS 26.5. SlowMist told Cointelegraph it views that range as preliminary and prefers to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence.

SlowMist said its strongest technical evidence covers iOS 18.4 through iOS 18.6.2. For users, the practical implication is straightforward even if the exact upper or lower bounds remain uncertain: anyone on an older iOS version should prioritize upgrading to the latest available security release.

SlowMist still recommended updating iOS and avoiding suspicious links. For users unable to update immediately—or those facing higher exposure risk—it pointed to Apple’s Lockdown Mode as an added defense, while also noting it has not confirmed that Lockdown Mode fully blocks this particular Safari attack.

Finally, SlowMist urged users who suspect their wallet key or seed phrase may have been exposed to move assets to a newly generated wallet created on a clean device, rather than continuing to rely on potentially compromised credentials.

With the iOS version scope still being refined and no confirmed victim tied to the exact sample yet established by SlowMist, the next phase to watch is whether further independent technical validation narrows the affected ranges and whether defenders see confirmed real-world compromises tied to the WYINCC Safari campaign.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure



Source link

Blockonomics

Be the first to comment

Leave a Reply

Your email address will not be published.


*