How to Secure an iPhone Crypto Wallet Against Malware and Web-Based Exploit

Changelly
Blockonomics


iPhone users running outdated iOS versions may face security risks after researchers linked poisoned website packages to an iOS exploit chain capable of accessing protected phone data and wallet secrets. 

Socket, a cybersecurity platform, disclosed the campaign on after finding 13 malicious themes on Packagist. The packages infected websites rather than phones. As a result, avoiding fake wallet apps was not enough to protect a vulnerable iPhone from an affected Safari page.

What Are the Malicious Packagist Packages Designed to Do? 

The packages posed as themes for OphimCMS and KKPhim, which support Vietnamese streaming sites. They appeared under five publishers: vsmov, vsphim, haiau009, chilltvcms, and ophimcms.

After a site operator installed a poisoned theme, hostile JavaScript appeared on its pages. Mobile visitors could receive gambling redirects or injected advertisements. The iPhone branch also checked the iOS version and loaded a matching exploit.

okex

Socket’s investigation found two WebKit entry points. CVE-2025-31277 targeted iOS 18.4 and 18.5. CVE-2025-43529 covered iOS 18.6.

Later stages escaped WebKit’s protected process and reached the iOS kernel. That access allowed the payload to read data normally blocked from a website.

Researchers found code for iPhone XS through iPhone 16 models running iOS 18.4 through 18.6.x. The analyzed version did not support iOS 18.7 or iOS 26.

The spyware could collect Keychain records, messages, contacts, photos, browser cookies, Wi-Fi passwords, location history, and account databases. An August update also searched for wallet material linked to Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX.

Why Do Newer Reports Name Different Crypto Wallets?

A newer SlowMist report examined separate WYINCC infrastructure. Its sample targeted Safari on iOS 18.4 through 18.6.2. The code focused on imToken, TokenPocket, and TronLink.

That payload could search app files, read decrypted Keychain entries, and monitor keyboard input while a targeted wallet was open. SlowMist recovered the functions but did not run them on a victim’s phone.

Therefore, the two wallet lists should remain separate. Socket studied malicious Packagist themes, while SlowMist analyzed another delivery system. Both showed links to the DarkSword exploit family.

Google’s Threat Intelligence Group had tracked DarkSword since November 2025. Google found several variants supporting iOS 18.4 through 18.7. Apple has released patches addressing the exploit chain in later iOS versions.

How Can Users Stop Wallet-Stealing Malware?

Installing the latest iOS update closes the known route. As of September 4, 2026, Apple lists iOS 26.6.1 as its current release. It also offers iOS 18.7.10 for the iPhone XS, XS Max, and XR.

Users can open Settings, select General, and tap Software Update. They should install the newest release offered for their device. Automatic downloads and installations should also be enabled.

People running iOS 26.1 or later can activate Background Security Improvements under Settings and Privacy & Security. This option delivers some WebKit and system protections between full updates.

Patches provide the main defense, while careful browsing lowers further risk. Users should leave sites that trigger gambling pages or repeated redirects. Google added known DarkSword domains to Safe Browsing, but attackers can rotate infrastructure.

Recovery phrases need separate protection. They should not be stored in Photos, Notes, email, chats, or unprotected cloud files. Researchers found that the malware could collect several of those data sources.

An offline backup limits that exposure. Large holders may also use a hardware wallet without importing its seed phrase into the iPhone. Every address and transaction should still be checked on the hardware device.

What Should Users Do After Possible Exposure?

Users should first check which iOS version was active when the page opened. A suspicious redirect alone does not confirm infection. SlowMist also warned against declaring a seed phrase stolen from access records alone.

The iPhone should still be updated immediately. If unauthorized transfers appear or a security review confirms exposure, the owner should create a new crypto wallet on a clean device. Its recovery phrase must be new.

The owner can then move remaining assets to the new addresses after checking the network and destination. Importing the old recovery phrase into another app would preserve the risk.

Users should revoke unknown wallet connections and review active sessions. Apple Account, email, exchange, and financial passwords may need replacement from a trusted device if wider data theft is suspected. Apple also advises users to remove unrecognized devices from their accounts.

Before erasing a high-value device, its owner may need professional mobile forensics because a reset can destroy evidence. SlowMist recommends preserving forensic data from exposed devices. Transaction hashes, wallet addresses, dates, screenshots, and alerts should also be saved.

Victims must avoid anyone promising recovery for an advance payment. Legitimate wallet support would not request a seed phrase or private key. Current software, offline seed storage, and quick action remain the strongest defenses against wallet-stealing malware.

Related: Cronos Network Halts After Tectonic Exploit, What Happens to User Funds?

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.





Source link

Coinmama

Be the first to comment

Leave a Reply

Your email address will not be published.


*