SlowMist warns Darksword may target wallets on iOS 26.5

by · crypto.news

SlowMist has warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5 and extract private keys from self-custody crypto wallets.

Summary

  • Darksword attacks can begin when an iPhone user opens a malicious link in Safari.
  • SlowMist says attackers may have adapted the exploit chain to iOS 26.5.
  • Google previously confirmed Darksword activity against iOS 18.4 through iOS 18.7.
  • Three U.S. investors separately allege fake wallet apps caused $1.835 million in Bitcoin losses.

SlowMist Chief Information Security Officer 23pds said attackers are using Darksword to bypass Apple’s security controls, gain extensive access to affected iPhones, and collect data from locally installed cryptocurrency wallets.

The reported iOS 26.5 exposure has not been independently confirmed by Apple or Google. Google Threat Intelligence Group’s published research documented support for iOS versions 18.4 through 18.7, while 23pds said attackers have since modified the tool to work against the newer operating system.

Darksword may reach iOS 26.5 devices

Google’s Threat Intelligence Group identified Darksword as a full iOS exploit chain that combines six vulnerabilities to compromise devices and deliver separate malicious payloads. The company tracked related activity from at least December 2025 through March 2026.

According to Google, the original framework supported iOS 18.4 through iOS 18.7. One flaw used against iOS 18.6 to 18.7 devices, tracked as CVE-2025-43529, affected JavaScriptCore, the engine that processes JavaScript in Safari. Apple patched the flaw in iOS 18.7.3 and iOS 26.2 after Google reported it.

SlowMist’s latest assessment extends the potential exposure to iOS 26.5, although the security company’s claim has not received official confirmation. No technical analysis cited in the warning established which vulnerability or replacement exploit could let Darksword compromise the newer release.

Attackers generally initiate the compromise through social engineering, according to 23pds. A target receives a link through a social network, messaging app, or another communication channel and opens the page in Safari. Malicious web content then attempts to exploit the browser and other iOS components without requiring the user to install a conventional application.

Once the chain succeeds, the attacker may obtain root-level control, 23pds said. Such access can remove the isolation that normally prevents one application from reading files and credentials belonging to another, placing private keys and other wallet records stored on the device at risk.

Malicious Safari links can expose wallet data

Google found several groups using Darksword with different final-stage payloads, rather than one fixed piece of malware. Depending on the campaign, the payloads could collect account details, messages, browser records, files, location history, saved Wi-Fi data and information linked to cryptocurrency wallets.

The security company connected separate operations to victims in Saudi Arabia, Turkey, Malaysia and Ukraine. Google associated some activity with commercial surveillance providers and suspected state-linked groups, while researchers also found signs that financially motivated actors had gained access to advanced iPhone exploitation tools.

No victim total or confirmed amount of cryptocurrency stolen through Darksword was included in the material supplied by SlowMist. The warning instead focused on the framework’s ability to reach wallet information after compromising the device that stores it.

A similar delivery method appeared in an earlier mobile threat. In March, crypto.news covered Google’s findings on Coruna, an exploit kit containing 23 vulnerabilities across five attack chains. Coruna targeted iPhones running versions from iOS 13 through iOS 17.2.1 and could search files and images for terms such as “backup phrase” and “bank account.”

Google researchers said Coruna fingerprinted a visitor’s device before selecting an exploit suited to the iPhone model and software version. Some operators placed the kit on fake gambling and cryptocurrency sites, allowing the compromise to begin when a target loaded the page.

Recent iOS threats have targeted private keys

Darksword is not the only recent security threat involving cryptocurrency data on Apple devices. Binance warned iPhone and iPad users on Sep. 19 about malicious code found in FomoPeek versions 1.1 and 1.2.

Researchers examining the app found a kernel exploitation framework with eight attack methods and declared support covering iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1. The malicious modules could escape the iOS sandbox, decrypt Keychain data, and access private keys, wallet recovery phrases, account credentials, and files held by other applications, according to a report on FomoPeek.

Binance advised anyone who had installed the affected versions to remove the app, update iOS, and avoid reinstalling it. Self-custody users were also told to create a new wallet on a clean device and transfer their assets, since deleting a malicious app would not protect a wallet if its private key or recovery phrase had already been copied.

Darksword uses a different route because its documented campaigns rely on malicious or compromised websites. Both cases, however, involve attempts to defeat the controls that ordinarily prevent software from obtaining sensitive records held elsewhere on an iPhone.

SlowMist advised users to install mobile operating-system updates promptly and avoid opening unsolicited links sent by strangers. Google and Apple have also treated current software as a central defense because Apple has patched the six vulnerabilities documented in the original Darksword chain.

U.S. investors have also sued Apple over fake wallets

For U.S. crypto holders, the Darksword warning follows a separate dispute over malicious wallet software distributed through Apple’s official marketplace. Three investors filed a federal lawsuit alleging that fake applications impersonating Sparrow Wallet appeared in the App Store and caused about $1.835 million in Bitcoin losses, according to earlier court coverage.

The plaintiffs’ allegations concern fraudulent applications rather than a browser-based exploit. Their case nevertheless centers on the security of Apple’s mobile distribution system and the financial damage that can occur when users trust software presented as a legitimate cryptocurrency wallet.

Another counterfeit application posing as Ledger Live allegedly stole at least $9.5 million from more than 50 victims between April 7 and April 13. Blockchain investigator ZachXBT traced funds from Bitcoin, Ethereum, Solana, Tron, and XRP users to more than 150 KuCoin deposit addresses and a mixing service.

The fake Ledger application asked users to enter their 24-word recovery phrases during what appeared to be a standard wallet setup. Apple later removed the listing, while one victim said he downloaded it while configuring a Ledger device on a new MacBook.

Unlike the Darksword chain, the fraudulent Ledger app did not need to break the operating system’s security controls. Users exposed their wallets by entering recovery phrases into the impersonating software, giving its operators control of every address derived from those phrases.