Slowmist Warns Darksword iOS Exploit Targets Crypto Wallet Keys

By Bitcoin News | Created at 2026-09-21 19:17:03 | Updated at 2026-09-21 20:21:56 1 hour ago
  1. News
  2. Security
  3. Slowmist Warns Darksword iOS Exploit Targets Crypto Wallet Keys

Published:Sep 21, 2026, 3:15 PM EDT

23pds, Chief Information Security Officer at Slowmist, reported the evolution of this exploit, which, due to the combination of several techniques, allows threat actors to steal wallet private keys and other data. Users must update their phones to the latest software version to avoid being targeted.

Published: Sep 21, 2026, 3:15 PM EDT

Slowmist Warns Darksword iOS Exploit Targets Crypto Wallet Keys

Key Takeaways

  • Hackers use the Darksword exploit via Safari to breach iOS security and drain self-custody crypto wallets.
  • Slowmist warns the exploit now targets newer iOS versions, vastly widening the threat to more mobile users.
  • Apple faces a lawsuit from three investors who lost $1.8M in BTC due to a fake wallet app on the App Store.

iPhone Face One Click Full Wallet Control Hack Exploit

iOS, the system used by all iPhones, Apple’s line of mobile phones, is being actively targeted by crypto threat actors.

23pds, Chief Information Security Officer (CISO) at Slowmist, revealed that hackers had been taking advantage of security vulnerabilities available in iOS via browsers to take control and steal funds from self-custody wallets installed on these devices.

He stressed that threat actors are using the Darksword exploit, first brought to the spotlight by the Google Threat Intelligence Group (GTIG) in March, for this task. Darksword had been used in several campaigns against users in Saudi Arabia, Turkey, Malaysia, and Ukraine.

Nonetheless, while Google reported that these attacks were only effective against iOS versions 18.4 through 18.7, 23pds disclosed that hackers had adapted Darksword to be effective against recent iOS versions (iOS 26.5), making it a far more dangerous exploit and widening the target audience. Nonetheless, this assessment has not been officially verified.

The attack likely starts with social engineering, as threat actors invite users to visit an exploited link using Safari, iOS’s default browser. Through a single click, the exploit takes control of the device and escapes established control safety measures, reaching root permissions and extracting wallet data and personal keys stored on the device.

To avoid becoming a victim of these exploits, users must update to the latest software version on their phones and avoid visiting sites suggested by unknown people on social media or messaging apps.

The alleged exploit comes as Apple is facing legal action from three investors who lost nearly $1.8 million in BTC after downloading a fake wallet app from Apple’s official App Store. The lawsuit alleges that Apple failed to enforce security standards and seeks reimbursement and compensation for the damages suffered.

Read Entire Article