Security firm SlowMist has not confirmed cryptocurrency theft linked to a specific iPhone Safari attack, despite reports of potential exposure of private keys. The firm's analysis, which covers iOS versions 18.4 through 18.6.2, indicates the attack reuses techniques from a previously disclosed exploit chain and targets Apple's Keychain.
While direct confirmation of crypto theft from this specific Safari attack remains pending, the potential for attackers to access sensitive information like private keys and seed phrases via exploits targeting widely used devices like iPhones poses a significant risk to cryptocurrency holders.
Security firm SlowMist has stated it has not yet confirmed cryptocurrency theft resulting from a specific iPhone Safari attack, despite widespread warnings to users. Reports this week suggested that malicious Safari pages could expose crypto private keys and seed phrases across a range of iOS versions, from 13 up to 26.5.
SlowMist clarified that its strongest technical evidence pertains to iOS versions 18.4 through 18.6.2, and it prefers to avoid confirming the broader range until reproducible technical evidence is available. The company noted that the attack reuses techniques from a previously disclosed DarkSword exploit chain, identified by Google Threat Intelligence Group in March as being used by multiple threat actors since at least November 2025.
The Safari attack, identified by SlowMist's MistEye threat intelligence team in early May, involves a malicious webpage that loads exploit code when opened in Safari on an iPhone, potentially without requiring an additional user click. The vulnerabilities exploited had already been disclosed and patched by Apple. SlowMist's analysis indicated the malicious sample was designed to access Apple's Keychain and potentially retrieve information stored by crypto wallet applications, though it stressed this capability does not prove successful extraction from every targeted wallet.
Despite the limitations in confirming a specific victim's compromise with the exact sample, SlowMist strongly advises iPhone users to install the latest iOS security updates, avoid suspicious links, and consider using Apple's Lockdown Mode for added protection. For those who believe their wallet keys or seed phrases may have been exposed, SlowMist recommends moving assets to a new wallet on a clean device.
Pick the topics you care about. Get only what matters, on your cadence.