CONNECT WITH US
Web3 & Blockchain

Web3 & Blockchain

SlowMist has yet to confirm crypto theft from iPhone Safari attack

Cointelegraph logo

Published on

Add as a preferred source on Google
SlowMist has yet to confirm crypto theft from iPhone Safari attack

The analyzed Safari sample targets iOS 18.4–18.6.2 using previously patched flaws, while its effectiveness on iOS 26.5 remains unverified.

An iPhone Safari attack behind recent security warnings hasn’t yet been linked to a confirmed cryptocurrency theft in SlowMist’s investigation.

Multiple reports surfaced this week urging iPhone users to update their devices immediately and warning that malicious Safari pages could expose crypto private keys and seed phrases, with some citing a range from iOS 13 through iOS 26.5.

SlowMist told Cointelegraph that it has not independently confirmed a victim compromised by the specific Safari attack sample it analyzed, while its strongest technical evidence covers iOS 18.4 through 18.6.2.

The company said the “iOS 13 to 26.5” range should be treated as preliminary. “We therefore prefer to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence,” it said.

The Safari attack reuses techniques from a previously disclosed DarkSword exploit chain and is separate from FomoPeek, another SlowMist investigation involving malicious components embedded in an App Store app.

Google Threat Intelligence Group (GTIG) disclosed DarkSword in March, describing it as an iOS exploit chain that had been used by multiple threat actors since at least November 2025.

SlowMist said MistEye, a threat intelligence team led by its chief information security officer, 23pds, first identified the relevant activity in early May.

SlowMist published its analysis of the WYINCC Safari campaign on Sept. 4, identifying a malicious webpage advertising a free virtual private server service.

SlowMist said the page loaded the exploit code when opened on an iPhone using Safari, without necessarily requiring another click from the user.


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We TheMorningPulse.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It's possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.