iPhone Attack Allows Thieves to Steal Crypto Wallet Data in Seconds
Crypto holders have been warned about a sophisticated iPhone attack that can compromise their devices via a malicious page in the Safari browser. The attack, known as DarkSword, is being used in real-world attacks and has been exploited by multiple threat actors since at least November 2025.
The malware can break through Apple's security protections before gaining deep access to an iPhone, allowing attackers to steal sensitive information including credentials and cryptocurrency wallet data. Charles Guillemet, Ledger Chief Technology Officer, warned that users who keep their seed phrases or other sensitive wallet information on their iPhones should reconsider this setup.
Guillemet specifically warned that attackers could use such access to extract wallet information, advising against storing recovery phrases in screenshots, notes, or cloud-synced files. To mitigate the risk, he recommended using a hardware wallet and updating iOS, as Google's Threat Intelligence Group had disclosed all six flaws related to DarkSword had been fixed by the release of iOS 26.3.