iPhone Safari Attack May Expose Crypto Private Keys
SlowMist has yet to confirm any cryptocurrency theft linked to an iPhone Safari attack. According to reports, malicious Safari pages could expose crypto private keys and seed phrases on iPhones with iOS versions ranging from 13 through 26.5.
SlowMist investigated the issue but couldn't independently confirm a victim compromised by the specific Safari attack sample it analyzed. The company's strongest technical evidence covers iOS 18.4 through 18.6.2, and they caution that the 'iOS 13 to 26.5' range should be treated as preliminary.
The Safari attack reuses techniques from a previously disclosed DarkSword exploit chain. SlowMist found that the malicious sample included a component designed to access Apple's Keychain and retrieve and decrypt information stored there, potentially exposing information stored by crypto wallet applications.
SlowMist recommends updating iOS immediately and avoiding suspicious links. For users who cannot update or face elevated risks, they suggest considering Apple's Lockdown Mode as an additional defense. Users who believe a wallet key or seed phrase may have been exposed are advised to move their assets to a newly generated wallet on a clean device.