iPhone Safari Flaw Exposes Crypto Keys to Hackers
A critical security flaw has been discovered in Safari on iPhone devices, allowing hackers to steal private crypto keys and seed phrases without needing a password. The issue affects iOS versions 13 to 26.5 and allows attackers to exploit memory corruption in WebKit and JavaScriptCore to gain arbitrary read/write at the JavaScript level.
The researcher, 23pds, described the capability as clicking a link to steal private keys and mnemonics. This iPhone security flaw can also steal Keychain contents, files, wallet secrets, and capture keystrokes when the wallet is in the foreground.
For crypto holders, the damage is irreversible once keys are taken. The greatest risk lies with retail investors who store seed phrases in screenshots or Apple Notes, or keep sensitive documents stored in iCloud.