Malicious Safari Attack May Expose Crypto Wallet Secrets
iPhone users have been warned about a potential exposure of cryptocurrency wallet secrets due to a malicious Safari-based attack. However, SlowMist, the threat intelligence firm that analyzed the specific Safari sample, has not independently confirmed an actual theft from a compromised victim tied to that exact code.
The suspected Safari exploit chain reuses techniques from an earlier iOS exploit chain known as DarkSword, which was disclosed by Google's Threat Intelligence Group (GTIG) in March. SlowMist's analysis found that the malicious sample included capabilities to interact with Apple's Keychain and access app files and shared app data, potentially exposing sensitive wallet-related information.
SlowMist has emphasized limits in what can be proven from static or controlled analysis, stating that it did not execute the full chain on a real victim device. The company urged iPhone users to update to the latest iOS security updates available for affected devices and avoid suspicious links, especially those delivered via unsolicited messages or pages that promise free services.
For wallet users who believe their credentials may have been compromised, SlowMist recommends moving assets to a newly generated wallet created on a clean device rather than continuing to use potentially exposed private keys or seed phrases. The company has not confirmed Lockdown Mode fully blocks this specific Safari attack, but it is still being recommended as an additional layer of defense.