Malicious Safari Page Linked to Crypto Theft Through Apple's Keychain
A malicious Safari page has been linked to potential crypto theft through Apple's Keychain and app storage. SlowMist, a security firm, analyzed the attack and found that it reused techniques from an earlier disclosed exploit chain called DarkSword. The attackers used the Safari page to trigger an exploit, which aimed to collect sensitive information such as private keys and seed phrases.
SlowMist's investigation did not confirm any specific victims or successful extraction of secrets, but it did find that the malicious webpage was designed to interact with Apple's Keychain and retrieve and decrypt information stored there. The firm emphasized that this demonstrates collection capability and intended targets, but does not itself prove successful extraction from every targeted wallet.
SlowMist recommends installing the latest iOS security updates, using Apple's Lockdown Mode, and rotating wallet credentials on suspected exposure. The firm also cautioned that its strongest technical evidence covers iOS 18.4 through iOS 18.6.2, while a broader range of affected iOS versions has been reported elsewhere.