Safari Attack on iPhones May Expose Crypto Private Keys, SlowMist Warns
SlowMist has not confirmed any cryptocurrency theft related to an iPhone Safari attack that has been causing security warnings. The company analyzed a malicious webpage that reused techniques from a previously disclosed exploit chain, DarkSword, which had been used by multiple threat actors since at least November 2025.
The malicious page was designed to access Apple's Keychain and retrieve information stored there, including data from crypto wallet applications. SlowMist found that the vulnerabilities used in the chain were already patched by Apple, but it still recommends updating iOS to prevent potential attacks.
SlowMist has not independently confirmed a victim compromised by the specific Safari attack sample it analyzed, and its strongest technical evidence covers iOS 18.4 through 18.6.2. The company advises iPhone users to update their devices immediately and avoid suspicious links.