SlowMist Warns of Malicious iPhone Safari Attack Targeting Crypto Wallets
A malicious iPhone Safari attack has raised concerns about crypto wallet security, prompting SlowMist to investigate and offer recommendations for users.
The firm analyzed a sample of the exploit and found that it reused techniques from the DarkSword iOS exploit chain, which was disclosed by Google Threat Intelligence Group in March. The malicious webpage appeared to advertise a free virtual private server service, but upon loading, it triggered the exploit code without requiring an additional click.
The sample targeted Apple's Keychain and accessed app files and shared app data, potentially exposing sensitive information such as crypto private keys and seed phrases. However, SlowMist emphasized that this demonstrates collection capability, not necessarily successful extraction from every targeted wallet.
The firm has not independently confirmed a victim compromise tied to the exact Safari sample it studied, but recommends installing the latest iOS security updates and taking additional precautions such as Apple's Lockdown Mode and rotating wallet credentials on suspected exposure. SlowMist also cautioned that the affected iOS version range is still being refined, with its strongest technical evidence covering iOS 18.4 through iOS 18.6.2.