SlowMist CISO Warns of Full-Chain iOS Exploit Stealing Crypto Wallet Keys
SlowMist Chief Information Security Officer 23pds issued an urgent warning on September 19, telling iPhone users to update their devices immediately after confirming that attackers have operationalized a full-chain iOS exploit capable…
kucoin.com
Publisher
Sep 20, 2026 at 11:22 AM UTC · 2 Min. Lesezeit

SlowMist Chief Information Security Officer 23pds issued an urgent warning on September 19, telling iPhone users to update their devices immediately after confirming that attackers have operationalized a full-chain iOS exploit capable of silently draining private keys and mnemonic seed phrases from crypto wallets. The disclosure, posted to X by the researcher, spans devices running iOS 13 through iOS 26.5 and represents a serious threat to self-custodied assets held in mobile wallets.
How the exploit chain works
The attack opens when a target visits a malicious webpage in Safari, typically reached through social engineering or a watering-hole link. The page exploits a memory-corruption bug in WebKit and JavaScriptCore to obtain arbitrary read and write access at the JavaScript layer. From there the chain bypasses Pointer Authentication Codes to gain native code execution, escapes the WebContent sandbox, and escalates to kernel-level root privileges — enough to read the device Keychain and pull wallet application data, including private keys and recovery phrases. Unlike a conventional phishing page that tricks a user into typing a seed phrase, this chain requires no action beyond visiting a link, which is why the warning is so urgent.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
