Slowmist Warns Darksword iOS Exploit Targets Crypto Wallet Keys
iOS, the system used by all iPhones, Apple’s line of mobile phones, is being actively targeted by crypto threat actors.
Cryptonews.net
Publisher
Sep 21, 2026 at 10:29 PM UTC · Updated vor 19 Stunden · 1 Min. Lesezeit

Key Signal
iOS 18.4-18.7 Reported vulnerable iOS range
Last Updated
vor 19 Stunden
iOS, the system used by all iPhones, Apple’s line of mobile phones, is being actively targeted by crypto threat actors.
23pds, Chief Information Security Officer (CISO) at Slowmist, revealed that hackers had been taking advantage of security vulnerabilities available in iOS via browsers to take control and steal funds from self-custody wallets installed on these devices.
He stressed that threat actors are using the Darksword exploit, first brought to the spotlight by the Google Threat Intelligence Group (GTIG) in March, for this task. Darksword had been used in several campaigns against users in Saudi Arabia, Turkey, Malaysia, and Ukraine.
Nonetheless, while Google reported that these attacks were only effective against iOS versions 18.4 through 18.7, 23pds disclosed that hackers had adapted Darksword to be effective against recent iOS versions (iOS 26.5), making it a far more dangerous exploit and widening the target audience. Nonetheless, this assessment has not been officially verified.
The attack likely starts with social engineering, as threat actors invite users to visit an exploited link using Safari, iOS’s default browser. Through a single click, the exploit takes control of the device and escapes established control safety measures, reaching root permissions and extracting wallet data and personal keys stored on the device.
Market Context
Bitcoin
BTC
$86,486
+0.49% (24H)
Market Cap
$1.73T
Circulating Supply
20.1M BTC
24H Volume
$46.7B
24H High
$87,447
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
