A fraudulent website posing as an official Apple preorder page for the upcoming iPhone Duo is attempting to break into vulnerable iPhones and steal cryptocurrency wallet data, saved credentials, and personal files, security researchers warn.
Fake iPhone Duo Preorder Site Uses DarkSword Exploit to Steal Crypto Wallets
A fraudulent website posing as an iPhone Duo preorder page reportedly used a DarkSword exploit to target visitors’ cryptocurrency wallets. The scheme highlights the risk of crypto theft through spoofed product-launch websites.
finance.biggo.com
Publisher
Sep 30, 2026 at 6:18 PM UTC · Updated il y a 18 minutes · 2 min de lecture

Malwarebytes identified the scam page, which mimics Apple's branding with similar fonts and a countdown timer to create a false sense of urgency. The site promises a $500 voucher and early access to iPhone Duo preorders under the label "Authorized Partner Exclusive." One telltale sign of the fraud: the countdown timer resets every time the page is refreshed.
Behind the polished facade, the page deploys the DarkSword exploit chain, which targets older iPhones that have not been patched. Crucially, the attack requires no user interaction. Simply opening the page is enough to trigger the attempt, researchers said.
If the exploit succeeds, a separate payload begins harvesting device identifiers and status information, then attempts to transmit a list of installed apps and the contents of Apple Notes. The malware then shifts focus to cryptocurrency wallets, scanning for MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper. It also tries to recover saved credentials from the phone's keychain.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
