Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News

    SlowMist Still Has Not Confirmed Crypto Theft From iPhone Safari Attack

    14 seconds ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Slowmist Still Has Not Confirmed Crypto Theft From Iphone Safari Attack
    Slowmist Still Has Not Confirmed Crypto Theft From Iphone Safari Attack

    Security warnings circulating this week about a malicious iPhone Safari attack have prompted renewed calls for iOS updates—particularly over fears that the exploit could be used to steal crypto wallet secrets. However, SlowMist says it has not yet confirmed a real victim whose device was compromised by the specific Safari sample it analyzed, and it cautions that the initially reported iOS versions affected may be wider than what is technically proven.

    In an investigation shared with Cointelegraph, SlowMist said the strongest evidence it has supports impact on iOS 18.4 through iOS 18.6.2, while an oft-cited “iOS 13 to 26.5” range should be treated as preliminary until reproducible proof is available. The firm also highlighted that the Safari campaign reuses techniques from the previously disclosed DarkSword iOS exploit chain, and that it is separate from another SlowMist case involving a malicious component embedded in an App Store application tied to the FomoPeek investigation.

    Key takeaways

    • SlowMist has not independently confirmed a crypto theft or a specific confirmed victim tied to the exact Safari sample it examined.
    • The firm’s strongest technical evidence points to iOS versions 18.4 through 18.6.2; broader iOS coverage reported elsewhere is not yet proven.
    • The malicious webpage was designed to trigger an exploit via Safari and, once accessed, target Apple Keychain data and other app storage.
    • SlowMist links the Safari techniques to DarkSword reuse, while emphasizing this Safari campaign is distinct from its earlier FomoPeek App Store-related investigation.
    • SlowMist continues to recommend installing the latest iOS security updates and taking additional precautions such as Apple’s Lockdown Mode and rotating wallet credentials on suspected exposure.

    Why the Safari warning is still urgent

    The core claim behind the current wave of warnings is that a malicious Safari page could expose crypto private keys and seed phrases. While SlowMist’s analysis supports that the sample includes functionality aimed at collecting sensitive information, it draws a clear line between “capability” and “confirmed success against a particular wallet on a real device.”

    SlowMist told Cointelegraph that it has not independently confirmed a victim compromise tied specifically to the Safari attack sample it studied. The company further noted that its investigation did not execute the full exploit chain on a real victim device, limiting the ability to identify an actual endpoint where secrets were successfully extracted.

    That distinction matters for both users and defenders: even without confirmed theft, the presence of a plausible collection mechanism is enough to justify immediate defensive steps—especially because seed phrases and private keys are once-off secrets that can’t be safely “partially” exposed.

    DarkSword techniques reused in a WYINCC Safari campaign

    SlowMist’s write-up ties the Safari attack’s underlying approach to DarkSword, an iOS exploit chain that was disclosed earlier by Google Threat Intelligence Group (GTIG) in March. According to GTIG, DarkSword had been used by multiple threat actors since at least November 2025.

    Google’s disclosure described DarkSword as an iOS exploit chain, and SlowMist said its own threat intelligence team—led by its chief information security officer, 23pds—first identified relevant activity in early May. SlowMist then published its analysis of the WYINCC Safari campaign on Sept. 4.

    In this campaign, SlowMist said the malicious webpage appeared to advertise a free virtual private server service. When opened on an iPhone using Safari, the page loaded exploit code. SlowMist’s description indicates that the page could trigger the malicious code without requiring an additional click beyond visiting the page.

    Importantly for risk assessment, SlowMist said the vulnerabilities employed in the chain had already been disclosed and patched by Apple. That aligns with the practical takeaway for users: applying the latest iOS updates is the most reliable way to reduce exposure to known, patched weaknesses.

    What the sample was built to target

    Beyond the delivery mechanism, SlowMist focused on what the malicious Safari sample attempted to access. The firm said the sample included a component designed to interact with Apple’s Keychain and retrieve and decrypt information stored there.

    SlowMist also said the code could access app files and shared app data—capabilities that may overlap with information stored by cryptocurrency wallet applications. At the same time, SlowMist stressed that this demonstrates collection capability and intended targets, but does not itself prove successful extraction from every targeted wallet.

    In other words, the technical evidence suggests a route to sensitive data. But it doesn’t automatically establish that the exploit would work on every device running the affected versions, nor does it prove that any specific wallet compromise occurred in the wild for this exact sample.

    SlowMist also cautioned that it did not run the complete chain on a real victim device, which prevented it from independently identifying a specific confirmed victim whose device was compromised by the exact Safari sample.

    How SlowMist frames iOS version risk and what to do next

    The most sensitive aspect of the reporting has been the breadth of iOS versions claimed to be affected. Some warnings circulating this week cited a wide range from iOS 13 through iOS 26.5. SlowMist told Cointelegraph it views that range as preliminary and prefers to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence.

    SlowMist said its strongest technical evidence covers iOS 18.4 through iOS 18.6.2. For users, the practical implication is straightforward even if the exact upper or lower bounds remain uncertain: anyone on an older iOS version should prioritize upgrading to the latest available security release.

    SlowMist still recommended updating iOS and avoiding suspicious links. For users unable to update immediately—or those facing higher exposure risk—it pointed to Apple’s Lockdown Mode as an added defense, while also noting it has not confirmed that Lockdown Mode fully blocks this particular Safari attack.

    Finally, SlowMist urged users who suspect their wallet key or seed phrase may have been exposed to move assets to a newly generated wallet created on a clean device, rather than continuing to rely on potentially compromised credentials.

    With the iOS version scope still being refined and no confirmed victim tied to the exact sample yet established by SlowMist, the next phase to watch is whether further independent technical validation narrows the affected ranges and whether defenders see confirmed real-world compromises tied to the WYINCC Safari campaign.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Doublezero Launches Fiber Market Data Feed For Hyperliquid Traders

    DoubleZero Launches Fiber Market Data Feed for Hyperliquid Traders

    1 hour ago
    Kelpdao Files Lawsuit Against Layerzero, Ceo Over $292m Rseth Exploit

    KelpDAO Files Lawsuit Against LayerZero, CEO Over $292M rsETH Exploit

    2 hours ago
    Kelpdao Files Lawsuit Against Layerzero, Ceo Over $292m Rseth Exploit

    KelpDAO Files Lawsuit Against LayerZero, CEO Over $292M rsETH Exploit

    3 hours ago
    Us Weighs Overseas Expansion Of Dollar-Backed Stablecoins, Bloomberg

    US Weighs Overseas Expansion of Dollar-Backed Stablecoins, Bloomberg

    4 hours ago
    Samourai Wallet Co-Founder’s New Transfer Followed 30-Day Hold

    Samourai Wallet Co-Founder’s New Transfer Followed 30-Day Hold

    4 hours ago
    Samourai Wallet Co-Founder Hits New Transfer After 30-Day Delay

    Samourai Wallet Co-Founder Hits New Transfer After 30-Day Delay

    5 hours ago

    Search Crypto News

    Featured Crypto News

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available For Crypto Executives, Investors And Vip Guests

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available for Crypto Executives, Investors and VIP Guests

    7 September 2026

    Latest News

    • SlowMist Still Has Not Confirmed Crypto Theft From iPhone Safari Attack
    • DoubleZero Launches Fiber Market Data Feed for Hyperliquid Traders
    • KelpDAO Files Lawsuit Against LayerZero, CEO Over $292M rsETH Exploit
    • KelpDAO Files Lawsuit Against LayerZero, CEO Over $292M rsETH Exploit
    • US Weighs Overseas Expansion of Dollar-Backed Stablecoins, Bloomberg
    • Samourai Wallet Co-Founder’s New Transfer Followed 30-Day Hold
    • Samourai Wallet Co-Founder Hits New Transfer After 30-Day Delay
    • Bitget Says $352M Security Incident Hit Hot Wallets; Withdrawals Paused
    • Researchers Explore Zcash-Style Private Bitcoin Transfers Without Soft Fork
    • Fed Outlines New Capital and Redemption Rules for Stablecoin Issuers

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    AVATRADE

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Crypto.com
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!