Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News

    SlowMist Still Hasn’t Confirmed Crypto Theft From iPhone Safari Attack

    15 seconds ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Slowmist Still Hasn’t Confirmed Crypto Theft From Iphone Safari Attack
    Slowmist Still Hasn’t Confirmed Crypto Theft From Iphone Safari Attack

    New warnings circulating among iPhone users link a malicious Safari-based attack to a potential exposure of cryptocurrency wallet secrets, including private keys and seed phrases. However, the threat intelligence firm that analyzed the specific Safari sample says it has not been able to independently confirm an actual theft from a compromised victim tied to that exact code.

    In a statement provided to Cointelegraph, SlowMist said the campaign it investigated appears to reuse techniques from an earlier iOS exploit chain known as DarkSword. While multiple reports urged users to update immediately and cited an especially broad iOS window—“iOS 13 through iOS 26.5” in some coverage—SlowMist cautioned that this range should be treated as preliminary until the company can demonstrate reproducible technical evidence for the latest versions.

    Key takeaways

    • SlowMist has not independently confirmed a real victim compromise or confirmed crypto theft tied to the exact Safari sample it analyzed.
    • The strongest technical evidence from SlowMist focuses on iOS 18.4 through 18.6.2.
    • SlowMist says the suspected Safari exploit chain reuses techniques from Google-disclosed DarkSword, rather than being the same as the separate FomoPeek incident.
    • The analyzed malware includes functionality aimed at reading and decrypting data from Apple Keychain, which can contain sensitive wallet-related information.
    • Even without proof of a successful extraction on every targeted device, SlowMist still recommends updating iOS and avoiding suspicious links.

    Why the iPhone warnings remain uncertain

    Multiple reports this week prompted immediate iOS updates, warning that malicious Safari pages could potentially expose crypto private keys and seed phrases. Some of those reports referenced a wide range of iOS versions, extending from iOS 13 to iOS 26.5.

    SlowMist’s assessment is more restrained. The company told Cointelegraph that it has not independently verified a victim device compromised by the particular Safari attack sample it reviewed. It also indicated that the iOS range appearing in public warnings may be broader than what it can technically support right now.

    In particular, SlowMist said it “prefer[s] to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence,” and noted its strongest evidence spans iOS 18.4 through 18.6.2. That distinction matters for users and organizations because overbroad impact claims can either create unnecessary fear on unexposed versions or, conversely, obscure where defenses should be prioritized first.

    What SlowMist says was reused from DarkSword

    The Safari campaign is not being treated by SlowMist as an entirely new exploitation method. According to SlowMist, the attack reuses techniques from DarkSword, an iOS exploit chain disclosed by Google’s Threat Intelligence Group (GTIG) in March. Google described DarkSword as having been used by multiple threat actors since at least November 2025, and documented the exploit chain publicly in a dedicated threat intelligence post.

    SlowMist said its own MistEye threat intelligence team—led by chief information security officer 23pds—first identified relevant activity in early May. Later, SlowMist published its analysis of the “WYINCC” Safari campaign on Sept. 4, describing how the malicious page presented a lure related to a free virtual private server service.

    SlowMist reported that when the page was opened in Safari on an iPhone, the exploit code could load without necessarily requiring an additional user click. Apple later patched the vulnerabilities used in the chain, and SlowMist stated that those underlying weaknesses had already been disclosed and fixed.

    Importantly, SlowMist also separated this issue from a different investigation it previously ran regarding FomoPeek—an iOS App Store-related incident described in earlier Cointelegraph coverage. SlowMist characterized the Safari attack as distinct from that separate App Store compromise vector.

    Targets inside the device: Apple Keychain and wallet exposure

    Beyond the exploit mechanism, SlowMist highlighted what the malicious sample was trying to access. In its analysis of the sample, the firm said the code included capabilities to interact with Apple’s Keychain—retrieving and decrypting information stored there. SlowMist added that the code could also access app files and shared app data, which could potentially include sensitive data handled by crypto wallet applications.

    At the same time, SlowMist emphasized limits in what can be proven from static or controlled analysis. The company said the sample “demonstrates the collection capability and the intended targets,” but does not automatically prove successful extraction from every wallet or every targeted device.

    Critically, SlowMist said it did not execute the full chain on a real victim device, which is why it cannot identify a specific victim whose device it independently confirmed was successfully compromised by that exact sample.

    Recommendations: update, avoid links, and move funds if exposed

    Even with those uncertainties, SlowMist urged iPhone users to take practical defensive steps. The firm advised updating to the latest iOS security updates available for affected devices and avoiding suspicious links—especially those delivered via unsolicited messages or pages that promise free services.

    For users who cannot update immediately or who face elevated risk, SlowMist pointed to Apple’s Lockdown Mode as an additional layer of defense. However, the company cautioned that it has not confirmed Lockdown Mode fully blocks this specific Safari attack.

    SlowMist also offered guidance for wallet users who believe their credentials may have been compromised. Its recommendation was to move assets to a newly generated wallet created on a clean device rather than continuing to use potentially exposed private keys or seed phrases.

    As more technical details become available, the key question for investors, traders, and wallet users is whether reproducible evidence will narrow the affected iOS versions further—and whether researchers can confirm how often, and under what conditions, the Keychain access successfully results in usable wallet secret extraction on real devices. For now, the safest approach remains the straightforward one highlighted by SlowMist: update promptly, be cautious with Safari links, and treat any suspected seed or key exposure as a reason to rotate credentials immediately.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Wall Street And Crypto Brace For Battle Over The Same Turf

    Wall Street and Crypto Brace for Battle Over the Same Turf

    1 hour ago
    Company Moves To Secure Shareholder Approval For Daily Preferred Dividends

    Company Moves to Secure Shareholder Approval for Daily Preferred Dividends

    2 hours ago
    Sec Clarifies Crypto Asset Rules For Staking Tokens And Projects

    SEC Clarifies Crypto Asset Rules for Staking Tokens and Projects

    3 hours ago
    Ex-Cftc Official Steps Down From Blockchain Association After Clarity Vote

    Ex-CFTC Official Steps Down from Blockchain Association After CLARITY Vote

    3 hours ago
    Og.com Files For Cftc Approval To Launch Single-Stock Perps

    OG.com Files for CFTC Approval to Launch Single-Stock Perps

    4 hours ago
    Ex-Cftc Official Exits Blockchain Association After Clarity Vote Fails

    Ex-CFTC Official Exits Blockchain Association After CLARITY Vote Fails

    5 hours ago

    Search Crypto News

    Featured Crypto News

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available For Crypto Executives, Investors And Vip Guests

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available for Crypto Executives, Investors and VIP Guests

    7 September 2026

    Latest News

    • SlowMist Still Hasn’t Confirmed Crypto Theft From iPhone Safari Attack
    • Wall Street and Crypto Brace for Battle Over the Same Turf
    • Company Moves to Secure Shareholder Approval for Daily Preferred Dividends
    • SEC Clarifies Crypto Asset Rules for Staking Tokens and Projects
    • Ex-CFTC Official Steps Down from Blockchain Association After CLARITY Vote
    • OG.com Files for CFTC Approval to Launch Single-Stock Perps
    • Ex-CFTC Official Exits Blockchain Association After CLARITY Vote Fails
    • OG.com Pursues CFTC Approval to Launch Single-Stock Perpetual Futures
    • Bitget Updates: $388M Affected After Security Breach Clarified
    • Death of Former Hack VC Partner Hsin-Ju Chuang Ruled Suicide

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Ledger

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!