SlowMist is warning that the Darksword iPhone exploit chain may now reach newer iOS builds and expose wallet data, a reminder that self-custody is powerful, but a phone is still a very tempting place for thieves to go hunting.
- SlowMist says Darksword may now target newer iOS builds
- Wallet secrets, not just generic data, are the prize
- The newer claim has not been independently confirmed
- Fake wallet apps and malicious iPhone software remain a live threat
SlowMist says the Darksword exploit chain may have been adapted to target devices running iOS 26.5 and extract private keys from self-custody crypto wallets. The warning is serious, but it should be read with the right level of caution. Apple and Google have not independently confirmed that specific iOS 26.5 claim.
According to 23pds, SlowMist’s chief information security officer, attackers are using Darksword to "bypass Apple’s security controls", "gain extensive access to affected iPhones", and "collect data from locally installed cryptocurrency wallets". He also described the chain as potentially capable of "root-level control", in plain English, the kind of access that can tear through most of the usual iPhone protections.
That matters because if a private key or recovery phrase is exposed, a self-custody wallet is effectively compromised. There is no support desk, no chargeback button, and no friendly bank manager to undo the damage. That is the tradeoff of holding your own keys: control is the point, but so is the risk.
How Darksword works
Darksword is a full iOS exploit chain, which means attackers string together multiple vulnerabilities to break through different layers of security. Google Threat Intelligence Group previously documented Darksword as combining six vulnerabilities and affecting iOS 18.4 through iOS 18.7.
Google also tied one of the flaws used against iOS 18.6 to 18.7 devices to CVE-2025-43529, a bug in JavaScriptCore, Apple’s engine for running JavaScript in Safari. Apple later patched the flaw in iOS 18.7.3 and iOS 26.2 after Google reported it.
The attack chain starts in a familiar way: social engineering. According to 23pds, attackers typically send a link through a social network, messaging app, or another channel. The link opens malicious web content in Safari and tries to exploit browser and system components without requiring a normal app install.
If that chain succeeds, the attacker may gain enough access to collect account details, messages, browser records, files, location history, saved Wi-Fi data, and information linked to cryptocurrency wallets. That is not a narrow, surgical strike. It is a full-device compromise with financial theft layered on top.
Why crypto users should care
Self-custody wallets are only as safe as the secrecy of the key material behind them. If attackers can read wallet data, copy recovery phrases, or pull credentials from the device, the wallet should be treated as compromised.
That is why mobile exploitation hits crypto users so hard. Phones now hold messaging apps, authentication tools, browser sessions, wallet software, and private data in one place. A successful compromise can turn a device that feels secure into a tool for surveillance, account takeover, and theft.
Google said it saw multiple groups using Darksword with different final-stage payloads. Some of those payloads were used to collect cryptocurrency wallet information, while others were aimed at broader device data. Google also connected separate operations to victims in Saudi Arabia, Turkey, Malaysia, and Ukraine, and said some of the activity appeared tied to commercial surveillance providers and suspected state-linked groups.
That mix is important. Advanced mobile exploit chains are not always built for crypto theft alone. Some are sold as surveillance tools, some are used by governments or their proxies, and some eventually leak into criminal hands. Once powerful tooling gets out, the use cases tend to get uglier fast.
A broader pattern of iPhone targeting
Darksword is not an isolated problem. In March, crypto.news covered Google’s findings on Coruna, an exploit kit with 23 vulnerabilities across five attack chains. Coruna targeted iPhones running iOS 13 through iOS 17.2.1 and could search files and images for terms such as "backup phrase" and "bank account".
That is exactly the kind of thing crypto users should worry about. Attackers are not guessing. They are looking for the words and files that usually give them direct access to funds.
Binance issued another warning on Sep. 19 about malicious code found in FomoPeek versions 1.1 and 1.2. Binance said the software included a kernel exploitation framework with eight attack methods and claimed support for iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1.
According to Binance, the malicious modules could escape the iOS sandbox, decrypt Keychain data, access private keys, access wallet recovery phrases, access account credentials, and reach files held by other applications. In other words, the package was built to go after the exact material crypto users care about most.
Binance’s guidance was straightforward: remove the app, update iOS, and do not reinstall it. For self-custody users, Binance said to create a new wallet on a clean device and move assets if there is any chance the private key or recovery phrase was copied. That is the right call. If the seed is exposed, the old wallet is no longer safe.
Fake wallet apps are still draining people
Not every theft needs a zero-day exploit chain. Sometimes scammers just impersonate the real thing and wait for users to hand over the keys.
Three investors filed a federal lawsuit alleging that fake apps impersonating Sparrow Wallet appeared in the App Store and caused about $1.835 million in Bitcoin losses. Another counterfeit app posing as Ledger Live allegedly stole at least $9.5 million from more than 50 victims between April 7 and April 13.
Blockchain investigator ZachXBT traced funds from Bitcoin, Ethereum, Solana, Tron, and XRP users to more than 150 KuCoin deposit addresses and a mixing service. That kind of tracing does not make stolen funds magically reappear, but it does help map the flow of money and shows how widely the scam spread before the fake listing was removed by Apple.
One victim said he downloaded the fake Ledger app while configuring a Ledger device on a new MacBook. That detail is painfully familiar: these scams work because they catch people at ordinary moments, when trust is high and suspicion is low.
The larger lesson is simple. Apple’s distribution system is safer than random download sites, but it is not airtight. A polished fake app, a malicious link, or a compromised webpage can still do damage if users assume the platform itself guarantees safety.
What users should take from this
Keep iOS updated. Avoid wallet software that does not come from the official source. Treat unsolicited links with suspicion, especially if they promise urgent fixes, airdrops, account recovery, or “security checks.”
If a wallet app has been installed and there is any chance a private key or recovery phrase was exposed, move funds to a new wallet created on a clean device. That old wallet should be considered burned. It is better to do the annoying, cautious thing than to discover later that someone else has already copied the seed.
It is also worth watching for signs of compromise: unexpected wallet approvals, strange outbound transfers, browser redirects, new apps you do not remember installing, or unusual battery and network behavior. None of those signs prove an exploit chain by themselves, but they are the kind of red flags that deserve attention fast.
Crypto gives users real control, but control cuts both ways. On a phone, the same convenience that makes self-custody usable also makes it a juicy target. The security bar is not “pretty secure.” It is “have you actually protected the keys.”
Key questions and takeaways
-
Is Darksword confirmed on iOS 26.5?
No. SlowMist says the chain may have been adapted for iOS 26.5, but that specific claim has not been independently confirmed by Apple or Google. -
What is Darksword trying to steal?
The goal appears to be access to device data, including information tied to crypto wallets. In practical terms, that can include the material needed to take control of funds. -
How does the attack usually begin?
With social engineering. A user receives a link through a messaging app, social network, or similar channel, and Safari opens malicious content that starts the exploit chain. -
Why is this dangerous for self-custody wallets?
Because self-custody depends on keeping private keys and recovery phrases secret. If those secrets are copied from the device, the wallet should be treated as compromised. -
What should someone do if they think their seed phrase was exposed?
Create a new wallet on a clean device and move assets as soon as possible. If the recovery phrase is copied, the old wallet is no longer safe. -
Should crypto users rely on an iPhone alone for storage?
Not for serious holdings. A hardware wallet or a separate, hardened setup is a better fit for larger balances than keeping everything on a daily-use phone.