DarkSword iPhone Exploit Still Targets Trust Wallet (TWT) Users Across 9 Wallet Apps
The DarkSword iPhone exploit still targets Trust Wallet and eight other wallet apps; Apple's iOS 26.3 patch closes the flaws the kit abuses.
AI SummaryAI
- Coruna malware scans photos and notes on infected iPhones for BIP39 recovery phrases.
- DarkSword targets nine wallet apps including Trust Wallet, MetaMask, Coinbase, Phantom and Exodus.
- Apple patched the exploited WebKit and JavaScriptCore vulnerabilities in iOS 26.3.
- iPhones on iOS 26.2 or below, including older iOS 18 builds, remain vulnerable without updates.
DarkSword Kit Still Targets Nine Wallet Apps
Apple's iOS 26.3 update closes every hole the DarkSword exploit kit uses, yet the campaign against iPhone-based crypto wallets, with Trust Wallet (TWT) among the targets, is still running on handsets that never installed the patch. Researchers at the cybersecurity firm Censys report that several servers hosting the deployment directories for DarkSword and the Coruna malware it delivers remain online, months after the exploits first surfaced. The researchers mapped the server-side plumbing that keeps the operation alive, not the leftovers of a shut-down campaign. That infrastructure being live makes the threat current rather than historical: an iPhone on unpatched software is a reachable target today.
The kit breaks in through two Apple components, WebKit and JavaScriptCore, which render web content and execute scripts inside applications. Once a vulnerable device is reached, Coruna turns to the wallet software installed on it and harvests whatever can unlock a user's funds. The affected apps are Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, Uniswap, Bitpie, imToken and OKEx, nine wallet products in total, a list spanning self-custody clients and exchange-linked ones. Each app on the list holds keys or credentials whose theft converts directly into stolen balances. For Trust Wallet the exposure has a token-level edge: TWT is the app's native utility asset, and the Trust Wallet Token price acts as a barometer of confidence in the wallet's user base. The most consequential behavior sits outside the wallet apps. Censys states that Coruna can scan photos and notes stored on an infected device while hunting for BIP39 recovery phrases, the 12- or 24-word lists that back up an HD wallet. A captured phrase lets an attacker restore the wallet on their own hardware and drain it without ever touching the phone again. Self-custody shifts the whole security burden onto the holder, which is why a mobile exploit like this becomes a direct asset risk instead of a nuisance.
The iOS 26.3 Patch and Its Limits
Apple shipped the remedy in iOS 26.3, where every vulnerability DarkSword relies on has been patched, so the fix exists even though adoption is the open variable. Handsets on iOS 26.2 or below, including devices still running older versions of iOS 18, can be attacked if the update has not reached them. The practical sequence for a holder is short: open Settings, confirm the installed iOS version, install the 26.3 update, and only then treat the phone as out of the kit's reach. Updating the operating system, however, does not reach every part of the problem. A recovery phrase that was photographed, screenshotted or typed into the Notes app stays exactly where it was after the patch, and Coruna's scanning routine is built to locate precisely that material. Storage practice therefore runs in parallel with the update: phrases belong offline, written on a card or metal backup rather than inside a synced photo library, and a hardware wallet keeps its seed material out of the phone entirely. A crypto wallet whose phrase ever sat on an unpatched handset should be treated as compromised. For anyone who finds their device was exposed, the cautious order of operations is to update first, then generate a fresh wallet on patched hardware and move the balances across, because a phrase that lived on an infected phone cannot be un-leaked. The token angle deserves its own line: TWT confers fee discounts and governance rights inside the Trust Wallet ecosystem but holds no custody of user funds, so the exploit threatens adoption and reputation rather than the token contract itself. Nothing in the patch reports whether a device was already probed, so checking the iOS version and auditing stored notes falls to the holder.
Residual Risk for TWT Holders
For TWT, this is a reputation event rather than a treasury one: no funds were pulled from a contract, and the token itself was never touched. The residual risk lives in the gap the patch cannot close, since no public figure says how many iPhones still run 26.2 or older or how many seed phrases sit in photos and notes. Security headlines of this kind can also stir short-term FUD around a mid-cap altcoin, and readers watching that play out in the tape can follow our TWT technical analysis coverage. The outstanding item is behavioral, not technical: until phrase storage moves off phones entirely, the patched WebKit holes do not end what this campaign can reach.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

