SlowMist Warns Darksword May Target Bitcoin (BTC) Wallets on iOS 26.5

SlowMist warns attackers may have adapted the Darksword exploit chain to iOS 26.5, putting Bitcoin wallet private keys and iPhone data at risk.

(04:18 AM UTC)
4 min read
AI SummaryAI
  • SlowMist warns Darksword may now compromise iPhones running iOS 26.5.
  • Google's Threat Intelligence Group documented Darksword support for iOS 18.4 through 18.7.
  • Darksword chains six vulnerabilities, including CVE-2025-43529 in Safari's JavaScriptCore.
  • Apple patched CVE-2025-43529 in iOS 18.7.3 and iOS 26.2.
k7rq2fdm

SlowMist Flags iOS 26.5 Exposure

SlowMist, the blockchain security firm, has warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5, putting private keys held in self-custody crypto wallets directly at risk. The assessment came from the firm's chief information security officer, known as 23pds, who stated in a public warning post that attackers are deploying Darksword to bypass Apple's security controls, gain broad access to affected iPhones and harvest data from locally installed cryptocurrency wallets. The warning extends a threat that Google Threat Intelligence Group has documented in detail. Google's researchers identified Darksword as a full iOS exploit chain — six vulnerabilities chained together to compromise a device and deliver interchangeable malicious payloads — and tracked active campaigns from at least December 2025 through March 2026. The original framework supported iOS versions 18.4 through 18.7. One flaw used against devices on iOS 18.6 and 18.7, tracked as CVE-2025-43529, sat in JavaScriptCore, the engine that processes JavaScript in Safari; Apple patched it in iOS 18.7.3 and iOS 26.2 after Google reported it. SlowMist's claim that the chain now reaches iOS 26.5 has not been confirmed by Apple or Google, and the security firm's warning did not cite technical analysis identifying which vulnerability or replacement exploit could compromise the newer release. The delivery method, however, follows the documented pattern: a target receives a link through a social network or messaging app and opens the page in Safari, where malicious web content attempts to exploit the browser and other iOS components without requiring any application install. Once the chain succeeds, an attacker can obtain root-level control — access that dissolves the isolation normally preventing one app from reading another app's files — placing private keys and wallet records stored on the device, rather than on a remote server or a blockchain node, within reach. Unlike cryptojacking, which hijacks device resources to mine, this class of attack targets the credentials themselves.

\n

Google's March Research on DarkSword

The anatomy of the attack, mapped in Google Threat Intelligence Group research published in March, starts with a memory-corruption flaw in JavaScriptCore and begins when the victim visits a malicious or compromised website in Safari. From there, the chain defeats Pointer Authentication Codes (PAC) — Apple's hardware-level defense that cryptographically signs memory pointers to block exploit primitives — breaks out of Safari's WebContent sandbox and, in its final stage, achieves kernel-level privileges, effectively handing the attacker full control of the handset. Lookout's research into the aftermath found that user credentials and data associated with crypto wallets can be exported from the device shortly after compromise. That makes the exposure acute for self-custody users who store a recovery phrase or private key on the phone itself, including those who sign transactions for a DeFi app from a mobile wallet. Google's findings show several separate groups operating Darksword with different final-stage payloads rather than one fixed malware strain: depending on the campaign, the payloads could collect account details, messages, browser records, files, location history, saved Wi-Fi data and information tied to cryptocurrency wallets. Researchers connected operations to victims in Saudi Arabia, Turkey, Malaysia and Ukraine, and associated some activity with commercial surveillance providers and suspected state-linked groups, while also finding signs that financially motivated actors had obtained access to advanced iPhone exploitation tooling. No confirmed victim total or verified amount of cryptocurrency stolen through Darksword has been disclosed in the material published so far; the emphasis remains on the framework's capability to reach wallet data after compromising the device that stores it. SlowMist's guidance is unchanged from earlier advisories: install mobile operating-system updates promptly and avoid opening unsolicited links from strangers. Because Apple has already patched the six vulnerabilities in the original Darksword chain, keeping software current is treated by both Apple and Google as the primary line of defense. Readers tracking the market in real time can follow live spot and futures prices on Bybit.

\n

A Rising iPhone Threat Pattern

In our view, Darksword is the second iPhone-centered threat to crypto users within days. Binance's official Sep. 19 notice flagged malicious code in FomoPeek versions 1.1 and 1.2 — a kernel framework with eight attack methods spanning iOS 12.0 through 18.7.2 and 26.0 through 26.1, capable of escaping the sandbox and decrypting Keychain data. Separately, three U.S. investors allege fake Sparrow Wallet apps in the App Store caused $1.835 million in Bitcoin losses. Our reading of SlowMist's primary post: the core claim — iOS 26.5 exposure — remains unconfirmed by Apple or Google, so treat it as a warning, not a verified breach, and move keys to a clean device if in doubt. For holders unwilling to keep keys on a phone, our guide to the Best Crypto Exchanges covers custody alternatives.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.