Security researchers have uncovered a sophisticated data-stealing operation targeting cryptocurrency users through compromised iPhones. The campaign, identified on March 19, 2026, leverages the DarkSword exploit chain to deploy a malware payload called Ghostblade that specifically hunts for wallet and exchange applications installed on infected devices, extracting credentials, private keys, and transaction histories before wiping its own traces.
The Exploit Mechanics
DarkSword chains six separate iOS vulnerabilities to achieve full remote code execution on target devices. Three of the exploited flaws reside in WebKit, the browser engine powering Safari and all web browsers on iOS and iPadOS. Two additional vulnerabilities affect the iOS kernel, while a sixth targets the Dynamic Link Editor (dyld) component of Apple operating systems. The exploit chain works against iPhones running iOS versions 18.4 through 18.7, and the attack vector is remarkably simple: visiting a malicious or compromised website with a vulnerable device triggers the entire infection process automatically. This drive-by approach means victims need not click suspicious links in emails or install rogue applications. A routine browsing session on a hijacked website is sufficient to compromise the device completely.
Once DarkSword gains initial access through Safari, it escapes the WebContent sandbox, leverages WebGPU to inject into the mediaplaybackd process, and from there crafts kernel-level read and write capabilities. This escalation allows the malware to modify sandbox restrictions and access restricted filesystem areas that normal applications cannot reach.
Affected Systems
The Ghostblade payload represents the most concerning aspect of this campaign for cryptocurrency holders. Upon successful exploitation, the malware systematically enumerates installed applications and specifically targets major cryptocurrency exchange platforms including Coinbase, Binance, Kraken, KuCoin, OKX, and MEXC. Hardware wallet companion apps for Ledger and Trezor are also targeted, alongside software wallets such as MetaMask, Exodus, Uniswap Wallet, Phantom, and Gnosis Safe.
For each identified application, Ghostblade extracts stored credentials, session tokens, encryption keys, and any locally cached transaction data. Beyond cryptocurrency-specific targets, the malware also collects SMS and iMessage messages, call history, contacts, Wi-Fi configuration and saved passwords, Safari cookies and browsing history, location data, notes, calendar entries, health data, photos, iCloud Drive files, SIM information, emails, and message histories from Telegram and WhatsApp.
The Mitigation Strategy
Apple has addressed all six DarkSword vulnerabilities across multiple iOS updates released between July 2025 and February 2026. CVE-2025-31277 was patched in iOS 18.6, while CVE-2025-43510 and CVE-2025-43520 received fixes in iOS 26.1 and 18.7.2 during November 2025. CVE-2025-43529 and CVE-2025-14174 were addressed in iOS 26.2 and 18.7.3 in December 2025 after reports of targeted in-the-wild exploitation. The most recent patch, CVE-2026-20700 affecting the dyld component, was fixed in iOS 26.3 during February 2026 following confirmed zero-day exploitation. Apple expanded these patches further with iOS 18.7.7 on April 1, 2026.
Cryptocurrency users running any iOS version below 18.7.7 remain potentially vulnerable. The recommendation is immediate: update to the latest available iOS version for your device. For high-value crypto holders, journalists, activists, or individuals with access to sensitive data, Apple Lockdown Mode provides an additional layer of protection that has proven effective against targeted surveillance campaigns.
Lessons Learned
The DarkSword campaign exposes several critical vulnerabilities in how cryptocurrency users approach mobile security. First, the assumption that iOS devices are inherently secure against sophisticated attacks has been repeatedly disproven. State-sponsored actors and commercial surveillance vendors maintain and deploy advanced exploit chains capable of fully compromising unpatched iPhones through routine web browsing. Second, the targeting of specific exchange and wallet applications indicates that cryptocurrency users are now a primary objective for both espionage and financial theft operations. The malware design suggests attackers understand the crypto ecosystem well enough to prioritize which applications yield the most valuable data.
Third, the self-deleting nature of Ghostblade means victims may never discover the compromise. The malware collects data, exfiltrates it to a remote server, deletes its temporary files, and terminates itself, leaving minimal forensic evidence on the device.
User Action Required
Every cryptocurrency user with an iPhone should take immediate steps to verify their device is running iOS 18.7.7 or later. Navigate to Settings, then General, then Software Update to check. Move high-value crypto assets to hardware wallets that are never connected to mobile devices. Enable two-factor authentication on all exchange accounts using a dedicated authenticator application rather than SMS-based verification. Consider using a separate, dedicated device for cryptocurrency operations that is not used for general web browsing or social media. Review recent exchange and wallet activity for any unauthorized transactions or login attempts from unfamiliar locations. With Bitcoin trading around $69,900 and Ethereum at $2,137 on the date of this discovery, the financial incentive for attackers targeting crypto holders has never been greater.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always consult with qualified cybersecurity professionals for personalized security recommendations.
Every cycle the infrastructure gets more robust
Mass adoption is happening incrementally — people just don’t notice
David Kim mass adoption incremental is right but 6 chained iOS vulns including kernel access means apple needs to step up their sandbox model
Takeshi Mori 3 of 6 chained vulns were in WebKit. Apple needs to harden the browser engine separately from the kernel because Safari is the attack surface
3 of 6 chained bugs in WebKit alone. Safari is the attack surface on iOS and Apple needs to harden it separately. kernel sandbox doesnt help when the browser engine is wide open
3 bugs in WebKit alone means Safari is doing all the heavy lifting for the attackers. Apple needs to decouple it from the kernel ASAP
drive by attack through safari with no click needed on iOS 18.4 to 18.7. thats a massive vulnerable device population for wallet theft
driveby_rekt no click needed through Safari on iOS 18.4 to 18.7. that covers millions of devices. update your phones people, this is not theoretical
Priya S. no click drive-by through safari on millions of devices should be treated as a national security issue
Ghostblade targeting exchange app credentials specifically means the attackers understand crypto user behavior. people keep banking apps and wallet apps on the same device
drive-by through Safari on iOS 18.4 to 18.7 with no interaction. that is millions of devices walking around with wallet apps installed and zero protection until they updated
Priya S. iOS 18.4 through 18.7 covers months of unpatched devices. anyone running Binance or Coinbase apps on those versions was basically handing over API keys
wiping_trace_ self cleaning malware means victims had zero indication until funds moved. by the time you notice the wallet is drained the attacker is already gone
3 WebKit bugs plus 2 kernel plus dyld is a chain that costs north of $5M on the exploit market. they were not targeting random $500 wallets with this
bytecode_rat a 6 bug exploit chain costing 5M plus on the market means the targets were whales holding 8 figures. nobody burns that kind of capital on random wallets
Ghostblade wiping its own traces after exfiltrating credentials means victims had zero indication anything was wrong until funds moved. terrifying opsec from the attackers
The fundamental value proposition of crypto keeps getting stronger
HODLKing_ the fundamental value prop getting stronger is true but Ghostblade specifically hunting exchange app credentials on mobile devices targets the weakest user behavior, not the protocol
3 WebKit zero days chained together just to get initial access. the economics of building this exploit chain vs stealing from one iphone user dont add up unless its targeted
webkit_rabbit_ the dyld exploit was the persistence layer. once they had RCE via safari the loader kept reinfecting after reboot. genuinely sophisticated
drive-by infection from just visiting a website is terrifying. no click needed, no app install. safari was the attack vector the whole time
Ghostblade specifically scanning for exchange apps is targeted. these attackers know exactly what theyre after
6 chained iOS vulns including kernel access on 18.4-18.7 is terrifying. apple needs to harden safari separately
6 chained vulns through Safari and Apple took months to patch 18.4-18.7. anyone running an older iOS with a hot wallet was basically serving their keys on a plate
6 vulns chained including kernel and dyld is nation-state level tooling being deployed for wallet theft. the cost to build this exploit chain is millions, theyre going after high value targets not random holders
3 WebKit zero days chained together just for initial access. Apple decoupling Safari from the kernel cannot come soon enough