📈 Get daily crypto insights that make you smarter about your money

Darksword May Now Crack iOS 26.5: SlowMist Says Your Wallet Private Keys Are the Prize

The iPhone in your pocket may be the weakest link between you and your crypto. Blockchain security firm SlowMist has warned that attackers appear to have adapted the Darksword exploit chain to compromise devices running iOS 26.5 and extract private keys from self-custody wallets, extending a threat that Google researchers originally documented against older versions of Apple’s operating system.

The warning, issued by SlowMist Chief Information Security Officer 23pds, says attackers are using Darksword to bypass Apple’s security controls, gain extensive access to affected iPhones, and collect data from locally installed cryptocurrency wallets. If accurate, the claim would push the known exposure window well beyond what Google’s Threat Intelligence Group catalogued earlier this year. The iOS 26.5 claim has not been independently confirmed by either Apple or Google, and no technical analysis accompanying the warning identified which vulnerability or replacement exploit could allow the chain to compromise the newer release.

## What Darksword actually does

Google’s Threat Intelligence Group identified Darksword as a full iOS exploit chain that combines six separate vulnerabilities to compromise a device and deliver distinct malicious payloads. The company tracked related activity from at least December 2025 through March 2026, and its published research documented support for iOS versions 18.4 through 18.7.

One of the flaws used against iOS 18.6 and 18.7 devices, tracked as CVE-2025-43529, affected JavaScriptCore, the engine that processes JavaScript in the Safari browser. Apple patched the vulnerability in iOS 18.7.3 and iOS 26.2 after Google reported it. SlowMist’s assessment suggests attackers have since reworked the toolkit to function against the far newer iOS 26.5.

According to 23pds, the compromise typically begins with social engineering rather than a malicious app. A target receives a link through a social network, messaging app, or another communication channel and opens the page in Safari. Malicious web content then attempts to exploit the browser and other iOS components without requiring the user to install anything. Once the chain succeeds, the attacker may obtain root-level control of the device. That level of access can strip away the sandbox isolation that normally prevents one application from reading files and credentials belonging to another, placing private keys and wallet records stored on the phone directly at risk.

## Multiple payloads, multiple victims

Google found several distinct groups using Darksword with different final-stage payloads rather than one fixed piece of malware. Depending on the campaign, those payloads could collect account details, messages, browser records, files, location history, saved Wi-Fi credentials, and information linked to cryptocurrency wallets. The company connected separate operations to victims in Saudi Arabia, Turkey, Malaysia, and Ukraine, and associated some of the activity with commercial surveillance providers and suspected state-linked groups. Researchers also found signs that financially motivated actors had gained access to advanced iPhone exploitation tools.

Notably, the material supplied by SlowMist did not include a victim count or a confirmed amount of cryptocurrency stolen through Darksword. The warning instead centered on the framework’s ability to reach wallet information after compromising the device that stores it, a distinction that matters for anyone keeping seed phrases or keys in notes apps, screenshots, or wallet software on iOS.

The delivery pattern echoes an earlier mobile threat. In March, Google detailed Coruna, an exploit kit containing 23 vulnerabilities across five attack chains that targeted iPhones running everything from iOS 13 through 17.2.1. Coruna could search compromised files and images for terms such as “backup phrase” and “bank account,” and fingerprinted a visitor’s device before selecting an exploit suited to the specific model and software version. Some operators hosted the kit on fake gambling and cryptocurrency sites, meaning the compromise began the moment a target simply loaded the page.

## A crowded month for iOS wallet threats

Darksword is far from the only recent security threat aimed at crypto data on Apple devices. On Sep. 19, Binance warned iPhone and iPad users about malicious code found in versions 1.1 and 1.2 of an app called FomoPeek. Researchers examining the software found a kernel exploitation framework with eight attack methods and declared support covering iOS 12.0 through 18.7.2, as well as iOS 26.0 through 26.1. The malicious modules could escape the iOS sandbox, decrypt Keychain data, and access private keys, wallet recovery phrases, account credentials, and files held by other applications.

Binance advised anyone who had installed the affected versions to remove the app, update iOS, and avoid reinstalling it. For self-custody users, the guidance went further: create a new wallet on a clean device and transfer assets, because deleting a malicious app does nothing to protect a wallet whose private key or recovery phrase has already been copied.

Separately, three U.S. investors have alleged in recent complaints that fake wallet applications caused a combined 1.835 million USD in Bitcoin losses, underscoring that social engineering and bogus software remain the most common paths to theft even as exploit chains like Darksword grab headlines.

## Practical steps for altcoin holders

For holders of altcoins and other digital assets on iOS devices, the SlowMist warning boils down to a handful of precautions. First, update to the latest available iOS release immediately, since Apple’s patches for the JavaScriptCore flaw and other bugs are already distributed. Second, never open unsolicited links in Safari, even from contacts, since the chain requires no app installation to fire. Third, consider keeping significant holdings in hardware wallets that never expose keys to the phone at all, and store recovery phrases offline rather than in any cloud-synced note or photo library.

At the time of writing, Bitcoin trades near 86,447 USD, up roughly 6.5 percent on the day, Ethereum sits at 2,772 USD, and Solana trades around 119 USD. Rising prices tend to attract exactly the kind of financially motivated attackers that Google says now have their hands on advanced iPhone exploitation tooling. The unconfirmed status of the iOS 26.5 claim is a reason for caution about the details, but not for delaying basic hygiene. In self-custody, the device is the vault, and right now the vault is the target.

15 thoughts on “Darksword May Now Crack iOS 26.5: SlowMist Says Your Wallet Private Keys Are the Prize”

  1. No patch note from Apple mentioning any of this in 26.5.x. Either it is being fixed quietly or SlowMist is early. Moved my hot wallet to a cheap spare android either way

    1. the spare android move is underrated. even if 26.5 is clean, one bad apk sideload puts your keys right back in the same place

  2. six chained vulns and the whole thing starts with just opening a link in safari. and people still keep their seed phrase in the notes app lol

    1. ^ exactly. CVE-2025-43529 was patched back in 26.2, so if this is real they chained something new and nobody knows what

  3. six chained bugs through Safari and root access to your files. anyone keeping a seed phrase in notes or screenshots on an iphone is playing with fire

  4. SlowMist posted this with zero technical proof it actually works on 26.5. Google only confirmed the 18.4 to 18.7 range. Hope Apple or someone verifies it fast, because right now it is just their word.

  5. a 26.5 claim with no poc dropped right as apple seeds a point release. if it holds up, the patch window is the real story

  6. slowmist drops this with zero technical analysis and no victim count. might be real but im waiting on apple or project zero before panic wiping anything

    1. waiting on apple too but slowmist flagged the bybit flow weeks before anyone confirmed it. updating costs nothing, panic costs sleep

    2. waiting on apple too but slowmist flagged the bybit flow weeks before anyone confirmed it. updating costs nothing, panic costs sleep

    3. fair, but CVE-2025-43529 was real and Apple patched it in 26.2. reworking the chain for 26.5 is not a wild claim at all

      1. chaining a fresh zero day to replace a patched link is expensive but nation state budgets exist. slowmist flagged the byby flow weeks before anyone confirmed it too

      2. patched in 26.2 sure, but that assumes the entry point is even the same. six bugs chained means one new zero and the whole 26.5 is safe argument collapses

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$86,421.00+6.4%ETH$2,771.54+4.9%SOL$118.68+6.9%BNB$798.62+3.3%XRP$1.54+8.7%ADA$0.2440+6.6%DOGE$0.0997+14.1%DOT$1.21+6.7%AVAX$11.23-0.6%LINK$13.13+4.9%UNI$9.01+2.6%ATOM$1.81+2.2%LTC$62.01+5.2%ARB$0.2264+3.3%NEAR$4.28+2.7%FIL$0.9864+4.2%SUI$1.04+15.9%BTC$86,421.00+6.4%ETH$2,771.54+4.9%SOL$118.68+6.9%BNB$798.62+3.3%XRP$1.54+8.7%ADA$0.2440+6.6%DOGE$0.0997+14.1%DOT$1.21+6.7%AVAX$11.23-0.6%LINK$13.13+4.9%UNI$9.01+2.6%ATOM$1.81+2.2%LTC$62.01+5.2%ARB$0.2264+3.3%NEAR$4.28+2.7%FIL$0.9864+4.2%SUI$1.04+15.9%
Scroll to Top